Latest CVE Feed
-
7.5
HIGHCVE-2001-0374
The HTTP server in Compaq web-enabled management software for (1) Foundation Agents, (2) Survey, (3) Power Manager, (4) Availability Agents, (5) Intelligent Cluster Administrator, and (6) Insight Manager can be used as a generic proxy server, which allows... Read more
Affected Products : web-enabled_management- EPSS Score: %0.35
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0247
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions g... Read more
- EPSS Score: %35.17
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0249
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.... Read more
- EPSS Score: %3.99
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2001-0408
vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when another user opens a file containing malicious VIM control codes.... Read more
- EPSS Score: %0.70
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0420
Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.... Read more
Affected Products : talkback- EPSS Score: %0.67
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2001-0427
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed... Read more
- EPSS Score: %0.86
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0466
Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.... Read more
Affected Products : ustorekeeper_online_shopping_system- EPSS Score: %3.62
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0465
TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive information.... Read more
Affected Products : turbo_tax- EPSS Score: %0.08
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0448
Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.... Read more
Affected Products : 602pro_lan_suite- EPSS Score: %0.58
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0372
Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.... Read more
Affected Products : akopia_interchange- EPSS Score: %1.55
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1160
udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the category_file field.... Read more
Affected Products : udirectory- EPSS Score: %9.14
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0412
Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode.... Read more
Affected Products : content_services_switch_11050 content_services_switch_11150 content_services_switch_11800- EPSS Score: %0.07
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0373
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.... Read more
- EPSS Score: %1.26
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0377
Infradig Inframail prior to 3.98a allows a remote attacker to create a denial of service via a malformed POST request which includes a space followed by a large string.... Read more
Affected Products : inframail- EPSS Score: %0.74
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0379
Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.... Read more
Affected Products : hp-ux- EPSS Score: %0.11
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0393
Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.... Read more
Affected Products : financials_server- EPSS Score: %0.66
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0397
Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.... Read more
Affected Products : silent_runner_collector_src- EPSS Score: %0.99
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0403
/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.... Read more
Affected Products : sunos- EPSS Score: %0.15
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0383
banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication.... Read more
Affected Products : php-nuke- EPSS Score: %0.06
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0409
vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory.... Read more
Affected Products : vim- EPSS Score: %0.16
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025