Latest CVE Feed
-
6.4
MEDIUMCVE-2001-0996
POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interpreted by various mail clients as valid POP server responses... Read more
Affected Products : pop3lite- EPSS Score: %0.86
- Published: Sep. 02, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0976
Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables.... Read more
Affected Products : process_resource_manager- EPSS Score: %0.05
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0943
dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse pro... Read more
Affected Products : database_server- EPSS Score: %0.80
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1067
Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP request with a long Authorization header.... Read more
Affected Products : aol_server- EPSS Score: %29.25
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0983
UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read the file to decrypt the passwords and gain privileges.... Read more
Affected Products : ultraedit-32- EPSS Score: %0.07
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1036
GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.... Read more
- EPSS Score: %0.13
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-1190
imwheel-solo in imwheel package allows local users to modify arbitrary files via a symlink attack from the .imwheelrc file.... Read more
Affected Products : imwheel- EPSS Score: %0.12
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1066
ns6install installation script for Netscape 6.01 on Solaris, and other versions including 6.2.1 beta, allows local users to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : solaris- EPSS Score: %0.09
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1064
Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwardi... Read more
Affected Products : cbos- EPSS Score: %5.66
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2001-0967
Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.... Read more
Affected Products : arkeia- EPSS Score: %0.36
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0970
Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script.... Read more
Affected Products : td_forum- EPSS Score: %1.66
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-1197
POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for ot... Read more
Affected Products : imap- EPSS Score: %0.08
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1199
PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.... Read more
Affected Products : postgresql- EPSS Score: %0.50
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1065
Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack.... Read more
Affected Products : cbos- EPSS Score: %0.48
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0973
BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space.... Read more
Affected Products : bscw- EPSS Score: %3.17
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0995
PHProjekt before 2.4a allows remote attackers to perform actions as other PHProjekt users by modifying the ID number in an HTTP request to PHProjekt CGI programs.... Read more
Affected Products : phpprojekt- EPSS Score: %0.87
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1041
oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.... Read more
Affected Products : database_server- EPSS Score: %0.29
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1072
Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.... Read more
Affected Products : http_server- EPSS Score: %0.85
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0981
HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user.... Read more
Affected Products : cifs-9000_server- EPSS Score: %0.39
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1452
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.... Read more
- EPSS Score: %5.37
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025