Latest CVE Feed
-
5.0
MEDIUMCVE-2001-1266
Directory traversal vulnerability in Doug Neal's HTTPD Daemon (DNHTTPD) before 0.4.1 allows remote attackers to view arbitrary files via a .. (dot dot) attack using the dot hex code '%2E'.... Read more
Affected Products : dnhttpd- Published: Jul. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0418
content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.... Read more
Affected Products : ncm_content_management_system- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2001-1441
Cross-site scripting (XSS) vulnerability in VisualAge for Java 3.5 Professional allows remote attackers to execute JavaScript on other clients via the URL, which injects the script in the resulting error message.... Read more
Affected Products : visualage_for_java- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0400
nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.... Read more
Affected Products : nph-maillist- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0262
Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.... Read more
Affected Products : smartdownload- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0422
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0239
Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.... Read more
Affected Products : isa_server- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0486
Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353.... Read more
Affected Products : bordermanager- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0354
TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on.... Read more
Affected Products : checkbo- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0238
Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1161
Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.... Read more
Affected Products : domino_r5_server- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0440
Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0386
AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.... Read more
Affected Products : simpleserver_www- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1159
load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary co... Read more
Affected Products : squirrelmail- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1084
Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error ... Read more
Affected Products : jrun- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0437
upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1042
Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.... Read more
Affected Products : broker_ftp_server- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0436
dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0405
ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the f... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0431
Vulnerability in iPlanet Web Server Enterprise Edition 4.x.... Read more
Affected Products : iplanet_web_server- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025