Latest CVE Feed
-
7.2
HIGHCVE-2001-0855
Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM environment variable.... Read more
Affected Products : clearcase- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0831
Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.... Read more
Affected Products : database_server- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0820
Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c.... Read more
Affected Products : ghttp- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0854
PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of ... Read more
Affected Products : php-nuke- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0801
lpstat in IRIX 6.5.13f and earlier allows local users to gain root privileges by specifying a Trojan Horse nettype shared library.... Read more
Affected Products : irix- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0851
Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie.... Read more
Affected Products : linux_kernel suse_linux linux openlinux openlinux_edesktop openlinux_eserver openlinux_server openlinux_workstation- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0808
gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.... Read more
Affected Products : gnatsweb- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0830
6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to and disconnecting from the server.... Read more
Affected Products : 6tunnel- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2001-0829
A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.... Read more
Affected Products : tomcat- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0860
Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Addre... Read more
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0832
Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the O... Read more
Affected Products : database_server- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0837
DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-readable locations in the installation directory, which allows local users to read the information in (1) temp.html, (2) the log folder, and (3) the PhoneBook folder.... Read more
Affected Products : pc-to-phone- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0824
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javasc... Read more
Affected Products : websphere_application_server- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0858
Buffer overflow in pppattach and other linked PPP utilities in Caldera Open Unix 8.0 and UnixWare 7.1.0 and 7.1.1 allows local users to gain privileges.... Read more
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0827
Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.... Read more
Affected Products : ceberus_ftp_server- Published: Dec. 06, 2001
- Modified: Apr. 23, 2025
-
10.0
HIGHCVE-2001-0840
Buffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI.... Read more
Affected Products : insight_manager_xe- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-1247
PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files.... Read more
Affected Products : php- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0845
Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources.... Read more
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0722
Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."... Read more
Affected Products : internet_explorer- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0843
Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request.... Read more
Affected Products : squid_web_proxy- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025