Latest CVE Feed
-
7.2
HIGHCVE-2001-1329
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.... Read more
Affected Products : aix- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1256
kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.... Read more
Affected Products : hp-ux- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1430
Cayman 3220-H DSL Router 1.0 ship without a password set, which allows remote attackers to gain unauthorized access.... Read more
Affected Products : 3220-h_dsl_router- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1368
Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data.... Read more
Affected Products : iplanet_web_server- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1359
Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server.... Read more
Affected Products : volution- Published: Jun. 08, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1263
telnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large number of characters to port 23, possibly due to a buffer overflow.... Read more
Affected Products : interaccess- Published: Jun. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1088
Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could al... Read more
- Published: Jun. 05, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1345
bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program.... Read more
Affected Products : bestcrypt- Published: Jun. 05, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0309
inetd in Red Hat 6.2 does not properly close sockets for internal services such as chargen, daytime, echo, etc., which allows remote attackers to cause a denial of service via a series of connections to the internal services.... Read more
Affected Products : linux- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1046
Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain privileges via a long username.... Read more
Affected Products : qpopper- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0215
ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename with a null byte.... Read more
Affected Products : roads- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1047
Race condition in OpenBSD VFS allows local users to cause a denial of service (kernel panic) by (1) creating a pipe in one thread and causing another thread to set one of the file descriptors to NULL via a close, or (2) calling dup2 on a file descriptor i... Read more
Affected Products : openbsd- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0261
Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.... Read more
Affected Products : windows_2000- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0149
Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.... Read more
Affected Products : internet_explorer- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0300
oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.... Read more
Affected Products : internet_directory- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0157
Debugging utility in the backdoor mode of Palm OS 3.5.2 and earlier allows attackers with physical access to a Palm device to bypass access restrictions and obtain passwords, even if the system lockout mechanism is enabled.... Read more
Affected Products : palm_os- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0252
iPlanet (formerly Netscape) Enterprise Server 4.1 allows remote attackers to cause a denial of service via a long HTTP GET request that contains many "/../" (dot dot) sequences.... Read more
Affected Products : iplanet_enterprise_server- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0206
Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into the requested pathname of an HTTP GET request.... Read more
Affected Products : serverworx- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0221
Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.... Read more
Affected Products : ja-xklock- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2001-0259
ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker can use to decrypt that user's private key file.... Read more
Affected Products : ssh- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025