Latest CVE Feed
-
7.5
HIGHCVE-2001-0826
Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD.... Read more
Affected Products : cesarftp- EPSS Score: %1.15
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2001-0829
A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.... Read more
Affected Products : tomcat- EPSS Score: %0.73
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0838
Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.... Read more
Affected Products : rwhoisd- EPSS Score: %4.45
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0849
viralator CGI script in Viralator 0.9pre1 and earlier allows remote attackers to execute arbitrary code via a URL for a file being downloaded, which is insecurely passed to a call to wget.... Read more
Affected Products : viralator- EPSS Score: %1.98
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0851
Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie.... Read more
Affected Products : linux_kernel suse_linux linux openlinux openlinux_edesktop openlinux_eserver openlinux_server openlinux_workstation- EPSS Score: %0.62
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0854
PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of ... Read more
Affected Products : php-nuke- EPSS Score: %0.02
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0839
ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing.... Read more
Affected Products : processing_plus- EPSS Score: %3.06
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0864
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions.... Read more
Affected Products : 12000_router- EPSS Score: %0.60
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0861
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic that generates a large number of ICMP Unreachable replies.... Read more
- EPSS Score: %0.91
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0835
Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retriev... Read more
Affected Products : webalizer- EPSS Score: %4.69
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0809
Vulnerability in CIFS/9000 Server (SAMBA) A.01.06 and earlier in HP-UX 11.0 and 11.11, when configured as a print server, allows local users to overwrite arbitrary files by modifying certain resources.... Read more
Affected Products : hp-ux- EPSS Score: %0.27
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0816
OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypass authorized_keys2 command= restrictions using sftp commands.... Read more
Affected Products : openssh- EPSS Score: %0.23
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0947
Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path.... Read more
Affected Products : enterprise_validation_authority- EPSS Score: %0.74
- Published: Dec. 04, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0950
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of an... Read more
Affected Products : enterprise_validation_authority- EPSS Score: %1.63
- Published: Dec. 04, 2001
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2001-0946
apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification dates of arbitrary files via a symlink attack on the LOW_POWER temporary file, which could be used to cause a denial of service, e.g. by creating /etc/nologi... Read more
Affected Products : linux- EPSS Score: %0.04
- Published: Dec. 04, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0948
Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which... Read more
Affected Products : enterprise_validation_authority- EPSS Score: %1.82
- Published: Dec. 04, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0949
Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) ... Read more
Affected Products : enterprise_validation_authority- EPSS Score: %5.68
- Published: Dec. 04, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0945
Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line.... Read more
Affected Products : outlook_express- EPSS Score: %17.85
- Published: Dec. 03, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0944
DDE in mIRC allows local users to launch applications under another user's account via a DDE message that executes a command, which may be executed by the other user's process.... Read more
Affected Products : mirc- EPSS Score: %0.06
- Published: Dec. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1437
easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out.... Read more
Affected Products : easynews- EPSS Score: %1.04
- Published: Dec. 01, 2001
- Modified: Apr. 03, 2025