Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 1.2

    LOW
    CVE-2001-0095

    catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.... Read more

    Affected Products : sunos
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0004

    IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading v... Read more

    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0048

    The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service... Read more

    Affected Products : windows_2000
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-0105

    Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the "sys" group.... Read more

    Affected Products : hp-ux
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0102

    "Multiple Users" Control Panel in Mac OS 9 allows Normal users to gain Owner privileges by removing the Users & Groups Data File, which effectively removes the Owner password and allows the Normal user to log in as the Owner account without a password.... Read more

    Affected Products : macos
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0065

    Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command.... Read more

    Affected Products : bftpd
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0063

    procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges.... Read more

    Affected Products : freebsd
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-0067

    The installation of J-Pilot creates the .jpilot directory with the user's umask, which could allow local attackers to read other users' PalmOS backup information if their umasks are not securely set.... Read more

    Affected Products : jpilot
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0076

    register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed.... Read more

    Affected Products : ikonboard
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0074

    Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter.... Read more

    Affected Products : technote
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0081

    swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.... Read more

    Affected Products : ncipher
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0087

    itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.... Read more

    Affected Products : itetris
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0099

    bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.... Read more

    Affected Products : bsguest.cgi
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0024

    simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter.... Read more

    Affected Products : simplestmail.cgi
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-0082

    Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.... Read more

    Affected Products : firewall-1 vpn-1_firewall-1
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0011

    Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.... Read more

    Affected Products : bind
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0010

    Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.... Read more

    Affected Products : bind
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 6.2

    MEDIUM
    CVE-2001-0005

    Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.... Read more

    Affected Products : powerpoint
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0053

    One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.... Read more

    Affected Products : netbsd openbsd ftpd-bsd
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0014

    Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.... Read more

    Affected Products : windows_2000
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 293588 Results