Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.2

    HIGH
    CVE-2001-0979

    Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long command line argument.... Read more

    Affected Products : hp-ux
    • EPSS Score: %0.17
    • Published: Sep. 03, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0978

    login in HP-UX 10.26 does not record failed login attempts in /var/adm/btmp, which could allow attackers to conduct brute force password guessing attacks without being detected or observed using the lastb program.... Read more

    Affected Products : hp-ux
    • EPSS Score: %1.29
    • Published: Sep. 03, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1169

    keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authenticatio... Read more

    Affected Products : s_key
    • EPSS Score: %0.47
    • Published: Sep. 02, 2001
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2001-0996

    POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interpreted by various mail clients as valid POP server responses... Read more

    Affected Products : pop3lite
    • EPSS Score: %0.86
    • Published: Sep. 02, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0976

    Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables.... Read more

    Affected Products : process_resource_manager
    • EPSS Score: %0.05
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1067

    Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP request with a long Authorization header.... Read more

    Affected Products : aol_server
    • EPSS Score: %29.25
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0943

    dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse pro... Read more

    Affected Products : database_server
    • EPSS Score: %0.80
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-1069

    libCoolType library as used in Adobe Acrobat (acroread) on Linux creates the AdobeFnt.lst file with world-writable permissions, which allows local users to modify the file and possibly modify acroread's behavior.... Read more

    Affected Products : acrobat_reader
    • EPSS Score: %0.09
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0968

    Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges.... Read more

    Affected Products : arkeia
    • EPSS Score: %0.95
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0965

    glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.... Read more

    Affected Products : glftpd
    • EPSS Score: %6.79
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0972

    Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."... Read more

    Affected Products : asp_forum
    • EPSS Score: %0.93
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-1070

    Sage Software MAS 200 allows remote attackers to cause a denial of service by connecting to port 10000 and entering a series of control characters.... Read more

    Affected Products : mas_200
    • EPSS Score: %0.28
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1007

    Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly guess the key via a brute force attack.... Read more

    Affected Products : truesync_desktop
    • EPSS Score: %0.48
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1004

    Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name contains the script tags.... Read more

    Affected Products : gnutella_client
    • EPSS Score: %0.41
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1008

    Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.... Read more

    Affected Products : jre java_plug-in
    • EPSS Score: %0.63
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2000-1199

    PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.... Read more

    Affected Products : postgresql
    • EPSS Score: %0.50
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1005

    Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registry key to decrypt the password and gain privileges.... Read more

    Affected Products : truesync_desktop
    • EPSS Score: %0.22
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1191

    htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes t... Read more

    Affected Products : htdig
    • EPSS Score: %2.00
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1061

    Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.... Read more

    Affected Products : aix
    • EPSS Score: %0.56
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2000-1194

    Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.... Read more

    Affected Products : ftp_server
    • EPSS Score: %2.91
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 291196 Results