Latest CVE Feed
-
7.5
HIGHCVE-2001-0299
Buffer overflow in Voyager web administration server for Nokia IP440 allows local users to cause a denial of service, and possibly execute arbitrary commands, via a long URL.... Read more
Affected Products : ip440_firewall_vpn_appliance- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2001-0259
ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker can use to decrypt that user's private key file.... Read more
Affected Products : ssh- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0252
iPlanet (formerly Netscape) Enterprise Server 4.1 allows remote attackers to cause a denial of service via a long HTTP GET request that contains many "/../" (dot dot) sequences.... Read more
Affected Products : iplanet_enterprise_server- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0260
Buffer overflow in Lotus Domino Mail Server 5.0.5 and earlier allows a remote attacker to crash the server or execute arbitrary code via a long "RCPT TO" command.... Read more
Affected Products : domino_mail_server- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0318
Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd).... Read more
Affected Products : proftpd- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0225
fortran math component in Infobot 0.44.5.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.... Read more
Affected Products : infobot- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0215
ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename with a null byte.... Read more
Affected Products : roads- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0310
sort in FreeBSD 4.1.1 and earlier, and possibly other operating systems, uses predictable temporary file names and does not properly handle when the temporary file already exists, which causes sort to crash and possibly impacts security-sensitive scripts.... Read more
Affected Products : freebsd- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2001-0150
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services f... Read more
Affected Products : internet_explorer- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0217
Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.... Read more
Affected Products : webpals- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0315
The locking feature in mIRC 5.7 allows local users to bypass the password mechanism by modifying the LockOptions registry key.... Read more
Affected Products : mirc- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0258
The Easycom/Safecom Print Server (firmware 404.590) PrintGuide server allows remote attackers to cause a denial of service via a large number of connections that send null characters.... Read more
Affected Products : easycom_safecom_print_server- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0313
Borderware Firewall Server 6.1.2 allows remote attackers to cause a denial of service via a ping to the broadcast address of the public network on which the server is placed, which causes the server to continuously send pings (echo requests) to the networ... Read more
Affected Products : firewall_server- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0254
FaSTream FTP++ Server 2.0 allows remote attackers to obtain the real pathname of the server via the "pwd" command.... Read more
Affected Products : ftp\+\+_server- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0001
cookiedecode function in PHP-Nuke 4.4 allows users to bypass authentication and gain access to other user accounts by extracting the authentication information from a cookie.... Read more
Affected Products : php-nuke- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0156
VShell SSH gateway 1.0.1 and earlier has a default port forwarding rule of 0.0.0.0/0.0.0.0, which could allow local users to conduct arbitrary port forwarding to other systems.... Read more
Affected Products : vshell- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0250
The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command.... Read more
Affected Products : enterprise_server- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0253
Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.... Read more
Affected Products : hyperseek- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0224
Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.... Read more
Affected Products : muscat_empower- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0212
Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.... Read more
Affected Products : auktion- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025