Latest CVE Feed
-
7.5
HIGHCVE-2001-0521
Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.... Read more
Affected Products : esafe_gateway- EPSS Score: %2.71
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0533
Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.... Read more
Affected Products : aix- EPSS Score: %0.07
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0528
Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain pri... Read more
Affected Products : e-business_suite- EPSS Score: %0.45
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0527
DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.... Read more
- EPSS Score: %6.99
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0520
Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT... Read more
Affected Products : esafe_gateway- EPSS Score: %2.71
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0559
crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.... Read more
Affected Products : vixie_cron- EPSS Score: %0.19
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1114
book.cgi in NetCode NC Book 0.2b allows remote attackers to execute arbitrary commands via shell metacharacters in the "current" parameter.... Read more
Affected Products : nc_book- EPSS Score: %2.82
- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1113
Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command.... Read more
Affected Products : trollftpd- EPSS Score: %1.45
- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1115
generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.... Read more
Affected Products : six-webboard- EPSS Score: %3.45
- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1292
Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password.... Read more
Affected Products : sambar_server- EPSS Score: %2.75
- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1157
Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using U... Read more
Affected Products : websweeper- EPSS Score: %0.42
- Published: Aug. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1117
LinkSys EtherFast BEFSR41 Cable/DSL routers running firmware before 1.39.3 Beta allows a remote attacker to view administration and user passwords by connecting to the router and viewing the HTML source for (1) index.htm and (2) Password.htm.... Read more
Affected Products : befsr41- EPSS Score: %1.51
- Published: Aug. 10, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1134
Xerox DocuPrint N40 Printers allow remote attackers to cause a denial of service via malformed data, such as that produced by the Code Red worm.... Read more
Affected Products : docuprint_n40- EPSS Score: %0.76
- Published: Aug. 09, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1260
Avaya Argent Office uses weak encryption (trivial encoding) for passwords, which allows remote attackers to gain administrator privileges by sniffing and decrypting the sniffing the passwords during a system reboot.... Read more
Affected Products : argent_office- EPSS Score: %0.52
- Published: Aug. 07, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1301
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.... Read more
- EPSS Score: %0.19
- Published: Aug. 07, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1259
Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload.... Read more
Affected Products : argent_office- EPSS Score: %2.96
- Published: Aug. 07, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1261
Avaya Argent Office 2.1 may allow remote attackers to change hold music by spoofing a legitimate server's response to a TFTP broadcast and providing an alternate HoldMusic file.... Read more
Affected Products : argent_office- EPSS Score: %0.48
- Published: Aug. 07, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1262
Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string.... Read more
Affected Products : argent_office- EPSS Score: %0.49
- Published: Aug. 07, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0647
Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version.... Read more
Affected Products : orange_web_server- EPSS Score: %3.39
- Published: Aug. 06, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1356
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.... Read more
Affected Products : surgeftp- EPSS Score: %1.10
- Published: Aug. 04, 2001
- Modified: Apr. 03, 2025