Latest CVE Feed
-
7.2
HIGHCVE-2001-0507
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.... Read more
- EPSS Score: %1.15
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0680
Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a "dot dot" attack in a LIST (ls) command.... Read more
- EPSS Score: %84.83
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0508
Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.... Read more
- EPSS Score: %19.92
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0650
Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute.... Read more
Affected Products : ios- EPSS Score: %1.31
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0690
Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers.... Read more
- EPSS Score: %19.93
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0691
Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.... Read more
Affected Products : imapd- EPSS Score: %0.10
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1018
Lotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that contains a long sequence of / (slash) characters.... Read more
Affected Products : domino- EPSS Score: %0.63
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0693
WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).... Read more
- EPSS Score: %3.78
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0688
Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command.... Read more
Affected Products : broker_ftp_server- EPSS Score: %2.96
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0659
Buffer overflow in IrDA driver providing infrared data exchange on Windows 2000 allows attackers who are physically close to the machine to cause a denial of service (reboot) via a malformed IrDA packet.... Read more
Affected Products : windows_2000- EPSS Score: %14.41
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0681
Buffer overflow in ftpd in QPC QVT/Net 5.0 and QVT/Term 5.0 allows a remote attacker to cause a denial of service via a long (1) username or (2) password.... Read more
- EPSS Score: %0.71
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0687
Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS command, (2) specifying arbitrary paths in the UNC format (\\computername\sh... Read more
Affected Products : broker_ftp_server- EPSS Score: %0.81
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0642
Directory traversal vulnerability in IncrediMail version 1400185 and earlier allows local users to overwrite files on the local hard drive by appending .. (dot dot) sequences to filenames listed in the content.ini file.... Read more
Affected Products : incredimail- EPSS Score: %0.12
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0704
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist.... Read more
Affected Products : arcadia_internet_store- EPSS Score: %3.06
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0645
Symantec/AXENT NetProwler 3.5.x contains several default passwords, which could allow remote attackers to (1) access to the management tier via the "admin" password, or (2) connect to a MySQL ODBC from the management tier using a blank password.... Read more
Affected Products : netprowler- EPSS Score: %1.34
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0709
Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode.... Read more
Affected Products : internet_information_server- EPSS Score: %26.03
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0705
Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument.... Read more
Affected Products : arcadia_internet_store- EPSS Score: %3.45
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0703
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with an MS-DOS device name in the template parameter.... Read more
Affected Products : arcadia_internet_store- EPSS Score: %4.72
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0694
Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.... Read more
Affected Products : wftpd- EPSS Score: %3.02
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0692
SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and 4.6 allows a remote attacker to bypass firewall filtering via a base64 MIME encoded email attachment whose boundary name ends in two dashes.... Read more
- EPSS Score: %0.43
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025