Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.6

    MEDIUM
    CVE-2001-1345

    bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program.... Read more

    Affected Products : bestcrypt
    • EPSS Score: %0.06
    • Published: Jun. 05, 2001
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2001-0150

    Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services f... Read more

    Affected Products : internet_explorer
    • EPSS Score: %14.38
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0315

    The locking feature in mIRC 5.7 allows local users to bypass the password mechanism by modifying the LockOptions registry key.... Read more

    Affected Products : mirc
    • EPSS Score: %0.43
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0211

    Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.... Read more

    Affected Products : webspirs
    • EPSS Score: %3.05
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0146

    IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.... Read more

    • EPSS Score: %13.30
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0256

    FaSTream FTP++ Server 2.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long username.... Read more

    Affected Products : ftp\+\+_server
    • EPSS Score: %1.22
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0253

    Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.... Read more

    Affected Products : hyperseek
    • EPSS Score: %7.78
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0217

    Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.... Read more

    Affected Products : webpals
    • EPSS Score: %3.45
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0216

    PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName parameter.... Read more

    Affected Products : webpals
    • EPSS Score: %6.95
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1046

    Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain privileges via a long username.... Read more

    Affected Products : qpopper
    • EPSS Score: %0.96
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 3.6

    LOW
    CVE-2001-0259

    ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker can use to decrypt that user's private key file.... Read more

    Affected Products : ssh
    • EPSS Score: %0.27
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0215

    ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename with a null byte.... Read more

    Affected Products : roads
    • EPSS Score: %4.31
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0210

    Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page parameter.... Read more

    Affected Products : commerce.cgi
    • EPSS Score: %2.67
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0252

    iPlanet (formerly Netscape) Enterprise Server 4.1 allows remote attackers to cause a denial of service via a long HTTP GET request that contains many "/../" (dot dot) sequences.... Read more

    Affected Products : iplanet_enterprise_server
    • EPSS Score: %0.76
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0214

    Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.... Read more

    Affected Products : way-board
    • EPSS Score: %2.67
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 1.2

    LOW
    CVE-2001-1047

    Race condition in OpenBSD VFS allows local users to cause a denial of service (kernel panic) by (1) creating a pipe in one thread and causing another thread to set one of the file descriptors to NULL via a close, or (2) calling dup2 on a file descriptor i... Read more

    Affected Products : openbsd
    • EPSS Score: %0.07
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0322

    MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.... Read more

    • EPSS Score: %13.45
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0314

    Buffer overflow in www.tol module in America Online (AOL) 5.0 may allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL in a link.... Read more

    Affected Products : aol_server
    • EPSS Score: %1.23
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0220

    Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.... Read more

    Affected Products : ja-elvis ko-helvis
    • EPSS Score: %0.43
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0225

    fortran math component in Infobot 0.44.5.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.... Read more

    Affected Products : infobot
    • EPSS Score: %2.10
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 291258 Results