Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2001-0992

    shopplus.cgi in ShopPlus shopping cart allows remote attackers to execute arbitrary commands via shell metacharacters in the "file" parameter.... Read more

    Affected Products : shopplus_cart
    • Published: Sep. 05, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-1012

    Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/.... Read more

    Affected Products : suse_linux
    • Published: Sep. 05, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1020

    edit_image.php in Vibechild Directory Manager before 0.91 allows remote attackers to execute arbitrary commands via shell metacharacters in the userfile_name parameter, which is sent unfiltered to the PHP passthru function.... Read more

    Affected Products : directory_manager
    • Published: Sep. 05, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1152

    Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.... Read more

    Affected Products : websweeper
    • Published: Sep. 05, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1456

    Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message.... Read more

    • Published: Sep. 04, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0994

    Marconi ForeThought 7.1 allows remote attackers to cause a denial of service by causing both telnet sessions to be locked via unusual input (e.g., from a port scanner), which prevents others from logging into the device.... Read more

    Affected Products : forethought
    • Published: Sep. 04, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-1017

    rmuser utility in FreeBSD 4.2 and 4.3 creates a copy of the master.passwd file with world-readable permissions while updating the original file, which could allow local users to gain privileges by reading the copied file while rmuser is running, obtain th... Read more

    Affected Products : freebsd
    • Published: Sep. 04, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1016

    PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe th... Read more

    • Published: Sep. 04, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-0990

    Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that ... Read more

    Affected Products : vpopmail
    • Published: Sep. 04, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0979

    Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long command line argument.... Read more

    Affected Products : hp-ux
    • Published: Sep. 03, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0978

    login in HP-UX 10.26 does not record failed login attempts in /var/adm/btmp, which could allow attackers to conduct brute force password guessing attacks without being detected or observed using the lastb program.... Read more

    Affected Products : hp-ux
    • Published: Sep. 03, 2001
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2001-0996

    POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interpreted by various mail clients as valid POP server responses... Read more

    Affected Products : pop3lite
    • Published: Sep. 02, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1169

    keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authenticatio... Read more

    Affected Products : s_key
    • Published: Sep. 02, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1027

    Buffer overflow in WindowMaker (aka wmaker) 0.64 and earlier allows remote attackers to execute arbitrary code via a long window title.... Read more

    Affected Products : windowmaker
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1008

    Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.... Read more

    Affected Products : jre java_plug-in
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0976

    Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables.... Read more

    Affected Products : process_resource_manager
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2001-0967

    Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.... Read more

    Affected Products : arkeia
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-1063

    Buffer overflow in uidadmin in Caldera Open Unix 8.0.0 and UnixWare 7 allows local users to gain root privileges via a long -S (scheme) command line argument.... Read more

    Affected Products : unixware openunix
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-1062

    Buffer overflow in mana in OpenServer 5.0.6a and earlier allows local users to execute arbitrary code.... Read more

    Affected Products : openserver
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1002

    The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains maliciou... Read more

    Affected Products : linux
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 294125 Results