Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2001-1157

    Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using U... Read more

    Affected Products : websweeper
    • EPSS Score: %0.42
    • Published: Aug. 12, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1117

    LinkSys EtherFast BEFSR41 Cable/DSL routers running firmware before 1.39.3 Beta allows a remote attacker to view administration and user passwords by connecting to the router and viewing the HTML source for (1) index.htm and (2) Password.htm.... Read more

    Affected Products : befsr41
    • EPSS Score: %1.51
    • Published: Aug. 10, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1134

    Xerox DocuPrint N40 Printers allow remote attackers to cause a denial of service via malformed data, such as that produced by the Code Red worm.... Read more

    Affected Products : docuprint_n40
    • EPSS Score: %0.76
    • Published: Aug. 09, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1260

    Avaya Argent Office uses weak encryption (trivial encoding) for passwords, which allows remote attackers to gain administrator privileges by sniffing and decrypting the sniffing the passwords during a system reboot.... Read more

    Affected Products : argent_office
    • EPSS Score: %0.52
    • Published: Aug. 07, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1262

    Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string.... Read more

    Affected Products : argent_office
    • EPSS Score: %0.49
    • Published: Aug. 07, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1261

    Avaya Argent Office 2.1 may allow remote attackers to change hold music by spoofing a legitimate server's response to a TFTP broadcast and providing an alternate HoldMusic file.... Read more

    Affected Products : argent_office
    • EPSS Score: %0.48
    • Published: Aug. 07, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1259

    Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload.... Read more

    Affected Products : argent_office
    • EPSS Score: %2.96
    • Published: Aug. 07, 2001
    • Modified: Apr. 03, 2025
  • 1.2

    LOW
    CVE-2001-1301

    rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.... Read more

    Affected Products : emacs xemacs
    • EPSS Score: %0.19
    • Published: Aug. 07, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0647

    Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version.... Read more

    Affected Products : orange_web_server
    • EPSS Score: %3.39
    • Published: Aug. 06, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1356

    NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.... Read more

    Affected Products : surgeftp
    • EPSS Score: %1.10
    • Published: Aug. 04, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-1472

    SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.... Read more

    Affected Products : phpbb
    • EPSS Score: %0.84
    • Published: Aug. 03, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1304

    Buffer overflow in SHOUTcast Server 1.8.2 allows remote attackers to cause a denial of service (crash) via several HTTP requests with a long (1) user-agent or (2) host HTTP header.... Read more

    Affected Products : shoutcast_server
    • EPSS Score: %0.62
    • Published: Aug. 03, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-1122

    Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode.... Read more

    Affected Products : windows_nt
    • EPSS Score: %0.30
    • Published: Aug. 03, 2001
    • Modified: Apr. 03, 2025
  • 6.2

    MEDIUM
    CVE-2001-1119

    cda in xmcd 3.0.2 and 2.6 in SuSE Linux allows local users to overwrite arbitrary files via a symlink attack.... Read more

    Affected Products : xmcd
    • EPSS Score: %0.08
    • Published: Aug. 03, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0603

    Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeatedly sending large (> 10Kb) amounts of data to the DIIOP - CORBA service on TCP port 63148.... Read more

    Affected Products : domino_r5_server
    • EPSS Score: %0.79
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0609

    Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.... Read more

    Affected Products : cfingerd
    • EPSS Score: %9.91
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0602

    Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeated (>400) URL requests for DOS devices.... Read more

    Affected Products : domino_r5_server
    • EPSS Score: %0.79
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0618

    Orinoco RG-1000 wireless Residential Gateway uses the last 5 digits of the 'Network Name' or SSID as the default Wired Equivalent Privacy (WEP) encryption key. Since the SSID occurs in the clear during communications, a remote attacker could determine th... Read more

    Affected Products : orinoco_rg-1000
    • EPSS Score: %0.41
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0601

    Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via HTTP requests containing certain combinations of UNICODE characters.... Read more

    Affected Products : domino_r5_server
    • EPSS Score: %0.79
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1118

    A module in Roxen 2.0 before 2.0.92, and 2.1 before 2.1.264, does not properly decode UTF-8, Mac and ISO-2202 encoded URLs, which could allow a remote attacker to execute arbitrary commands or view arbitrary files via an encoded URL.... Read more

    Affected Products : roxen_webserver
    • EPSS Score: %1.25
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 291205 Results