Latest CVE Feed
-
5.0
MEDIUMCVE-2001-1571
The Remote Desktop client in Windows XP sends the most recent user account name in cleartext, which could allow remote attackers to obtain terminal server user account names via sniffing.... Read more
Affected Products : windows_xp- EPSS Score: %30.26
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1489
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.... Read more
Affected Products : ie- EPSS Score: %13.45
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1515
Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended.... Read more
Affected Products : windows_2000- EPSS Score: %0.78
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2001-1494
script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.... Read more
- EPSS Score: %0.04
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1551
Linux kernel 2.2.19 enables CAP_SYS_RESOURCE for setuid processes, which allows local users to exceed disk quota restrictions during execution of setuid programs.... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1503
The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.... Read more
- EPSS Score: %0.22
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2001-1496
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.... Read more
Affected Products : thttpd- EPSS Score: %19.07
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1564
setrlimit in HP-UX 10.01, 10.10, 10.24, 10.20, 11.00, 11.04 and 11.11 does not properly enforce core file size on processes after setuid or setgid privileges are dropped, which could allow local users to cause a denial of service by exhausting available d... Read more
Affected Products : hp-ux- EPSS Score: %0.10
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1550
CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impersonate users.... Read more
- EPSS Score: %0.18
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
5.3
MEDIUMCVE-2001-1533
Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the se... Read more
Affected Products : isa_server- EPSS Score: %26.89
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2001-1523
Cross-site scripting (XSS) vulnerability in the DMOZGateway module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the topic parameter.... Read more
Affected Products : dmozgateway- EPSS Score: %0.35
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1536
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.... Read more
Affected Products : audiogalaxy- EPSS Score: %0.76
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1514
ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess fu... Read more
Affected Products : coldfusion- EPSS Score: %0.08
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1547
Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, does not block email attachments from forwarded messages, which could allow remote attackers to execute arbitrary code.... Read more
Affected Products : outlook_express- EPSS Score: %21.82
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1534
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session I... Read more
Affected Products : http_server- EPSS Score: %0.12
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1510
Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the re... Read more
Affected Products : jrun- EPSS Score: %3.38
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1572
The MAC module in Netfilter in Linux kernel 2.4.1 through 2.4.11, when configured to filter based on MAC addresses, allows remote attackers to bypass packet filters via small packets.... Read more
Affected Products : linux_kernel- EPSS Score: %0.40
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1478
Buffer overflow in xlock in UnixWare 7.1.0 and 7.1.1 and Open Unix 8.0.0 allows local users to execute arbitrary code.... Read more
- EPSS Score: %0.06
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1545
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing.... Read more
Affected Products : jrun- EPSS Score: %0.39
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1555
pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of terminals, which allows local users to write to other users' terminals by modifying the ACL of a TTY.... Read more
- EPSS Score: %0.07
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025