Latest CVE Feed
-
4.6
MEDIUMCVE-2001-0713
Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the h... Read more
Affected Products : sendmail- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0729
Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.... Read more
Affected Products : http_server- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0545
IIS 4.0 with URL redirection enabled allows remote attackers to cause a denial of service (crash) via a malformed request that specifies a length that is different than the actual length.... Read more
- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0505
Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.... Read more
Affected Products : services- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0660
Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresses by directly accessing a back-end function that processes the global address list (GAL).... Read more
Affected Products : exchange_server- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0665
Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "... Read more
- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0669
Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before... Read more
- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0652
Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.... Read more
- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0715
Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to obtain potentially sensitive information about the mail queue by setting debugging flags to enable debug mode.... Read more
Affected Products : sendmail- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0544
IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type table.... Read more
Affected Products : internet_information_services- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0540
Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389.... Read more
Affected Products : terminal_server- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0666
Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.... Read more
Affected Products : exchange_server- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0662
RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed request.... Read more
Affected Products : windows_nt- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0923
RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried.... Read more
Affected Products : redhat_package_manager- Published: Oct. 25, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1462
WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information.... Read more
Affected Products : securid- Published: Oct. 24, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1438
Handspring Visor 1.0 and 1.0.1 with the VisorPhone Springboard module installed allows remote attackers to cause a denial of service (PalmOS crash and VisorPhone database corruption) by sending a large or crafted SMS image.... Read more
- Published: Oct. 22, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1461
Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to access restricted resources via URL-encoded (1) /.. or (2) \.. sequences.... Read more
Affected Products : securid- Published: Oct. 22, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0765
BisonFTP V4R1 allows local users to access directories outside of their home directory by uploading .bdl files, which can then be linked to other directories.... Read more
Affected Products : bison_ftp_server- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0777
Omnicron OmniHTTPd 2.0.8 allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests for PHP scripts.... Read more
Affected Products : omnihttpd- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0743
Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followed by JavaScript commands.... Read more
Affected Products : webboard- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025