Latest CVE Feed
-
7.5
HIGHCVE-2001-0382
Computer Associates CCC\Harvest 5.0 for Windows NT/2000 uses weak encryption for passwords, which allows a remote attacker to gain privileges on the application.... Read more
Affected Products : ccc_harvest- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0372
Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.... Read more
Affected Products : akopia_interchange- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0448
Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.... Read more
Affected Products : 602pro_lan_suite- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0263
Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.... Read more
Affected Products : g6_ftp_server- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0482
Configuration error in Argus PitBull LX allows root users to bypass specified access control restrictions and cause a denial of service or execute arbitrary commands by modifying kernel variables such as MaxFiles, MaxInodes, and ModProbePath in /proc/sys ... Read more
Affected Products : pitbull_lx- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0376
SonicWALL Tele2 and SOHO firewalls with 6.0.0.0 firmware using IPSEC with IKE pre-shared keys do not allow for the use of full 128 byte IKE pre-shared keys, which is the intended design of the IKE pre-shared key, and only support 48 byte keys. This allow... Read more
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0404
Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.... Read more
Affected Products : javaserver_web_dev_kit- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0414
Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.... Read more
- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1163
Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.... Read more
Affected Products : netsql- Published: Jun. 16, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1077
Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name argument.... Read more
Affected Products : rxvt- Published: Jun. 15, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1148
Multiple buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allow local users to gain privileges via a long TERM environment variable to (1) atcronsh, (2) auditsh, (3) authsh, (4) backupsh, (5) lpsh, (6) sysadm... Read more
Affected Products : openserver- Published: Jun. 13, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1344
WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).... Read more
- Published: Jun. 12, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1343
ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.... Read more
- Published: Jun. 12, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1430
Cayman 3220-H DSL Router 1.0 ship without a password set, which allows remote attackers to gain unauthorized access.... Read more
Affected Products : 3220-h_dsl_router- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1277
makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.... Read more
Affected Products : makewhatis- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1330
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.... Read more
Affected Products : aix- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1329
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.... Read more
Affected Products : aix- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1256
kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.... Read more
Affected Products : hp-ux- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1368
Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data.... Read more
Affected Products : iplanet_web_server- Published: Jun. 11, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1359
Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server.... Read more
Affected Products : volution- Published: Jun. 08, 2001
- Modified: Apr. 03, 2025