Latest CVE Feed
-
6.4
MEDIUMCVE-2001-0996
POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interpreted by various mail clients as valid POP server responses... Read more
Affected Products : pop3lite- Published: Sep. 02, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0973
BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space.... Read more
Affected Products : bscw- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1039
The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer.... Read more
Affected Products : jetadmin- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1070
Sage Software MAS 200 allows remote attackers to cause a denial of service by connecting to port 10000 and entering a series of control characters.... Read more
Affected Products : mas_200- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1005
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registry key to decrypt the password and gain privileges.... Read more
Affected Products : truesync_desktop- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0969
ipfw in FreeBSD does not properly handle the use of "me" in its rules when point to point interfaces are used, which causes ipfw to allow connections from arbitrary remote hosts.... Read more
Affected Products : freebsd- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1072
Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.... Read more
Affected Products : http_server- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1068
qpopper 4.01 with PAM based authentication on Red Hat systems generates different error messages when an invalid username is provided instead of a valid name, which allows remote attackers to determine valid usernames on the system.... Read more
Affected Products : qpopper- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0966
Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the CD (CWD) command.... Read more
Affected Products : nudester- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1006
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to restrict access, which allows an attacker to read the files using a different application.... Read more
Affected Products : truesync_desktop- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0970
Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script.... Read more
Affected Products : td_forum- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0965
glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.... Read more
Affected Products : glftpd- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1192
Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap.... Read more
Affected Products : snmp_trap_watcher- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1003
Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can read the WEBCT.SVR file to decrypt the passwords and gain additional privileges.... Read more
Affected Products : respondus- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1064
Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwardi... Read more
Affected Products : cbos- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0981
HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user.... Read more
Affected Products : cifs-9000_server- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1027
Buffer overflow in WindowMaker (aka wmaker) 0.64 and earlier allows remote attackers to execute arbitrary code via a long window title.... Read more
Affected Products : windowmaker- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2000-1198
qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.... Read more
Affected Products : qpopper- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1194
Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.... Read more
Affected Products : ftp_server- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-1190
imwheel-solo in imwheel package allows local users to modify arbitrary files via a symlink attack from the .imwheelrc file.... Read more
Affected Products : imwheel- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025