Latest CVE Feed
-
7.2
HIGHCVE-2001-0268
The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the ... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0283
Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.... Read more
Affected Products : sun_ftp- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0271
mailnews.cgi 1.3 and earlier allows remote attackers to execute arbitrary commands via a user name that contains shell metacharacters.... Read more
Affected Products : mailnews.cgi- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0297
Directory traversal vulnerability in Simple Server HTTPd 1.0 (originally Free Java Server) allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.... Read more
Affected Products : simple_server- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0285
Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.... Read more
Affected Products : http_server- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0308
UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the... Read more
Affected Products : java_http_server- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0236
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0165
Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0267
NM debug in HP MPE/iX 6.5 and earlier does not properly handle breakpoints, which allows local users to gain privileges.... Read more
Affected Products : mpe_ix- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0196
inetd ident server in FreeBSD 4.x and earlier does not properly set group permissions, which allows remote attackers to read the first 16 bytes of files that are accessible by the wheel group.... Read more
Affected Products : freebsd- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0226
Directory traversal vulnerability in BiblioWeb web server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) or ... attack in an HTTP GET request.... Read more
Affected Products : biblioweb_server- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0303
tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file.... Read more
Affected Products : pi3web- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0298
Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.... Read more
Affected Products : webreflex- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0277
Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.... Read more
Affected Products : badblue- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0266
Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges.... Read more
Affected Products : hp-ux- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0180
Lars Ellingsen guestserver.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the "email" parameter.... Read more
Affected Products : guestserver- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0304
Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request.... Read more
Affected Products : resin- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0326
Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the <<ALL FILES>> FilePe... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0227
Buffer overflow in BiblioWeb web server 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.... Read more
Affected Products : biblioweb_server- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0289
Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute j... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025