Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2001-0970

    Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script.... Read more

    Affected Products : td_forum
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0966

    Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the CD (CWD) command.... Read more

    Affected Products : nudester
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1193

    Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port.... Read more

    Affected Products : irix
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-1063

    Buffer overflow in uidadmin in Caldera Open Unix 8.0.0 and UnixWare 7 allows local users to gain root privileges via a long -S (scheme) command line argument.... Read more

    Affected Products : unixware openunix
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-1062

    Buffer overflow in mana in OpenServer 5.0.6a and earlier allows local users to execute arbitrary code.... Read more

    Affected Products : openserver
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1154

    Cyrus 2.0.15, 2.0.16, and 1.6.24 on BSDi 4.2, with IMAP enabled, allows remote attackers to cause a denial of service (hang) using PHP IMAP clients.... Read more

    Affected Products : bsd_os cyrus_imap_server
    • Published: Aug. 30, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1168

    Directory traversal vulnerability in index.php in PhpMyExplorer before 1.2.1 allows remote attackers to read arbitrary files via a ..%2F (modified dot dot) in the chemin parameter.... Read more

    • Published: Aug. 29, 2001
    • Modified: Apr. 03, 2025
  • 5.5

    MEDIUM
    CVE-2001-0682

    ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.... Read more

    Affected Products : zonealarm zonealarm_pro
    • Published: Aug. 29, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1389

    Multiple vulnerabilities in xinetd 2.3.0 and earlier, and additional variants until 2.3.3, may allow remote attackers to cause a denial of service or execute arbitrary code, primarily via buffer overflows or improper NULL termination.... Read more

    Affected Products : linux xinetd
    • Published: Aug. 29, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1379

    The PostgreSQL authentication modules (1) mod_auth_pgsql 0.9.5, and (2) mod_auth_pgsql_sys 0.9.4, allow remote attackers to bypass authentication and execute arbitrary SQL via a SQL injection attack on the user name.... Read more

    Affected Products : mod_auth_pgsql
    • Published: Aug. 29, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-1153

    lpsystem in OpenUnix 8.0.0 allows local users to cause a denial of service and possibly execute arbitrary code via a long command line argument.... Read more

    Affected Products : openunix
    • Published: Aug. 28, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1444

    The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption options sent from the server, which allows remote attackers to downgrade authentication and encryption mechanisms via ... Read more

    Affected Products : kth_kerberos
    • Published: Aug. 27, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1443

    KTH Kerberos IV and Kerberos V (Heimdal) for Telnet clients do not encrypt connections if the server does not support the requested encryption, which allows remote attackers to read communications via a man-in-the-middle attack.... Read more

    Affected Products : kth_kerberos
    • Published: Aug. 27, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1455

    Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters.... Read more

    Affected Products : siteminder
    • Published: Aug. 24, 2001
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2001-1155

    TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spoofing.... Read more

    Affected Products : freebsd
    • Published: Aug. 23, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-1091

    The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.... Read more

    Affected Products : netbsd
    • Published: Aug. 23, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2001-0576

    lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the '-u' command line parameter.... Read more

    Affected Products : openserver
    • Published: Aug. 22, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0593

    Anaconda Partners Clipper 3.3 and earlier allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the template parameter.... Read more

    Affected Products : clipper
    • Published: Aug. 22, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1294

    Buffer overflow in A-V Tronics Inetserv 3.2.1 and earlier allows remote attackers to cause a denial of service (crash) in the Webmail interface via a long username and password.... Read more

    Affected Products : inetserv
    • Published: Aug. 22, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1140

    BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request.... Read more

    Affected Products : badblue
    • Published: Aug. 22, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 294322 Results