Latest CVE Feed
-
5.0
MEDIUMCVE-2001-0460
Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header.... Read more
Affected Products : websweeper- EPSS Score: %3.39
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0417
Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.... Read more
- EPSS Score: %0.11
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0425
AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to verify login information.... Read more
Affected Products : adcycle- EPSS Score: %4.59
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0246
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain... Read more
Affected Products : internet_explorer- EPSS Score: %18.80
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0334
FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.... Read more
Affected Products : internet_information_server- EPSS Score: %25.08
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0450
Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name.... Read more
Affected Products : broker_ftp_server- EPSS Score: %1.51
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0496
kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.... Read more
- EPSS Score: %0.07
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0473
Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.... Read more
- EPSS Score: %0.81
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0337
The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.... Read more
Affected Products : internet_information_server- EPSS Score: %4.62
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0241
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.... Read more
Affected Products : windows_2000- EPSS Score: %88.82
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0329
Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.... Read more
Affected Products : bugzilla- EPSS Score: %4.40
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0493
Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.... Read more
Affected Products : small_http_server- EPSS Score: %0.76
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2001-0361
Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a "Bleichenbacher attack" on PKCS#1 vers... Read more
- EPSS Score: %1.49
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1083
Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or \ (backward slash).... Read more
Affected Products : icecast- EPSS Score: %16.70
- Published: Jun. 26, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1324
cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain priv... Read more
Affected Products : idtools- EPSS Score: %0.07
- Published: Jun. 26, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1162
Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.... Read more
- EPSS Score: %30.17
- Published: Jun. 23, 2001
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2001-0906
teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produced when printing .dvi files using lpr.... Read more
Affected Products : tetex- EPSS Score: %0.22
- Published: Jun. 22, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1328
Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.... Read more
Affected Products : sunos- EPSS Score: %6.21
- Published: Jun. 22, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1078
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6... Read more
Affected Products : extremail- EPSS Score: %4.22
- Published: Jun. 21, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1276
ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file.... Read more
Affected Products : ispell- EPSS Score: %0.09
- Published: Jun. 21, 2001
- Modified: Apr. 03, 2025