Latest CVE Feed
-
5.0
MEDIUMCVE-2001-0472
Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.... Read more
Affected Products : high_availability_cluster_multiprocessing- EPSS Score: %0.93
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0332
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain... Read more
Affected Products : internet_explorer- EPSS Score: %18.08
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0459
Buffer overflows in ascdc Afterstep while running setuid allows local users to gain root privileges via a long (1) -d option, (2) -m option, or (3) -f option.... Read more
- EPSS Score: %0.18
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0237
Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.... Read more
Affected Products : windows_2000- EPSS Score: %12.54
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0407
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).... Read more
Affected Products : mysql- EPSS Score: %0.71
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0493
Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.... Read more
Affected Products : small_http_server- EPSS Score: %0.76
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2001-0361
Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a "Bleichenbacher attack" on PKCS#1 vers... Read more
- EPSS Score: %1.49
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0329
Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.... Read more
Affected Products : bugzilla- EPSS Score: %4.40
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0367
Mirabilis ICQ WebFront Plug-in ICQ2000b Build 3278 allows a remote attacker to create a denial of service via HTTP URL requests containing a large number of % characters.... Read more
Affected Products : icq- EPSS Score: %0.63
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0494
Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header.... Read more
Affected Products : imail- EPSS Score: %0.56
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0331
Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows remote attackers to execute arbitrary commands.... Read more
Affected Products : irix- EPSS Score: %1.03
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0452
BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.... Read more
Affected Products : webweaver- EPSS Score: %3.45
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0330
Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.... Read more
Affected Products : bugzilla- EPSS Score: %0.85
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0243
Windows Media Player 7 and earlier stores Internet shortcuts in a user's Temporary Files folder with a fixed filename instead of in the Internet Explorer cache, which causes the HTML in those shortcuts to run in the Local Computer Zone instead of the Inte... Read more
Affected Products : windows_media_player- EPSS Score: %37.01
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0462
Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.... Read more
Affected Products : perl_web_server- EPSS Score: %4.09
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0381
The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters the encrypted private key file and captures a single message signed with the signature key.... Read more
Affected Products : openpgp- EPSS Score: %0.09
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0359
Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.... Read more
- EPSS Score: %1.84
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0365
Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options are enabled, via an HTML email message containing Javascript, with ActiveX controls and malicious code wi... Read more
Affected Products : eudora- EPSS Score: %4.82
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0492
Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3.... Read more
Affected Products : netcruiser_web_server- EPSS Score: %0.68
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0488
pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.... Read more
Affected Products : hp-ux- EPSS Score: %0.07
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025