Latest CVE Feed
-
7.5
HIGHCVE-2001-0561
Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.... Read more
Affected Products : a1stats- EPSS Score: %10.51
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0562
a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters.... Read more
Affected Products : a1stats- EPSS Score: %1.28
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0615
Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'.... Read more
Affected Products : freestyle_chat- EPSS Score: %6.18
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0629
HP Event Correlation Service (ecsd) as included with OpenView Network Node Manager 6.1 allows a remote attacker to gain addition privileges via a buffer overflow attack in the '-restore_config' command line parameter.... Read more
Affected Products : openview_network_node_manager- EPSS Score: %0.98
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0527
DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.... Read more
- EPSS Score: %6.99
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0533
Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.... Read more
Affected Products : aix- EPSS Score: %0.07
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0521
Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.... Read more
Affected Products : esafe_gateway- EPSS Score: %2.71
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0520
Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT... Read more
Affected Products : esafe_gateway- EPSS Score: %2.71
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0528
Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain pri... Read more
Affected Products : e-business_suite- EPSS Score: %0.45
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0519
Aladdin eSafe Gateway versions 2.x allows a remote attacker to circumvent HTML SCRIPT filtering via a special arrangement of HTML tags which includes SCRIPT tags embedded within other SCRIPT tags.... Read more
Affected Products : esafe_gateway- EPSS Score: %2.71
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0616
Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (e.g., GET /aux HTTP/1.0).... Read more
Affected Products : freestyle_chat- EPSS Score: %7.89
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0570
minicom 1.83.1 and earlier allows a local attacker to gain additional privileges via numerous format string attacks.... Read more
Affected Products : minicom- EPSS Score: %0.05
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0574
Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot) in the URL.... Read more
Affected Products : mp3mystic- EPSS Score: %6.89
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0563
ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via large (> 160000 character) strings sent to port 23.... Read more
Affected Products : electrocomm- EPSS Score: %4.72
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0538
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.... Read more
Affected Products : outlook- EPSS Score: %68.32
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0526
Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable.... Read more
Affected Products : solaris- EPSS Score: %0.13
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0565
Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.... Read more
- EPSS Score: %0.18
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0628
Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.... Read more
Affected Products : word- EPSS Score: %2.10
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0530
Spearhead NetGAP 200 and 300 before build 78 allow a remote attacker to bypass file blocking and content inspection via specially encoded URLs which include '%' characters.... Read more
- EPSS Score: %0.50
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0548
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.... Read more
- EPSS Score: %0.12
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025