Latest CVE Feed
-
7.5
HIGHCVE-2001-0535
Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variab... Read more
Affected Products : coldfusion_server- EPSS Score: %0.75
- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0923
RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried.... Read more
Affected Products : redhat_package_manager- EPSS Score: %0.07
- Published: Oct. 25, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1462
WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information.... Read more
Affected Products : securid- EPSS Score: %0.82
- Published: Oct. 24, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1461
Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to access restricted resources via URL-encoded (1) /.. or (2) \.. sequences.... Read more
Affected Products : securid- EPSS Score: %0.53
- Published: Oct. 22, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1438
Handspring Visor 1.0 and 1.0.1 with the VisorPhone Springboard module installed allows remote attackers to cause a denial of service (PalmOS crash and VisorPhone database corruption) by sending a large or crafted SMS image.... Read more
- EPSS Score: %1.04
- Published: Oct. 22, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0743
Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followed by JavaScript commands.... Read more
Affected Products : webboard- EPSS Score: %2.96
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0765
BisonFTP V4R1 allows local users to access directories outside of their home directory by uploading .bdl files, which can then be linked to other directories.... Read more
Affected Products : bison_ftp_server- EPSS Score: %0.08
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0777
Omnicron OmniHTTPd 2.0.8 allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests for PHP scripts.... Read more
Affected Products : omnihttpd- EPSS Score: %0.89
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0737
A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle attack.... Read more
Affected Products : cordless_freedom cordless_freedom_navigator cordless_freedom_pro cordless_itouch_keyboard- EPSS Score: %0.89
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0745
Netscape 4.7x allows remote attackers to obtain sensitive information such as the user's login, mailbox location and installation path via Javascript that accesses the mailbox: URL in the document.referrer property.... Read more
Affected Products : messanger- EPSS Score: %1.08
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0744
Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file.... Read more
Affected Products : imp- EPSS Score: %0.09
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0784
Directory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack using encoded URL characters.... Read more
Affected Products : icecast- EPSS Score: %10.68
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1380
OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresse... Read more
Affected Products : openssh- EPSS Score: %4.58
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0750
Cisco IOS 12.1(2)T, 12.1(3)T allow remote attackers to cause a denial of service (reload) via a connection to TCP ports 3100-3999, 5100-5999, 7100-7999 and 10100-10999.... Read more
Affected Products : ios- EPSS Score: %0.76
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0736
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.... Read more
- EPSS Score: %0.17
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0735
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file.... Read more
Affected Products : cfingerd- EPSS Score: %0.20
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0757
Cisco 6400 Access Concentrator Node Route Processor 2 (NRP2) 12.1DC card does not properly disable access when a password has not been set for vtys, which allows remote attackers to obtain access via telnet.... Read more
Affected Products : 6400_nrp_2- EPSS Score: %1.77
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0770
Buffer overflow in GuildFTPd Server 0.97 allows remote attacker to execute arbitrary code via a long SITE command.... Read more
Affected Products : guildftpd- EPSS Score: %3.21
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0776
Buffer overflow in DynFX MailServer version 2.10 allows remote attackers to conduct a denial of service via a long username to the POP3 service.... Read more
Affected Products : dynfx_mailserver- EPSS Score: %0.81
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0778
OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20).... Read more
Affected Products : omnihttpd- EPSS Score: %3.06
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025