Latest CVE Feed
-
7.5
HIGHCVE-2001-0027
mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users.... Read more
Affected Products : proftpd- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0896
WatchGuard SOHO firewall allows remote attackers to cause a denial of service via a flood of fragmented IP packets, which causes the firewall to drop connections and stop forwarding packets.... Read more
Affected Products : soho_firewall- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0105
Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the "sys" group.... Read more
Affected Products : hp-ux- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0048
The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service... Read more
Affected Products : windows_2000- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0060
Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.... Read more
Affected Products : stunnel- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0078
in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.... Read more
Affected Products : cluster- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0008
Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.... Read more
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0023
everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.... Read more
Affected Products : everythingform.cgi- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0077
The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations.... Read more
Affected Products : cluster- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0073
Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory.... Read more
Affected Products : security-enhanced_linux- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0013
Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.... Read more
Affected Products : bind- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0096
FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.... Read more
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0098
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.... Read more
Affected Products : weblogic_server- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2001-0006
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the ... Read more
Affected Products : windows_nt- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0067
The installation of J-Pilot creates the .jpilot directory with the user's umask, which could allow local attackers to read other users' PalmOS backup information if their umasks are not securely set.... Read more
Affected Products : jpilot- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0076
register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed.... Read more
Affected Products : ikonboard- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0019
Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands.... Read more
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0014
Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.... Read more
Affected Products : windows_2000- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0053
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.... Read more
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2001-0005
Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.... Read more
Affected Products : powerpoint- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025