Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2001-0680

    Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a "dot dot" attack in a LIST (ls) command.... Read more

    Affected Products : qvt_net avt_term
    • EPSS Score: %84.83
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0508

    Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.... Read more

    Affected Products : internet_information_services iis
    • EPSS Score: %19.92
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0690

    Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers.... Read more

    Affected Products : debian_linux exim linux linux exim
    • EPSS Score: %19.93
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0650

    Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute.... Read more

    Affected Products : ios
    • EPSS Score: %1.31
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0648

    Directory traversal vulnerability in PHProjekt 2.1 and earlier allows a remote attacker to conduct unauthorized activities via a dot dot (..) attack on the file module.... Read more

    Affected Products : phprojekt
    • EPSS Score: %0.50
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0668

    Buffer overflow in line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to execute arbitrary commands.... Read more

    Affected Products : hp-ux
    • EPSS Score: %1.76
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0695

    WFTPD 3.00 R5 allows a remote attacker to cause a denial of service by making repeated requests to cd to the floppy drive (A:\).... Read more

    Affected Products : wftpd
    • EPSS Score: %0.79
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0681

    Buffer overflow in ftpd in QPC QVT/Net 5.0 and QVT/Term 5.0 allows a remote attacker to cause a denial of service via a long (1) username or (2) password.... Read more

    Affected Products : qvt_net qvt_term
    • EPSS Score: %0.71
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0506

    Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vu... Read more

    • EPSS Score: %37.94
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-0653

    Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d) command line arguments, which is interpreted as a negative number.... Read more

    Affected Products : sendmail
    • EPSS Score: %0.33
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0507

    IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.... Read more

    Affected Products : internet_information_services iis
    • EPSS Score: %1.15
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0962

    IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.... Read more

    • EPSS Score: %1.05
    • Published: Sep. 19, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1215

    The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information.... Read more

    Affected Products : lotus_domino
    • EPSS Score: %0.76
    • Published: Sep. 19, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0961

    Buffer overflow in tab expansion capability of the most program allows local or remote attackers to execute arbitrary code via a malformed file that is viewed with most.... Read more

    Affected Products : most
    • EPSS Score: %6.45
    • Published: Sep. 18, 2001
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2001-1353

    ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.... Read more

    Affected Products : ghostscript
    • EPSS Score: %0.07
    • Published: Sep. 18, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0960

    Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows local and remote attackers to gain privileges.... Read more

    • EPSS Score: %1.16
    • Published: Sep. 15, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1014

    eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter.... Read more

    • EPSS Score: %3.75
    • Published: Sep. 15, 2001
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2001-0959

    Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 creates a hidden share named ARCSERVE$, which allows remote attackers to obtain sensitive information and overwrite critical files.... Read more

    • EPSS Score: %0.87
    • Published: Sep. 15, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0986

    SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinf... Read more

    Affected Products : index_server
    • EPSS Score: %74.06
    • Published: Sep. 14, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-0984

    Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options enab... Read more

    Affected Products : password_safe
    • EPSS Score: %0.07
    • Published: Sep. 13, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 291160 Results