Latest CVE Feed
-
7.5
HIGHCVE-2001-0257
Buffer overflow in Easycom/Safecom Print Server Web service, version 404.590 and earlier, allows remote attackers to execute arbitrary commands via (1) a long URL or (2) a long HTTP header field such as "Host:".... Read more
Affected Products : easycom_safecom_print_server- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0323
The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to low... Read more
Affected Products : solaris- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0155
Format string vulnerability in VShell SSH gateway 1.0.1 and earlier allows remote attackers to execute arbitrary commands via a user name that contains format string specifiers.... Read more
Affected Products : vshell- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0312
IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere ... Read more
Affected Products : websphere_plugin- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0148
The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.... Read more
- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0215
ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename with a null byte.... Read more
Affected Products : roads- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0212
Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.... Read more
Affected Products : auktion- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0230
Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and possibly other operating systems, allows local users to gain privileges.... Read more
Affected Products : freebsd- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0204
Watchguard Firebox II allows remote attackers to cause a denial of service by establishing multiple connections and sending malformed PPTP packets.... Read more
Affected Products : firebox_ii- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0781
Buffer overflow in SpoonFTP 1.0.0.12 allows remote attackers to execute arbitrary code via a long argument to the commands (1) CWD or (2) LIST.... Read more
Affected Products : spoonftp- Published: May. 30, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1326
Eudora 5.1 allows remote attackers to execute arbitrary code when the "Use Microsoft Viewer" option is enabled and the "allow executables in HTML content" option is disabled, via an HTML email with a form that is activated from an image that the attacker ... Read more
Affected Products : eudora- Published: May. 29, 2001
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2001-1349
Sendmail before 8.11.4, and 8.12.0 before 8.12.0.Beta10, allows local users to cause a denial of service and possibly corrupt the heap and gain privileges via race conditions in signal handlers.... Read more
Affected Products : sendmail- Published: May. 28, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1074
Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges.... Read more
Affected Products : webmin- Published: May. 28, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1336
CesarFTP 0.98b and earlier stores usernames and passwords in plaintext in the settings.ini file, which allows attackers to gain privileges.... Read more
Affected Products : cesarftp- Published: May. 28, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1028
Buffer overflow in ultimate_source function of man 1.5 and earlier allows local users to gain privileges.... Read more
Affected Products : linux- Published: May. 28, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1348
TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter.... Read more
Affected Products : twig- Published: May. 28, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1335
Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contains a ...%5c (modified dot dot).... Read more
Affected Products : cesarftp- Published: May. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0749
Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to read arbitrary files via a webserver root directory set to system root.... Read more
Affected Products : ipc_at_chip_embedded-webserver- Published: May. 24, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1428
The (1) FTP and (2) Telnet services in Beck GmbH IPC@Chip are shipped with a default password, which allows remote attackers to gain unauthorized access.... Read more
Affected Products : ipc_at_chip_embedded-webserver- Published: May. 24, 2001
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2001-1339
Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.... Read more
- Published: May. 24, 2001
- Modified: Apr. 03, 2025