Latest CVE Feed
-
6.4
MEDIUMCVE-2001-0973
BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space.... Read more
Affected Products : bscw- EPSS Score: %3.17
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1061
Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.... Read more
Affected Products : aix- EPSS Score: %0.56
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1192
Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap.... Read more
Affected Products : snmp_trap_watcher- EPSS Score: %2.28
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1025
PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.... Read more
Affected Products : php-nuke- EPSS Score: %0.07
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1070
Sage Software MAS 200 allows remote attackers to cause a denial of service by connecting to port 10000 and entering a series of control characters.... Read more
Affected Products : mas_200- EPSS Score: %0.28
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1004
Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name contains the script tags.... Read more
Affected Products : gnutella_client- EPSS Score: %0.41
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1007
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly guess the key via a brute force attack.... Read more
Affected Products : truesync_desktop- EPSS Score: %0.48
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1069
libCoolType library as used in Adobe Acrobat (acroread) on Linux creates the AdobeFnt.lst file with world-writable permissions, which allows local users to modify the file and possibly modify acroread's behavior.... Read more
Affected Products : acrobat_reader- EPSS Score: %0.09
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0968
Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges.... Read more
Affected Products : arkeia- EPSS Score: %0.95
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0972
Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."... Read more
Affected Products : asp_forum- EPSS Score: %0.93
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0970
Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script.... Read more
Affected Products : td_forum- EPSS Score: %1.66
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0965
glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.... Read more
Affected Products : glftpd- EPSS Score: %6.79
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1193
Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port.... Read more
Affected Products : irix- EPSS Score: %4.19
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1009
Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as part of a response to a LIST request.... Read more
Affected Products : fetchmail- EPSS Score: %13.12
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0711
Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management Interface (ILMI) SNMP community string.... Read more
Affected Products : ios- EPSS Score: %13.01
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1199
PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.... Read more
Affected Products : postgresql- EPSS Score: %0.50
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1196
PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.... Read more
Affected Products : publishingxpert- EPSS Score: %8.51
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1202
ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.... Read more
Affected Products : http_server_ssl_module_common- EPSS Score: %0.09
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1062
Buffer overflow in mana in OpenServer 5.0.6a and earlier allows local users to execute arbitrary code.... Read more
Affected Products : openserver- EPSS Score: %0.33
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0969
ipfw in FreeBSD does not properly handle the use of "me" in its rules when point to point interfaces are used, which causes ipfw to allow connections from arbitrary remote hosts.... Read more
Affected Products : freebsd- EPSS Score: %0.43
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025