Latest CVE Feed
-
7.5
HIGHCVE-2001-0700
Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header.... Read more
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1029
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alterna... Read more
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0543
Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed posts.... Read more
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0696
NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con.... Read more
Affected Products : surgeftp- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0641
Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group man via a long -S option.... Read more
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0690
Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers.... Read more
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0648
Directory traversal vulnerability in PHProjekt 2.1 and earlier allows a remote attacker to conduct unauthorized activities via a dot dot (..) attack on the file module.... Read more
Affected Products : phprojekt- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0675
Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a carriage return <CR> that is not followed by a line feed <LF>.... Read more
Affected Products : the_bat- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0688
Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command.... Read more
Affected Products : broker_ftp_server- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0509
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.... Read more
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0552
ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message.... Read more
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0703
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with an MS-DOS device name in the template parameter.... Read more
Affected Products : arcadia_internet_store- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0702
Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) password, or (3) PASV command.... Read more
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0645
Symantec/AXENT NetProwler 3.5.x contains several default passwords, which could allow remote attackers to (1) access to the management tier via the "admin" password, or (2) connect to a MySQL ODBC from the management tier using a blank password.... Read more
Affected Products : netprowler- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0643
Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type.... Read more
Affected Products : internet_explorer- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0677
Eudora 5.0.2 allows a remote attacker to read arbitrary files via an email with the path of the target file in the "Attachment Converted" MIME header, which sends the file when the email is forwarded to the attacker by the user.... Read more
Affected Products : eudora- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0691
Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.... Read more
Affected Products : imapd- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0693
WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).... Read more
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0650
Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute.... Read more
Affected Products : ios- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0705
Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument.... Read more
Affected Products : arcadia_internet_store- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025