Latest CVE Feed
-
5.0
MEDIUMCVE-2001-0004
IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading v... Read more
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0048
The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service... Read more
Affected Products : windows_2000- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0105
Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the "sys" group.... Read more
Affected Products : hp-ux- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0061
procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by forking a child process and executing a privileged process from the child, while... Read more
Affected Products : freebsd- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0102
"Multiple Users" Control Panel in Mac OS 9 allows Normal users to gain Owner privileges by removing the Users & Groups Data File, which effectively removes the Owner password and allows the Normal user to log in as the Owner account without a password.... Read more
Affected Products : macos- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0073
Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory.... Read more
Affected Products : security-enhanced_linux- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0106
Vulnerability in inetd server in HP-UX 11.04 and earlier allows attackers to cause a denial of service when the "swait" state is used by a server.... Read more
Affected Products : hp-ux- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0094
Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library) in NetBSD 1.5 and FreeBSD 4.2 and earlier, as used in Kerberised applications such as telnetd and login, allows local users to gain root privileges.... Read more
Affected Products : freebsd- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1090
Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.... Read more
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0894
HTTP server on the WatchGuard SOHO firewall does not properly restrict access to administrative functions such as password resets or rebooting, which allows attackers to cause a denial of service or conduct unauthorized activities.... Read more
Affected Products : soho_firewall- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0896
WatchGuard SOHO firewall allows remote attackers to cause a denial of service via a flood of fragmented IP packets, which causes the firewall to drop connections and stop forwarding packets.... Read more
Affected Products : soho_firewall- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0078
in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.... Read more
Affected Products : cluster- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0008
Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.... Read more
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0003
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka... Read more
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0097
The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request.... Read more
Affected Products : infinite_interchange- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0028
Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of " (quotation) characters.... Read more
Affected Products : oops_proxy_server- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1273
The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).... Read more
Affected Products : linux_kernel- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0084
GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.... Read more
Affected Products : gtk- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2000-0889
Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun.... Read more
Affected Products :- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0072
gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.... Read more
Affected Products : privacy_guard- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025