Latest CVE Feed
-
7.5
HIGHCVE-2001-1208
Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code.... Read more
Affected Products : daydream_bbs- EPSS Score: %1.62
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1536
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.... Read more
Affected Products : audiogalaxy- EPSS Score: %0.76
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2001-1523
Cross-site scripting (XSS) vulnerability in the DMOZGateway module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the topic parameter.... Read more
Affected Products : dmozgateway- EPSS Score: %0.35
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1547
Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, does not block email attachments from forwarded messages, which could allow remote attackers to execute arbitrary code.... Read more
Affected Products : outlook_express- EPSS Score: %21.82
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1581
The File Blocker feature in Clearswift MAILsweeper for SMTP 4.2 allows remote attackers to bypass e-mail attachment filtering policies via a modified name in a Content-Type header.... Read more
Affected Products : mailsweeper- EPSS Score: %0.25
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1477
The Domain gateway in BEA Tuxedo 7.1 does not perform authorization checks for imported services and qspaces on remote domains, even when an ACL exists, which allows users to access services in a remote domain.... Read more
Affected Products : tuxedo- EPSS Score: %0.08
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1518
RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. NOTE: the v... Read more
Affected Products : windows_2000- EPSS Score: %0.61
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1576
Buffer overflow in cron in Caldera UnixWare 7 allows local users to execute arbitrary code via a command line argument.... Read more
Affected Products : unixware- EPSS Score: %0.09
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1482
SQL injection vulnerability in bb_memberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL queries via the $sortby variable.... Read more
Affected Products : phpbb- EPSS Score: %0.49
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1480
Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.... Read more
- EPSS Score: %0.54
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2001-1524
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and file parameters in modules.php, (3) subject, story and st... Read more
Affected Products : php-nuke- EPSS Score: %0.11
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1573
Buffer overflow in smtpscan.dll for Trend Micro InterScan VirusWall 3.51 for Windows NT has allows remote attackers to execute arbitrary code via a certain configuration parameter.... Read more
Affected Products : interscan_viruswall- EPSS Score: %1.95
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1550
CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impersonate users.... Read more
- EPSS Score: %0.18
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
5.3
MEDIUMCVE-2001-1533
Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the se... Read more
Affected Products : isa_server- EPSS Score: %26.89
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2001-1559
The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigger a null dereference.... Read more
Affected Products : openbsd- EPSS Score: %0.40
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2001-1519
RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service. NOTE: the vendor disputes this issue, saying that adminis... Read more
Affected Products : windows_2000- EPSS Score: %2.00
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2001-1496
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.... Read more
Affected Products : thttpd- EPSS Score: %19.07
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1553
Buffer overflow in setiathome for SETI@home 3.03, if installed setuid, could allow local users to execute arbitrary code via long command line options (1) socks_server, (2) socks_user, and (3) socks_passwd. NOTE: since the default configuration of setiath... Read more
Affected Products : seti_at_home- EPSS Score: %0.09
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-1568
CMG WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack.... Read more
Affected Products : wap_gateway- EPSS Score: %0.18
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1549
Tiny Personal Firewall 1.0 and 2.0 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters.... Read more
Affected Products : tiny_personal_firewall- EPSS Score: %0.14
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025