Latest CVE Feed
-
6.2
MEDIUMCVE-2001-0371
Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted informatio... Read more
Affected Products : freebsd- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1160
udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the category_file field.... Read more
Affected Products : udirectory- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1163
Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.... Read more
Affected Products : netsql- Published: Jun. 16, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1077
Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name argument.... Read more
Affected Products : rxvt- Published: Jun. 15, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1148
Multiple buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allow local users to gain privileges via a long TERM environment variable to (1) atcronsh, (2) auditsh, (3) authsh, (4) backupsh, (5) lpsh, (6) sysadm... Read more
Affected Products : openserver- Published: Jun. 13, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1344
WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).... Read more
- Published: Jun. 12, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1343
ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.... Read more
- Published: Jun. 12, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1430
Cayman 3220-H DSL Router 1.0 ship without a password set, which allows remote attackers to gain unauthorized access.... Read more
Affected Products : 3220-h_dsl_router- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1329
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.... Read more
Affected Products : aix- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1256
kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.... Read more
Affected Products : hp-ux- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1368
Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data.... Read more
Affected Products : iplanet_web_server- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1277
makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.... Read more
Affected Products : makewhatis- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1330
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.... Read more
Affected Products : aix- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1359
Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server.... Read more
Affected Products : volution- Published: Jun. 08, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1263
telnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large number of characters to port 23, possibly due to a buffer overflow.... Read more
Affected Products : interaccess- Published: Jun. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1088
Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could al... Read more
- Published: Jun. 05, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1345
bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program.... Read more
Affected Products : bestcrypt- Published: Jun. 05, 2001
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2001-0150
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services f... Read more
Affected Products : internet_explorer- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0217
Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.... Read more
Affected Products : webpals- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0315
The locking feature in mIRC 5.7 allows local users to bypass the password mechanism by modifying the LockOptions registry key.... Read more
Affected Products : mirc- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025