Latest CVE Feed
-
7.5
HIGHCVE-2001-0330
Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.... Read more
Affected Products : bugzilla- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0495
Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack.... Read more
Affected Products : webxq- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0462
Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.... Read more
Affected Products : perl_web_server- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0488
pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.... Read more
Affected Products : hp-ux- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0492
Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3.... Read more
Affected Products : netcruiser_web_server- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0470
Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.... Read more
Affected Products : sunos- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0332
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain... Read more
Affected Products : internet_explorer- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0472
Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.... Read more
Affected Products : high_availability_cluster_multiprocessing- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0246
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain... Read more
Affected Products : internet_explorer- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0370
fcheck prior to 2.57.59 calls the file signature checking program insecurely, which can allow a local user to run arbitrary commands via a file name that contains shell metacharacters.... Read more
Affected Products : fcheck- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0242
Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed i... Read more
Affected Products : windows_media_player- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0415
REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts.... Read more
Affected Products : rediplus- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0457
man2html before 1.5-22 allows remote attackers to cause a denial of service (memory exhaustion).... Read more
Affected Products : debian_linux- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0471
SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.... Read more
Affected Products : ssh- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0456
postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended.... Read more
Affected Products : debian_linux- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0337
The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.... Read more
Affected Products : internet_information_server- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0468
Buffer overflow in FTPFS allows local users to gain root privileges via a long user name.... Read more
Affected Products : ftpfs- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0459
Buffer overflows in ascdc Afterstep while running setuid allows local users to gain root privileges via a long (1) -d option, (2) -m option, or (3) -f option.... Read more
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0474
Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file.... Read more
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0364
SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections.... Read more
Affected Products : ssh2- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025