Latest CVE Feed
-
4.6
MEDIUMCVE-2001-0046
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permiss... Read more
- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0045
The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.... Read more
Affected Products : windows_nt- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0047
The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilit... Read more
Affected Products : windows_nt- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0036
KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.... Read more
Affected Products : kth_kerberos- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0042
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.... Read more
Affected Products : http_server- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0049
WatchGuard SOHO FireWall 2.2.1 and earlier allows remote attackers to cause a denial of service via a large number of GET requests.... Read more
Affected Products : soho_firewall- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0037
Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifiers.... Read more
Affected Products : homeseer- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0034
KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.... Read more
Affected Products : kth_kerberos- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0021
MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.... Read more
Affected Products : mailman_webmail- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0032
Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain root privileges via malicious format string specifiers in a URL.... Read more
Affected Products : ssldump- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0043
phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program.... Read more
Affected Products : phpgroupware- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2001-0092
A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.... Read more
Affected Products : internet_explorer- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0066
Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer.... Read more
Affected Products : secure_locate- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0893
The presence of the Distributed GL Daemon (dgld) service on port 5232 on SGI IRIX systems allows remote attackers to identify the target host as an SGI system.... Read more
Affected Products : irix- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1439
Buffer overflow in the text editor functionality in HP-UX 10.01 through 11.04 on HP9000 Series 700 and Series 800 allows local users to cause a denial of service ("system availability") via text editors such as (1) e, (2) ex, (3) vi, (4) edit, (5) view, a... Read more
Affected Products : hp-ux- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2000-0890
periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : freebsd- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0051
IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.... Read more
Affected Products : db2_universal_database- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0039
IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.... Read more
Affected Products : imail- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0040
APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file.... Read more
Affected Products : apcupsd- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0054
Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.... Read more
Affected Products : serv-u_file_server- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025