Latest CVE Feed
-
10.0
HIGHCVE-2001-0968
Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges.... Read more
Affected Products : arkeia- EPSS Score: %0.95
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0972
Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."... Read more
Affected Products : asp_forum- EPSS Score: %0.93
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1004
Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name contains the script tags.... Read more
Affected Products : gnutella_client- EPSS Score: %0.41
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1007
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly guess the key via a brute force attack.... Read more
Affected Products : truesync_desktop- EPSS Score: %0.48
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1069
libCoolType library as used in Adobe Acrobat (acroread) on Linux creates the AdobeFnt.lst file with world-writable permissions, which allows local users to modify the file and possibly modify acroread's behavior.... Read more
Affected Products : acrobat_reader- EPSS Score: %0.09
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2000-1198
qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.... Read more
Affected Products : qpopper- EPSS Score: %0.26
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1192
Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap.... Read more
Affected Products : snmp_trap_watcher- EPSS Score: %2.28
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1061
Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.... Read more
Affected Products : aix- EPSS Score: %0.56
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1194
Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.... Read more
Affected Products : ftp_server- EPSS Score: %2.91
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1027
Buffer overflow in WindowMaker (aka wmaker) 0.64 and earlier allows remote attackers to execute arbitrary code via a long window title.... Read more
Affected Products : windowmaker- EPSS Score: %23.72
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1154
Cyrus 2.0.15, 2.0.16, and 1.6.24 on BSDi 4.2, with IMAP enabled, allows remote attackers to cause a denial of service (hang) using PHP IMAP clients.... Read more
- EPSS Score: %0.74
- Published: Aug. 30, 2001
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2001-0682
ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.... Read more
- EPSS Score: %0.13
- Published: Aug. 29, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1168
Directory traversal vulnerability in index.php in PhpMyExplorer before 1.2.1 allows remote attackers to read arbitrary files via a ..%2F (modified dot dot) in the chemin parameter.... Read more
- EPSS Score: %0.49
- Published: Aug. 29, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1389
Multiple vulnerabilities in xinetd 2.3.0 and earlier, and additional variants until 2.3.3, may allow remote attackers to cause a denial of service or execute arbitrary code, primarily via buffer overflows or improper NULL termination.... Read more
- EPSS Score: %2.44
- Published: Aug. 29, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1379
The PostgreSQL authentication modules (1) mod_auth_pgsql 0.9.5, and (2) mod_auth_pgsql_sys 0.9.4, allow remote attackers to bypass authentication and execute arbitrary SQL via a SQL injection attack on the user name.... Read more
Affected Products : mod_auth_pgsql- EPSS Score: %1.72
- Published: Aug. 29, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1153
lpsystem in OpenUnix 8.0.0 allows local users to cause a denial of service and possibly execute arbitrary code via a long command line argument.... Read more
Affected Products : openunix- EPSS Score: %0.05
- Published: Aug. 28, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1443
KTH Kerberos IV and Kerberos V (Heimdal) for Telnet clients do not encrypt connections if the server does not support the requested encryption, which allows remote attackers to read communications via a man-in-the-middle attack.... Read more
Affected Products : kth_kerberos- EPSS Score: %0.70
- Published: Aug. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1444
The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption options sent from the server, which allows remote attackers to downgrade authentication and encryption mechanisms via ... Read more
Affected Products : kth_kerberos- EPSS Score: %0.68
- Published: Aug. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1455
Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters.... Read more
Affected Products : siteminder- EPSS Score: %0.76
- Published: Aug. 24, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1091
The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.... Read more
Affected Products : netbsd- EPSS Score: %0.06
- Published: Aug. 23, 2001
- Modified: Apr. 03, 2025