Latest CVE Feed
-
5.0
MEDIUMCVE-2001-0557
T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).... Read more
Affected Products : jana_web_server- EPSS Score: %12.65
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0549
Symantec LiveUpdate 1.5 stores proxy passwords in cleartext in a registry key, which could allow local users to obtain the passwords.... Read more
Affected Products : liveupdate- EPSS Score: %0.10
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1231
GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.... Read more
Affected Products : groupwise- EPSS Score: %1.66
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0570
minicom 1.83.1 and earlier allows a local attacker to gain additional privileges via numerous format string attacks.... Read more
Affected Products : minicom- EPSS Score: %0.05
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0529
OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.... Read more
Affected Products : openssh- EPSS Score: %0.13
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0567
Digital Creations Zope 2.3.2 and earlier allows a local attacker to gain additional privileges via the changing of ZClass permission mappings for objects and methods in the ZClass.... Read more
Affected Products : zope- EPSS Score: %0.08
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0554
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.... Read more
Affected Products : debian_linux aix solaris sunos freebsd netbsd kerberos_5 openbsd kerberos irix +2 more products- EPSS Score: %16.67
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0553
SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field.... Read more
Affected Products : secure_shell- EPSS Score: %0.22
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1292
Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password.... Read more
Affected Products : sambar_server- EPSS Score: %2.75
- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1114
book.cgi in NetCode NC Book 0.2b allows remote attackers to execute arbitrary commands via shell metacharacters in the "current" parameter.... Read more
Affected Products : nc_book- EPSS Score: %2.82
- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1115
generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.... Read more
Affected Products : six-webboard- EPSS Score: %3.45
- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1113
Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command.... Read more
Affected Products : trollftpd- EPSS Score: %1.45
- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1157
Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using U... Read more
Affected Products : websweeper- EPSS Score: %0.42
- Published: Aug. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1117
LinkSys EtherFast BEFSR41 Cable/DSL routers running firmware before 1.39.3 Beta allows a remote attacker to view administration and user passwords by connecting to the router and viewing the HTML source for (1) index.htm and (2) Password.htm.... Read more
Affected Products : befsr41- EPSS Score: %1.51
- Published: Aug. 10, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1134
Xerox DocuPrint N40 Printers allow remote attackers to cause a denial of service via malformed data, such as that produced by the Code Red worm.... Read more
Affected Products : docuprint_n40- EPSS Score: %0.76
- Published: Aug. 09, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1260
Avaya Argent Office uses weak encryption (trivial encoding) for passwords, which allows remote attackers to gain administrator privileges by sniffing and decrypting the sniffing the passwords during a system reboot.... Read more
Affected Products : argent_office- EPSS Score: %0.52
- Published: Aug. 07, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1301
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.... Read more
- EPSS Score: %0.19
- Published: Aug. 07, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1262
Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string.... Read more
Affected Products : argent_office- EPSS Score: %0.49
- Published: Aug. 07, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1259
Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload.... Read more
Affected Products : argent_office- EPSS Score: %2.96
- Published: Aug. 07, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1261
Avaya Argent Office 2.1 may allow remote attackers to change hold music by spoofing a legitimate server's response to a TFTP broadcast and providing an alternate HoldMusic file.... Read more
Affected Products : argent_office- EPSS Score: %0.48
- Published: Aug. 07, 2001
- Modified: Apr. 03, 2025