Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 1.2

    LOW
    CVE-2001-1301

    rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.... Read more

    Affected Products : emacs xemacs
    • Published: Aug. 07, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1260

    Avaya Argent Office uses weak encryption (trivial encoding) for passwords, which allows remote attackers to gain administrator privileges by sniffing and decrypting the sniffing the passwords during a system reboot.... Read more

    Affected Products : argent_office
    • Published: Aug. 07, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1262

    Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string.... Read more

    Affected Products : argent_office
    • Published: Aug. 07, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1261

    Avaya Argent Office 2.1 may allow remote attackers to change hold music by spoofing a legitimate server's response to a TFTP broadcast and providing an alternate HoldMusic file.... Read more

    Affected Products : argent_office
    • Published: Aug. 07, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1259

    Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload.... Read more

    Affected Products : argent_office
    • Published: Aug. 07, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0647

    Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version.... Read more

    Affected Products : orange_web_server
    • Published: Aug. 06, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1356

    NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.... Read more

    Affected Products : surgeftp
    • Published: Aug. 04, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-1472

    SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.... Read more

    Affected Products : phpbb
    • Published: Aug. 03, 2001
    • Modified: Apr. 03, 2025
  • 6.2

    MEDIUM
    CVE-2001-1119

    cda in xmcd 3.0.2 and 2.6 in SuSE Linux allows local users to overwrite arbitrary files via a symlink attack.... Read more

    Affected Products : xmcd
    • Published: Aug. 03, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-1122

    Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode.... Read more

    Affected Products : windows_nt
    • Published: Aug. 03, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1304

    Buffer overflow in SHOUTcast Server 1.8.2 allows remote attackers to cause a denial of service (crash) via several HTTP requests with a long (1) user-agent or (2) host HTTP header.... Read more

    Affected Products : shoutcast_server
    • Published: Aug. 03, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0602

    Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeated (>400) URL requests for DOS devices.... Read more

    Affected Products : domino_r5_server
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0590

    Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).... Read more

    Affected Products : tomcat
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0618

    Orinoco RG-1000 wireless Residential Gateway uses the last 5 digits of the 'Network Name' or SSID as the default Wired Equivalent Privacy (WEP) encryption key. Since the SSID occurs in the clear during communications, a remote attacker could determine th... Read more

    Affected Products : orinoco_rg-1000
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0597

    Zetetic Secure Tool for Recalling Important Passwords (STRIP) 0.5 and earlier for the PalmOS allows a local attacker to recover passwords via a brute force attack. This attack is made feasible by STRIP's use of SysRandom, which is seeded by TimeGetTicks,... Read more

    Affected Products : strip
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0619

    The Lucent Closed Network protocol can allow remote attackers to join Closed Network networks which they do not have access to. The 'Network Name' or SSID, which is used as a shared secret to join the network, is transmitted in the clear.... Read more

    Affected Products : orinoco
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-0594

    kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.... Read more

    Affected Products : solaris sunos
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-0610

    kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in /tmp.... Read more

    Affected Products : suse_linux kde
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0604

    Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via URL requests (>8Kb) containing a large number of '/' characters.... Read more

    Affected Products : domino_r5_server
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-0620

    iPlanet Calendar Server 5.0p2 and earlier allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP database and read arbitrary files by obtaining the cleartext administrator username and password from the configuration file, which ha... Read more

    Affected Products : calendar_server
    • Published: Aug. 02, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 294202 Results