Latest CVE Feed
-
5.0
MEDIUMCVE-2001-1023
Xcache 2.1 allows remote attackers to determine the absolute path of web server documents by requesting a URL that is not cached by Xcache, which returns the full pathname in the Content-PageName header.... Read more
Affected Products : xcache- Published: Sep. 21, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0940
Buffer overflow in the GUI authentication code of Check Point VPN-1/FireWall-1 Management Server 4.0 and 4.1 allows remote attackers to execute arbitrary code via a long user name.... Read more
- Published: Sep. 21, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0674
Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a hexadecimal encoded dot-dot attack (eg. http://www.server.com/%2e%2e/%2e%2e) in an HTTP URL request.... Read more
Affected Products : viking_server- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0709
Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode.... Read more
Affected Products : internet_information_server- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0694
Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.... Read more
Affected Products : wftpd- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0704
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist.... Read more
Affected Products : arcadia_internet_store- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0507
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.... Read more
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0710
NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool.... Read more
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0963
Directory traversal vulnerability in SpoonFTP 1.1 allows local and sometimes remote attackers to access files outside of the FTP root via a ... (modified dot dot) in the CD (CWD) command.... Read more
Affected Products : spoonftp- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0658
Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly... Read more
Affected Products : isa_server- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0707
Denicomp RSHD 2.18 and earlier allows a remote attacker to cause a denial of service (crash) via a long string to port 514.... Read more
Affected Products : rshd- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0646
Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specific length.... Read more
Affected Products : rumpus_ftp_server- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0706
Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies a large number of sub-folders.... Read more
Affected Products : rumpus_ftp_server- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2001-0685
Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file.... Read more
Affected Products : fcron- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0698
Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command.... Read more
Affected Products : surgeftp- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0546
Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.... Read more
Affected Products : isa_server- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0697
NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.... Read more
Affected Products : surgeftp- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0547
Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).... Read more
Affected Products : isa_server- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0684
Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service by sending seven or more characters to TCP port 5239.... Read more
Affected Products : collabra_server- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1018
Lotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that contains a long sequence of / (slash) characters.... Read more
Affected Products : domino- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025