Latest CVE Feed
-
10.0
HIGHCVE-1999-0760
Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.... Read more
Affected Products : coldfusion_server- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-0922
An example application in ColdFusion Server 4.0 allows remote attackers to view source code via the sourcewindow.cfm file.... Read more
Affected Products : coldfusion_server- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1103
FTP Voyager ActiveX control before 8.0, when it is marked as safe for scripting (the default) or if allowed by the IObjectSafety interface, allows remote attackers to execute arbitrary commands.... Read more
Affected Products : ftp_voyager- Published: Mar. 03, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1445
Unknown vulnerability in the SMTP server in Lotus Domino 5.0 through 5.7 allows remote attackers to bypass mail relaying restrictions via crafted e-mail addresses in "RCPT TO" commands.... Read more
Affected Products : domino_mail_server- Published: Mar. 01, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1434
Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topology information via an "snmp-server host" command, which creates a readable "community" community string if one has not been previously created.... Read more
Affected Products : ios- Published: Feb. 28, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1776
Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data via the cable-docsis read-write community string used by the Data Over Cable Service Interface Specification (DOCSIS) standard.... Read more
Affected Products : ios- Published: Feb. 28, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1435
inetd in Compaq Tru64 UNIX 5.1 allows attackers to cause a denial of service (network connection loss) by causing one of the services handled by inetd to core dump during startup, which causes inetd to stop accepting connections to all of its services.... Read more
Affected Products : tru64- Published: Feb. 23, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0055
CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.... Read more
- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0030
FoolProof 3.9 allows local users to bypass program execution restrictions by downloading the restricted executables from another source and renaming them.... Read more
Affected Products : foolproof_security- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0042
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.... Read more
Affected Products : http_server- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0034
KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.... Read more
Affected Products : kth_kerberos- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0049
WatchGuard SOHO FireWall 2.2.1 and earlier allows remote attackers to cause a denial of service via a large number of GET requests.... Read more
Affected Products : soho_firewall- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0037
Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifiers.... Read more
Affected Products : homeseer- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0021
MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.... Read more
Affected Products : mailman_webmail- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0032
Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain root privileges via malicious format string specifiers in a URL.... Read more
Affected Products : ssldump- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0043
phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program.... Read more
Affected Products : phpgroupware- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2001-0092
A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.... Read more
Affected Products : internet_explorer- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2000-0890
periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : freebsd- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0088
common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.... Read more
Affected Products : phpweblog- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0035
Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request.... Read more
Affected Products : kth_kerberos- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025