Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2001-0659

    Buffer overflow in IrDA driver providing infrared data exchange on Windows 2000 allows attackers who are physically close to the machine to cause a denial of service (reboot) via a malformed IrDA packet.... Read more

    Affected Products : windows_2000
    • EPSS Score: %14.41
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0700

    Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header.... Read more

    Affected Products : w3m w3m
    • EPSS Score: %13.31
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-0642

    Directory traversal vulnerability in IncrediMail version 1400185 and earlier allows local users to overwrite files on the local hard drive by appending .. (dot dot) sequences to filenames listed in the content.ini file.... Read more

    Affected Products : incredimail
    • EPSS Score: %0.12
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0687

    Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS command, (2) specifying arbitrary paths in the UNC format (\\computername\sh... Read more

    Affected Products : broker_ftp_server
    • EPSS Score: %0.81
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-1029

    libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alterna... Read more

    Affected Products : openssh freebsd
    • EPSS Score: %0.13
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0674

    Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a hexadecimal encoded dot-dot attack (eg. http://www.server.com/%2e%2e/%2e%2e) in an HTTP URL request.... Read more

    Affected Products : viking_server
    • EPSS Score: %0.46
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0702

    Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) password, or (3) PASV command.... Read more

    • EPSS Score: %9.14
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0677

    Eudora 5.0.2 allows a remote attacker to read arbitrary files via an email with the path of the target file in the "Attachment Converted" MIME header, which sends the file when the email is forwarded to the attacker by the user.... Read more

    Affected Products : eudora
    • EPSS Score: %0.98
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0704

    tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist.... Read more

    Affected Products : arcadia_internet_store
    • EPSS Score: %3.06
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0680

    Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a "dot dot" attack in a LIST (ls) command.... Read more

    Affected Products : qvt_net avt_term
    • EPSS Score: %84.83
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0508

    Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.... Read more

    Affected Products : internet_information_services iis
    • EPSS Score: %19.92
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0690

    Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers.... Read more

    Affected Products : debian_linux exim linux linux exim
    • EPSS Score: %19.93
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-0691

    Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.... Read more

    Affected Products : imapd
    • EPSS Score: %0.10
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0650

    Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute.... Read more

    Affected Products : ios
    • EPSS Score: %1.31
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0707

    Denicomp RSHD 2.18 and earlier allows a remote attacker to cause a denial of service (crash) via a long string to port 514.... Read more

    Affected Products : rshd
    • EPSS Score: %0.66
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0689

    Vulnerability in TrendMicro Virus Control System 1.8 allows a remote attacker to view configuration files and change the configuration via a certain CGI program.... Read more

    Affected Products : virus_control_system
    • EPSS Score: %0.64
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0658

    Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly... Read more

    Affected Products : isa_server
    • EPSS Score: %11.67
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0636

    Buffer overflows in Raytheon SilentRunner allow remote attackers to (1) cause a denial of service in the collector (cle.exe) component of SilentRunner 2.0 via traffic containing long passwords, or (2) execute arbitrary commands via long HTTP queries in th... Read more

    Affected Products : silentrunner
    • EPSS Score: %0.99
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-0686

    Buffer overflow in mail included with SunOS 5.8 for x86 allows a local user to gain privileges via a long HOME environment variable.... Read more

    Affected Products : solaris
    • EPSS Score: %0.13
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-0706

    Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies a large number of sub-folders.... Read more

    Affected Products : rumpus_ftp_server
    • EPSS Score: %0.88
    • Published: Sep. 20, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 291558 Results