Latest CVE Feed
-
7.5
HIGHCVE-2001-0410
Buffer overflow in Trend Micro Virus Buster 2001 8.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long "From" header.... Read more
Affected Products : virus_buster_2001- EPSS Score: %0.99
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0403
/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.... Read more
Affected Products : sunos- EPSS Score: %0.15
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0383
banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication.... Read more
Affected Products : php-nuke- EPSS Score: %0.06
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0379
Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.... Read more
Affected Products : hp-ux- EPSS Score: %0.11
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0409
vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory.... Read more
Affected Products : vim- EPSS Score: %0.16
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1160
udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the category_file field.... Read more
Affected Products : udirectory- EPSS Score: %9.14
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0393
Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.... Read more
Affected Products : financials_server- EPSS Score: %0.66
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0373
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.... Read more
- EPSS Score: %1.26
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0248
Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.... Read more
- EPSS Score: %5.32
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0465
TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive information.... Read more
Affected Products : turbo_tax- EPSS Score: %0.08
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0398
The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT! to misrepresent the attachment's type with ... Read more
Affected Products : the_bat- EPSS Score: %1.05
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0380
Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented community string 'ILMI'.... Read more
Affected Products : xlt-f- EPSS Score: %3.22
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0372
Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.... Read more
Affected Products : akopia_interchange- EPSS Score: %1.55
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0448
Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.... Read more
Affected Products : 602pro_lan_suite- EPSS Score: %0.58
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0375
Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests.... Read more
- EPSS Score: %16.08
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2001-0371
Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted informatio... Read more
Affected Products : freebsd- EPSS Score: %0.05
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0399
Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.... Read more
Affected Products : resin- EPSS Score: %3.05
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0446
IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.... Read more
Affected Products : websphere_commerce_suite- EPSS Score: %0.56
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0392
Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.... Read more
Affected Products : financials_server- EPSS Score: %0.66
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0404
Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.... Read more
Affected Products : javaserver_web_dev_kit- EPSS Score: %0.58
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025