Latest CVE Feed
-
7.2
HIGHCVE-2001-0424
BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2001-0395
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0434
The LogDataListToFile ActiveX function used in (1) Knowledge Center and (2) Back web components of Compaq Presario computers allows remote attackers to modify arbitrary files and cause a denial of service.... Read more
Affected Products : presario- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0400
nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.... Read more
Affected Products : nph-maillist- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0426
Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0439
licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0464
Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter.... Read more
Affected Products : cyberscheduler- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0419
Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the applicatio... Read more
Affected Products : application_server- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0391
Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory.... Read more
Affected Products : xitami- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0262
Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.... Read more
Affected Products : smartdownload- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0443
Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0422
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0440
Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0386
AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.... Read more
Affected Products : simpleserver_www- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1042
Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.... Read more
Affected Products : broker_ftp_server- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0437
upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2001-1441
Cross-site scripting (XSS) vulnerability in VisualAge for Java 3.5 Professional allows remote attackers to execute JavaScript on other clients via the URL, which injects the script in the resulting error message.... Read more
Affected Products : visualage_for_java- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0327
iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: ... Read more
Affected Products : iplanet_web_server- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0354
TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on.... Read more
Affected Products : checkbo- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0238
Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.... Read more
- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025