Latest CVE Feed
-
7.5
HIGHCVE-2001-0522
Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.... Read more
Affected Products : privacy_guard- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0565
Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.... Read more
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0548
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.... Read more
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0504
Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activities such as mail relaying.... Read more
Affected Products : windows_2000- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1232
GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".... Read more
Affected Products : groupwise- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0554
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.... Read more
Affected Products : debian_linux aix solaris sunos freebsd netbsd kerberos_5 openbsd kerberos irix +2 more products- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0553
SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field.... Read more
Affected Products : secure_shell- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0615
Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'.... Read more
Affected Products : freestyle_chat- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0629
HP Event Correlation Service (ecsd) as included with OpenView Network Node Manager 6.1 allows a remote attacker to gain addition privileges via a buffer overflow attack in the '-restore_config' command line parameter.... Read more
Affected Products : openview_network_node_manager- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0635
Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can allow a local attacker to gain additional privileges by reading sensitive information from the swap file, such as passwords.... Read more
Affected Products : linux- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0567
Digital Creations Zope 2.3.2 and earlier allows a local attacker to gain additional privileges via the changing of ZClass permission mappings for objects and methods in the ZClass.... Read more
Affected Products : zope- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0529
OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.... Read more
Affected Products : openssh- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0549
Symantec LiveUpdate 1.5 stores proxy passwords in cleartext in a registry key, which could allow local users to obtain the passwords.... Read more
Affected Products : liveupdate- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0523
eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory trav... Read more
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0566
Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disabled.... Read more
Affected Products : catalyst_2900- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0526
Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable.... Read more
Affected Products : solaris- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0574
Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot) in the URL.... Read more
Affected Products : mp3mystic- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0538
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.... Read more
Affected Products : outlook- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0527
DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.... Read more
- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0520
Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT... Read more
Affected Products : esafe_gateway- Published: Aug. 14, 2001
- Modified: Apr. 03, 2025