Latest CVE Feed
-
5.0
MEDIUMCVE-2001-1408
Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the mailbox parameter.... Read more
- Published: Jul. 05, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1076
Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.... Read more
- Published: Jul. 05, 2001
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2001-1085
Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.... Read more
Affected Products : lmail- Published: Jul. 05, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1087
The default configuration of the config.http.tunnel.allow_ports option on NetCache devices is set to +all, which allows remote attackers to connect to arbitrary ports on remote systems behind the device.... Read more
Affected Products : netcache- Published: Jul. 05, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1075
poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by causing a "POP login by user" string that includes the attacker's IP address to be injected into the maillog log file.... Read more
Affected Products : cobalt_raq_3i- Published: Jul. 04, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1243
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2... Read more
- Published: Jul. 04, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1086
XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.... Read more
Affected Products : x11r6- Published: Jul. 04, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1266
Directory traversal vulnerability in Doug Neal's HTTPD Daemon (DNHTTPD) before 0.4.1 allows remote attackers to view arbitrary files via a .. (dot dot) attack using the dot hex code '%2E'.... Read more
Affected Products : dnhttpd- Published: Jul. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0428
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option.... Read more
Affected Products : vpn_3000_concentrator_series_software- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0432
Buffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote attackers to execute arbitrary commands.... Read more
Affected Products : interscan_viruswall- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1159
load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary co... Read more
Affected Products : squirrelmail- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1084
Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error ... Read more
Affected Products : jrun- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0390
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0387
Format string vulnerability in hfaxd in HylaFAX before 4.1.b2_2 allows local users to gain privileges via the -q command line argument.... Read more
Affected Products : hylafax- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0384
ppd in Reliant Sinix allows local users to corrupt arbitrary files via a symlink attack in the /tmp/ppd.trace file.... Read more
Affected Products : reliant_unix- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0396
The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.... Read more
Affected Products : consoleserver- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0421
FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could rel... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0429
Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service.... Read more
Affected Products : catos- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2001-0430
Vulnerability in exuberant-ctags before 3.2.4-0.1 insecurely creates temporary files.... Read more
Affected Products : debian_linux- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0438
Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu.... Read more
Affected Products : timbuktu_mac- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025