Latest CVE Feed
-
7.5
HIGHCVE-2001-1386
WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension.... Read more
Affected Products : wftpd- Published: Jul. 01, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1043
ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.... Read more
Affected Products : ftp_server- Published: Jul. 01, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1246
PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.... Read more
Affected Products : php- Published: Jun. 30, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1248
vWebServer 1.2.0 allows remote attackers to view arbitrary ASP scripts via a request for an ASP script that ends with a URL-encoded space character (%20).... Read more
Affected Products : vwebserver- Published: Jun. 29, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1249
vWebServer 1.2.0 allows remote attackers to cause a denial of service via a URL that contains MS-DOS device names.... Read more
Affected Products : vwebserver- Published: Jun. 29, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1250
vWebServer 1.2.0 allows remote attackers to cause a denial of service (hang) via a small number of long URL requests, possibly due to a buffer overflow.... Read more
Affected Products : vwebserver- Published: Jun. 29, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1239
PowerNet IX allows remote attackers to cause a denial of service via a port scan.... Read more
Affected Products : powernet_ix- Published: Jun. 29, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1251
SmallHTTP 1.204 through 3.00 beta 8 allows remote attackers to cause a denial of service via multiple long URL requests.... Read more
- Published: Jun. 29, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1290
admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration, gain privileges, and execute arbitrary Perl code via the table_width parameter.... Read more
Affected Products : active_classifieds- Published: Jun. 28, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0470
Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.... Read more
Affected Products : sunos- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0472
Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.... Read more
Affected Products : high_availability_cluster_multiprocessing- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0332
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain... Read more
Affected Products : internet_explorer- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0368
Directory traversal vulnerability in BearShare 2.2.2 and earlier allows a remote attacker to read certain files via a URL containing a series of . characters, a variation of the .. (dot dot) attack.... Read more
Affected Products : bearshare- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0462
Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.... Read more
Affected Products : perl_web_server- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0330
Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.... Read more
Affected Products : bugzilla- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0495
Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack.... Read more
Affected Products : webxq- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0488
pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.... Read more
Affected Products : hp-ux- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0476
Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter.... Read more
Affected Products : aspseek- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0492
Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3.... Read more
Affected Products : netcruiser_web_server- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0336
The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.... Read more
Affected Products : internet_information_server- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025