Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2001-1080

    diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.... Read more

    Affected Products : aix
    • EPSS Score: %3.41
    • Published: Jun. 19, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1459

    OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.... Read more

    Affected Products : openssh
    • EPSS Score: %0.56
    • Published: Jun. 19, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0414

    Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.... Read more

    Affected Products : ntpd xntp3
    • EPSS Score: %87.30
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-0465

    TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive information.... Read more

    Affected Products : turbo_tax
    • EPSS Score: %0.08
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 6.2

    MEDIUM
    CVE-2001-0371

    Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted informatio... Read more

    Affected Products : freebsd
    • EPSS Score: %0.05
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0392

    Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.... Read more

    Affected Products : financials_server
    • EPSS Score: %0.66
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0446

    IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.... Read more

    Affected Products : websphere_commerce_suite
    • EPSS Score: %0.56
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0399

    Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.... Read more

    Affected Products : resin
    • EPSS Score: %3.05
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0375

    Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests.... Read more

    Affected Products : pix_firewall_515 pix_firewall_520
    • EPSS Score: %16.08
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0433

    Buffer overflow in Savant 3.0 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Host HTTP header.... Read more

    Affected Products : savant_webserver
    • EPSS Score: %0.99
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0404

    Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.... Read more

    Affected Products : javaserver_web_dev_kit
    • EPSS Score: %0.58
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0420

    Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.... Read more

    Affected Products : talkback
    • EPSS Score: %0.67
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0374

    The HTTP server in Compaq web-enabled management software for (1) Foundation Agents, (2) Survey, (3) Power Manager, (4) Availability Agents, (5) Intelligent Cluster Administrator, and (6) Insight Manager can be used as a generic proxy server, which allows... Read more

    Affected Products : web-enabled_management
    • EPSS Score: %0.35
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2001-0408

    vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when another user opens a file containing malicious VIM control codes.... Read more

    Affected Products : linux vim
    • EPSS Score: %0.70
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0249

    Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.... Read more

    Affected Products : solaris hp-ux solaris irix
    • EPSS Score: %3.99
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0247

    Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions g... Read more

    Affected Products : freebsd netbsd kerberos_5 openbsd irix
    • EPSS Score: %35.17
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0466

    Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.... Read more

    • EPSS Score: %3.62
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 7.1

    HIGH
    CVE-2001-0427

    Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed... Read more

    • EPSS Score: %0.86
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0413

    BinTec X4000 Access router, and possibly other versions, allows remote attackers to cause a denial of service via a SYN port scan, which causes the router to hang.... Read more

    Affected Products : x1000 x1200 x4000
    • EPSS Score: %0.91
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0402

    IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted ... Read more

    Affected Products : freebsd openbsd ipfilter
    • EPSS Score: %3.36
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 291058 Results