Latest CVE Feed
-
4.6
MEDIUMCVE-2001-0831
Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.... Read more
Affected Products : database_server- EPSS Score: %0.30
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0825
Buffer overflow in internal string handling routines of xinetd before 2.1.8.8 allows remote attackers to execute arbitrary commands via a length argument of zero or less, which disables the length check.... Read more
- EPSS Score: %3.08
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0821
The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt.... Read more
Affected Products : dcshop- EPSS Score: %11.73
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0720
Internet Explorer 5.1 for Macintosh on Mac OS X allows remote attackers to execute arbitrary commands by causing a BinHex or MacBinary file type to be downloaded, which causes the files to be executed if automatic decoding is enabled.... Read more
Affected Products : mac_os_x- EPSS Score: %1.01
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0663
Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.... Read more
- EPSS Score: %23.05
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0852
TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header.... Read more
Affected Products : linux- EPSS Score: %6.94
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0859
2.4.3-12 kernel in Red Hat Linux 7.1 Korean installation program sets the setting default umask for init to 000, which installs files with world-writeable permissions.... Read more
Affected Products : linux- EPSS Score: %0.47
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0800
lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.... Read more
Affected Products : irix- EPSS Score: %78.03
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0726
Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail mess... Read more
Affected Products : exchange_server- EPSS Score: %9.90
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0842
Directory traversal vulnerability in Search.cgi in Leoboard LB5000 LB5000II 1029 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.... Read more
Affected Products : lb5000- EPSS Score: %1.96
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2001-0806
Apple MacOS X 10.0 and 10.1 allow a local user to read and write to a user's desktop folder via insecure default permissions for the Desktop when it is created in some languages.... Read more
Affected Products : mac_os_x- EPSS Score: %0.08
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0823
The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCP_LOG_DIR).... Read more
Affected Products : performance_co-pilot- EPSS Score: %0.24
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0853
Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) AboutBox.gas.bat.... Read more
Affected Products : getaccess- EPSS Score: %3.87
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0862
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL.... Read more
Affected Products : 12000_router- EPSS Score: %0.45
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0843
Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request.... Read more
Affected Products : squid_web_proxy- EPSS Score: %24.97
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0835
Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retriev... Read more
Affected Products : webalizer- EPSS Score: %4.69
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0861
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic that generates a large number of ICMP Unreachable replies.... Read more
- EPSS Score: %0.91
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0860
Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Addre... Read more
- EPSS Score: %9.10
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0845
Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources.... Read more
- EPSS Score: %0.07
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0844
Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter.... Read more
- EPSS Score: %2.31
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025