Latest CVE Feed
-
7.2
HIGHCVE-2001-0084
GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.... Read more
Affected Products : gtk- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2001-0006
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the ... Read more
Affected Products : windows_nt- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0013
Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.... Read more
Affected Products : bind- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0098
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.... Read more
Affected Products : weblogic_server- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0096
FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.... Read more
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0022
simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter.... Read more
Affected Products : simplestguest.cgi- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0064
Webconfig, IMAP, and other services in MDaemon 3.5.0 and earlier allows remote attackers to cause a denial of service via a long URL terminated by a "\r\n" string.... Read more
Affected Products : mdaemon- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0075
Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter.... Read more
Affected Products : technote- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0012
BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.... Read more
Affected Products : bind- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0103
CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords.... Read more
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0895
Buffer overflow in HTTP server on the WatchGuard SOHO firewall allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long GET request.... Read more
Affected Products : soho_firewall- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0071
gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.... Read more
Affected Products : privacy_guard- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0101
Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.... Read more
Affected Products : fetchmail- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1453
Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.... Read more
Affected Products : mysql- Published: Feb. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1454
Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.... Read more
Affected Products : mysql- Published: Feb. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1468
PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code.... Read more
Affected Products : phpsecurepages- Published: Feb. 07, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1358
Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.... Read more
Affected Products : phpmychat- Published: Feb. 07, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1357
Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.... Read more
Affected Products : phpmychat- Published: Feb. 07, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1422
WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.... Read more
Affected Products : winvnc- Published: Jan. 23, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1274
Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.... Read more
Affected Products : mysql- Published: Jan. 23, 2001
- Modified: Apr. 03, 2025