Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.2

    HIGH
    CVE-2001-1173

    Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases.... Read more

    Affected Products : masqmail
    • EPSS Score: %0.05
    • Published: Jul. 26, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1021

    Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD.... Read more

    Affected Products : ws_ftp_server
    • EPSS Score: %84.42
    • Published: Jul. 26, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1106

    The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the samba... Read more

    Affected Products : sambar_server
    • EPSS Score: %1.46
    • Published: Jul. 25, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1011

    index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID parameter and providing the appropriate administrator information in other parameters.... Read more

    Affected Products : mambo_site_server
    • EPSS Score: %1.70
    • Published: Jul. 25, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1104

    SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions.... Read more

    Affected Products : soho_firmware soho
    • EPSS Score: %4.35
    • Published: Jul. 25, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0991

    Cross-site scripting vulnerability in Proxomitron Naoko-4 BetaFour and earlier allows remote attackers to execute arbitrary script on other clients via an incorrect URL containing the malicious script, which is printed back in an error message.... Read more

    Affected Products : proxomitron_naoko-4
    • EPSS Score: %16.58
    • Published: Jul. 24, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1097

    Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.... Read more

    Affected Products : ios
    • EPSS Score: %9.84
    • Published: Jul. 24, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-0993

    sendmsg function in NetBSD 1.3 through 1.5 allows local users to cause a denial of service (kernel trap or panic) via a msghdr structure with a large msg_controllen length.... Read more

    Affected Products : netbsd
    • EPSS Score: %0.06
    • Published: Jul. 24, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0988

    Arkeia backup server 4.2.8-2 and earlier creates its database files with world-writable permissions, which could allow local users to overwrite the files or obtain sensitive information.... Read more

    Affected Products : arkeia
    • EPSS Score: %0.04
    • Published: Jul. 23, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0989

    Buffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or (2) a long callsign.... Read more

    Affected Products : pileup
    • EPSS Score: %0.34
    • Published: Jul. 23, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0982

    Directory traversal vulnerability in IBM Tivoli WebSEAL Policy Director 3.01 through 3.7.1 allows remote attackers to read arbitrary files or directories via encoded .. (dot dot) sequences containing "%2e" strings.... Read more

    Affected Products : tivoli_secureway_policy_director
    • EPSS Score: %2.76
    • Published: Jul. 23, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0987

    Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by causing the Javascript to be inserted into error messages that are generated by CGIWrap.... Read more

    Affected Products : cgiwrap
    • EPSS Score: %9.55
    • Published: Jul. 22, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1010

    Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) attack on the page parameter.... Read more

    Affected Products : sambar_server
    • EPSS Score: %5.05
    • Published: Jul. 22, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0002

    Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.... Read more

    • EPSS Score: %25.60
    • Published: Jul. 21, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0340

    An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is execu... Read more

    Affected Products : exchange_server
    • EPSS Score: %6.26
    • Published: Jul. 21, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0499

    Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.... Read more

    Affected Products : database_server oracle8i
    • EPSS Score: %74.94
    • Published: Jul. 21, 2001
    • Modified: Apr. 03, 2025
  • 9.3

    HIGH
    CVE-2001-0537

    HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.... Read more

    Affected Products : ios
    • EPSS Score: %93.45
    • Published: Jul. 21, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0353

    Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine.... Read more

    Affected Products : solaris sunos
    • EPSS Score: %1.48
    • Published: Jul. 21, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0500

    Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query... Read more

    • EPSS Score: %91.04
    • Published: Jul. 21, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-0502

    Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login passw... Read more

    Affected Products : windows_2000
    • EPSS Score: %0.96
    • Published: Jul. 21, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 291255 Results