Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2001-1160

    udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the category_file field.... Read more

    Affected Products : udirectory
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0414

    Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.... Read more

    Affected Products : ntpd xntp3
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 6.2

    MEDIUM
    CVE-2001-0371

    Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted informatio... Read more

    Affected Products : freebsd
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0483

    Configuration error in Axent Raptor Firewall 6.5 allows remote attackers to use the firewall as a proxy to access internal web resources when the http.noproxy Rule is not set.... Read more

    Affected Products : raptor_firewall
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1163

    Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.... Read more

    Affected Products : netsql
    • Published: Jun. 16, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-1077

    Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name argument.... Read more

    Affected Products : rxvt
    • Published: Jun. 15, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-1148

    Multiple buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allow local users to gain privileges via a long TERM environment variable to (1) atcronsh, (2) auditsh, (3) authsh, (4) backupsh, (5) lpsh, (6) sysadm... Read more

    Affected Products : openserver
    • Published: Jun. 13, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1343

    ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.... Read more

    Affected Products : webstore_400 webstore_400cs
    • Published: Jun. 12, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1344

    WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).... Read more

    Affected Products : webstore_400 webstore_400cs
    • Published: Jun. 12, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-1329

    Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.... Read more

    Affected Products : aix
    • Published: Jun. 11, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1430

    Cayman 3220-H DSL Router 1.0 ship without a password set, which allows remote attackers to gain unauthorized access.... Read more

    Affected Products : 3220-h_dsl_router
    • Published: Jun. 11, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-1277

    makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.... Read more

    Affected Products : makewhatis
    • Published: Jun. 11, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-1330

    Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.... Read more

    Affected Products : aix
    • Published: Jun. 11, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1368

    Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data.... Read more

    Affected Products : iplanet_web_server
    • Published: Jun. 11, 2001
    • Modified: Apr. 03, 2025
  • 1.2

    LOW
    CVE-2001-1256

    kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.... Read more

    Affected Products : hp-ux
    • Published: Jun. 11, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1359

    Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server.... Read more

    Affected Products : volution
    • Published: Jun. 08, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1263

    telnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large number of characters to port 23, possibly due to a buffer overflow.... Read more

    Affected Products : interaccess
    • Published: Jun. 06, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-1345

    bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program.... Read more

    Affected Products : bestcrypt
    • Published: Jun. 05, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1088

    Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could al... Read more

    Affected Products : outlook outlook_express
    • Published: Jun. 05, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-0300

    oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.... Read more

    Affected Products : internet_directory
    • Published: Jun. 02, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 293496 Results