Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2001-0527

    DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.... Read more

    Affected Products : dcforum dcforum_2000
    • EPSS Score: %6.99
    • Published: Aug. 14, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0521

    Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.... Read more

    Affected Products : esafe_gateway
    • EPSS Score: %2.71
    • Published: Aug. 14, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0533

    Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.... Read more

    Affected Products : aix
    • EPSS Score: %0.07
    • Published: Aug. 14, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0520

    Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT... Read more

    Affected Products : esafe_gateway
    • EPSS Score: %2.71
    • Published: Aug. 14, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0615

    Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'.... Read more

    Affected Products : freestyle_chat
    • EPSS Score: %6.18
    • Published: Aug. 14, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0528

    Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain pri... Read more

    Affected Products : e-business_suite
    • EPSS Score: %0.45
    • Published: Aug. 14, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-0567

    Digital Creations Zope 2.3.2 and earlier allows a local attacker to gain additional privileges via the changing of ZClass permission mappings for objects and methods in the ZClass.... Read more

    Affected Products : zope
    • EPSS Score: %0.08
    • Published: Aug. 14, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0529

    OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.... Read more

    Affected Products : openssh
    • EPSS Score: %0.13
    • Published: Aug. 14, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0558

    T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0).... Read more

    Affected Products : jana_web_server
    • EPSS Score: %5.88
    • Published: Aug. 14, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0559

    crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.... Read more

    Affected Products : vixie_cron
    • EPSS Score: %0.19
    • Published: Aug. 14, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1113

    Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command.... Read more

    Affected Products : trollftpd
    • EPSS Score: %1.45
    • Published: Aug. 13, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1114

    book.cgi in NetCode NC Book 0.2b allows remote attackers to execute arbitrary commands via shell metacharacters in the "current" parameter.... Read more

    Affected Products : nc_book
    • EPSS Score: %2.82
    • Published: Aug. 13, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1292

    Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password.... Read more

    Affected Products : sambar_server
    • EPSS Score: %2.75
    • Published: Aug. 13, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1115

    generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.... Read more

    Affected Products : six-webboard
    • EPSS Score: %3.45
    • Published: Aug. 13, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1157

    Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using U... Read more

    Affected Products : websweeper
    • EPSS Score: %0.42
    • Published: Aug. 12, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1117

    LinkSys EtherFast BEFSR41 Cable/DSL routers running firmware before 1.39.3 Beta allows a remote attacker to view administration and user passwords by connecting to the router and viewing the HTML source for (1) index.htm and (2) Password.htm.... Read more

    Affected Products : befsr41
    • EPSS Score: %1.51
    • Published: Aug. 10, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1134

    Xerox DocuPrint N40 Printers allow remote attackers to cause a denial of service via malformed data, such as that produced by the Code Red worm.... Read more

    Affected Products : docuprint_n40
    • EPSS Score: %0.76
    • Published: Aug. 09, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1260

    Avaya Argent Office uses weak encryption (trivial encoding) for passwords, which allows remote attackers to gain administrator privileges by sniffing and decrypting the sniffing the passwords during a system reboot.... Read more

    Affected Products : argent_office
    • EPSS Score: %0.52
    • Published: Aug. 07, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1262

    Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string.... Read more

    Affected Products : argent_office
    • EPSS Score: %0.49
    • Published: Aug. 07, 2001
    • Modified: Apr. 03, 2025
  • 1.2

    LOW
    CVE-2001-1301

    rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.... Read more

    Affected Products : emacs xemacs
    • EPSS Score: %0.19
    • Published: Aug. 07, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 291219 Results