Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2001-1476

    SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages dependin... Read more

    Affected Products : ssh
    • Published: Jan. 18, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1385

    The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.... Read more

    Affected Products : php mandrake_linux
    • Published: Jan. 12, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1044

    Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the... Read more

    Affected Products : basilix_webmail
    • Published: Jan. 11, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1464

    Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.... Read more

    Affected Products : crystal_reports
    • Published: Jan. 10, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2000-1134

    Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a sy... Read more

    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2000-1169

    OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent.... Read more

    Affected Products : openssh
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2000-1176

    Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field.... Read more

    Affected Products : yabb
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2000-1084

    The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows a... Read more

    Affected Products : sql_server sql_server data_engine
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1152

    Browser IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.... Read more

    Affected Products : beos
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2000-1183

    Buffer overflow in socks5 server on Linux allows attackers to execute arbitrary commands via a long connection request.... Read more

    Affected Products : socks_5
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2000-1123

    Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.... Read more

    Affected Products : aix
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2000-1115

    Buffer overflow in remote web administration component (webprox.dll) of 602Pro LAN SUITE before 2000.0.1.33 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.... Read more

    Affected Products : 602pro_lan_suite
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2000-1135

    fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.... Read more

    Affected Products : debian_linux
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2000-1093

    Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.... Read more

    Affected Products : instant_messenger
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2000-1137

    GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack.... Read more

    Affected Products : ed linux
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1117

    The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.... Read more

    Affected Products : lotus_notes
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1181

    Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including sensitive information, by accessing the /admin/includes/ URL.... Read more

    Affected Products : realserver
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2000-1136

    elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack.... Read more

    Affected Products : elvis_tiny
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1165

    Balabit syslog-ng allows remote attackers to cause a denial of service (application crash) via a malformed log message that does not have a closing > in the priority specifier.... Read more

    Affected Products : syslog-ng
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2000-1166

    Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.... Read more

    Affected Products : twig
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 293592 Results