Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2001-1321

    Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.... Read more

    Affected Products : internet_directory
    • EPSS Score: %5.25
    • Published: Jul. 16, 2001
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2001-1238

    Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot... Read more

    Affected Products : windows_2000
    • EPSS Score: %0.80
    • Published: Jul. 16, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1315

    Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.... Read more

    • EPSS Score: %11.26
    • Published: Jul. 16, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1306

    iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite.... Read more

    Affected Products : iplanet_directory_server
    • EPSS Score: %8.06
    • Published: Jul. 16, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0975

    Buffer overflow vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.... Read more

    Affected Products : internet_directory
    • EPSS Score: %7.16
    • Published: Jul. 16, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1308

    Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.... Read more

    Affected Products : iplanet_directory_server
    • EPSS Score: %17.52
    • Published: Jul. 16, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-1181

    Dynamically Loadable Kernel Module (dlkm) static kernel symbol table in HP-UX 11.11 is not properly configured, which allows local users to gain privileges.... Read more

    Affected Products : hp-ux
    • EPSS Score: %0.05
    • Published: Jul. 16, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1319

    Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.... Read more

    Affected Products : exchange_server
    • EPSS Score: %16.96
    • Published: Jul. 16, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1314

    Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.... Read more

    • EPSS Score: %13.08
    • Published: Jul. 16, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1053

    AdLogin.pm in AdCycle 1.15 and earlier allows remote attackers to bypass authentication and gain privileges by injecting SQL code in the $password argument.... Read more

    Affected Products : adcycle
    • EPSS Score: %0.46
    • Published: Jul. 13, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1082

    Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack.... Read more

    Affected Products : radius radius
    • EPSS Score: %0.58
    • Published: Jul. 13, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1291

    The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.... Read more

    • EPSS Score: %9.89
    • Published: Jul. 12, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1142

    ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the password file to gain privileges.... Read more

    Affected Products : ftp_server
    • EPSS Score: %1.79
    • Published: Jul. 12, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1176

    Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via format strings in the control connection.... Read more

    • EPSS Score: %2.31
    • Published: Jul. 12, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1183

    PPTP implementation in Cisco IOS 12.1 and 12.2 allows remote attackers to cause a denial of service (crash) via a malformed packet.... Read more

    Affected Products : ios
    • EPSS Score: %0.24
    • Published: Jul. 12, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-1267

    Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).... Read more

    Affected Products : tar
    • EPSS Score: %0.12
    • Published: Jul. 12, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-1268

    Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename.... Read more

    Affected Products : unzip
    • EPSS Score: %0.34
    • Published: Jul. 12, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-1269

    Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that begin with the '/' (slash) character.... Read more

    Affected Products : unzip
    • EPSS Score: %0.14
    • Published: Jul. 12, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-1271

    Directory traversal vulnerability in rar 2.02 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) attack on archived filenames.... Read more

    Affected Products : rar
    • EPSS Score: %0.14
    • Published: Jul. 12, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-1270

    Directory traversal vulnerability in the console version of PKZip (pkzipc) 4.00 and earlier allows attackers to overwrite arbitrary files during archive extraction with the -rec (recursive) option via a .. (dot dot) attack on the archived files.... Read more

    Affected Products : pkzip
    • EPSS Score: %0.14
    • Published: Jul. 12, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 291129 Results