Latest CVE Feed
-
4.6
MEDIUMCVE-2001-0548
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.... Read more
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0628
Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.... Read more
Affected Products : word- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0553
SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field.... Read more
Affected Products : secure_shell- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0554
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.... Read more
Affected Products : debian_linux aix solaris sunos freebsd netbsd kerberos_5 openbsd kerberos irix +2 more products- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0629
HP Event Correlation Service (ecsd) as included with OpenView Network Node Manager 6.1 allows a remote attacker to gain addition privileges via a buffer overflow attack in the '-restore_config' command line parameter.... Read more
Affected Products : openview_network_node_manager- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1231
GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.... Read more
Affected Products : groupwise- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1232
GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".... Read more
Affected Products : groupwise- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0538
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.... Read more
Affected Products : outlook- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0574
Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot) in the URL.... Read more
Affected Products : mp3mystic- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0526
Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable.... Read more
Affected Products : solaris- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0527
DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.... Read more
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0615
Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'.... Read more
Affected Products : freestyle_chat- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0520
Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT... Read more
Affected Products : esafe_gateway- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0559
crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.... Read more
Affected Products : vixie_cron- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1292
Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password.... Read more
Affected Products : sambar_server- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1114
book.cgi in NetCode NC Book 0.2b allows remote attackers to execute arbitrary commands via shell metacharacters in the "current" parameter.... Read more
Affected Products : nc_book- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1113
Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command.... Read more
Affected Products : trollftpd- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1115
generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.... Read more
Affected Products : six-webboard- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1157
Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using U... Read more
Affected Products : websweeper- Published: Aug. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1117
LinkSys EtherFast BEFSR41 Cable/DSL routers running firmware before 1.39.3 Beta allows a remote attacker to view administration and user passwords by connecting to the router and viewing the HTML source for (1) index.htm and (2) Password.htm.... Read more
Affected Products : befsr41- Published: Aug. 10, 2001
- Modified: Apr. 03, 2025