Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2001-0027

    mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users.... Read more

    Affected Products : proftpd
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0070

    Buffer overflow in 1st Up Mail Server 4.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long MAIL FROM command.... Read more

    Affected Products : 1st_up_mail_server
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0100

    bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.... Read more

    Affected Products : bslist.cgi
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0072

    gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.... Read more

    Affected Products : privacy_guard
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0026

    rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option.... Read more

    Affected Products : pppoe
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0025

    ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.... Read more

    Affected Products : ad.cgi
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0101

    Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.... Read more

    Affected Products : fetchmail
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-0071

    gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.... Read more

    Affected Products : privacy_guard
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0011

    Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.... Read more

    Affected Products : bind
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0074

    Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter.... Read more

    Affected Products : technote
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0010

    Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.... Read more

    Affected Products : bind
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2001-0067

    The installation of J-Pilot creates the .jpilot directory with the user's umask, which could allow local attackers to read other users' PalmOS backup information if their umasks are not securely set.... Read more

    Affected Products : jpilot
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0024

    simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter.... Read more

    Affected Products : simplestmail.cgi
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0063

    procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges.... Read more

    Affected Products : freebsd
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0065

    Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command.... Read more

    Affected Products : bftpd
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0099

    bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.... Read more

    Affected Products : bsguest.cgi
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0081

    swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.... Read more

    Affected Products : ncipher
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 6.2

    MEDIUM
    CVE-2001-0005

    Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.... Read more

    Affected Products : powerpoint
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2001-0087

    itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.... Read more

    Affected Products : itetris
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-0014

    Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.... Read more

    Affected Products : windows_2000
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 293612 Results