Latest CVE Feed
-
5.0
MEDIUMCVE-2001-0042
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.... Read more
Affected Products : http_server- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0021
MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.... Read more
Affected Products : mailman_webmail- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0037
Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifiers.... Read more
Affected Products : homeseer- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0036
KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.... Read more
Affected Products : kth_kerberos- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0057
Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.... Read more
- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0035
Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request.... Read more
Affected Products : kth_kerberos- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0052
IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.... Read more
Affected Products : db2_universal_database- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0038
Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in the requested URL.... Read more
Affected Products : offline_explorer- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2001-0091
The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.... Read more
Affected Products : internet_explorer- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0893
The presence of the Distributed GL Daemon (dgld) service on port 5232 on SGI IRIX systems allows remote attackers to identify the target host as an SGI system.... Read more
Affected Products : irix- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0046
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permiss... Read more
- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0040
APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file.... Read more
Affected Products : apcupsd- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0055
CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.... Read more
- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1439
Buffer overflow in the text editor functionality in HP-UX 10.01 through 11.04 on HP9000 Series 700 and Series 800 allows local users to cause a denial of service ("system availability") via text editors such as (1) e, (2) ex, (3) vi, (4) edit, (5) view, a... Read more
Affected Products : hp-ux- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0051
IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.... Read more
Affected Products : db2_universal_database- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0044
Multiple buffer overflows in Lexmark MarkVision printer driver programs allows local users to gain privileges via long arguments to the cat_network, cat_paraller, and cat_serial commands.... Read more
Affected Products : markvision- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0056
The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.... Read more
Affected Products : broadband_operating_system- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2001-0089
Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.... Read more
Affected Products : internet_explorer- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0058
The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character.... Read more
- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0088
common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.... Read more
Affected Products : phpweblog- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025