Latest CVE Feed
-
7.5
HIGHCVE-2001-1328
Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.... Read more
Affected Products : sunos- Published: Jun. 22, 2001
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2001-0906
teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produced when printing .dvi files using lpr.... Read more
Affected Products : tetex- Published: Jun. 22, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1078
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6... Read more
Affected Products : extremail- Published: Jun. 21, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1276
ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file.... Read more
Affected Products : ispell- Published: Jun. 21, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1080
diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.... Read more
Affected Products : aix- Published: Jun. 19, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1459
OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.... Read more
Affected Products : openssh- Published: Jun. 19, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0446
IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.... Read more
Affected Products : websphere_commerce_suite- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0402
IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted ... Read more
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0447
Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters.... Read more
Affected Products : 602pro_lan_suite- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0409
vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory.... Read more
Affected Products : vim- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0392
Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.... Read more
Affected Products : financials_server- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0401
Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.... Read more
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0397
Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.... Read more
Affected Products : silent_runner_collector_src- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0373
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.... Read more
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0399
Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.... Read more
Affected Products : resin- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2001-0427
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed... Read more
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0379
Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.... Read more
Affected Products : hp-ux- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0375
Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests.... Read more
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0412
Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode.... Read more
Affected Products : content_services_switch_11050 content_services_switch_11150 content_services_switch_11800- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0465
TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive information.... Read more
Affected Products : turbo_tax- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025