Latest CVE Feed
-
7.5
HIGHCVE-2001-1389
Multiple vulnerabilities in xinetd 2.3.0 and earlier, and additional variants until 2.3.3, may allow remote attackers to cause a denial of service or execute arbitrary code, primarily via buffer overflows or improper NULL termination.... Read more
- Published: Aug. 29, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1153
lpsystem in OpenUnix 8.0.0 allows local users to cause a denial of service and possibly execute arbitrary code via a long command line argument.... Read more
Affected Products : openunix- Published: Aug. 28, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1444
The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption options sent from the server, which allows remote attackers to downgrade authentication and encryption mechanisms via ... Read more
Affected Products : kth_kerberos- Published: Aug. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1443
KTH Kerberos IV and Kerberos V (Heimdal) for Telnet clients do not encrypt connections if the server does not support the requested encryption, which allows remote attackers to read communications via a man-in-the-middle attack.... Read more
Affected Products : kth_kerberos- Published: Aug. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1455
Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters.... Read more
Affected Products : siteminder- Published: Aug. 24, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1091
The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.... Read more
Affected Products : netbsd- Published: Aug. 23, 2001
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2001-1155
TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spoofing.... Read more
Affected Products : freebsd- Published: Aug. 23, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0576
lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the '-u' command line parameter.... Read more
Affected Products : openserver- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1139
Directory traversal vulnerability in ASCII NT WinWrapper Professional allows remote attackers to read arbitrary files via a .. (dot dot) in the server request.... Read more
Affected Products : winwrapper_professional- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0612
McAfee Remote Desktop 3.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of packets to port 5045.... Read more
Affected Products : remote_desktop_32- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0578
Buffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a long first argument to the lpforms command.... Read more
Affected Products : openserver- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0571
Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the requested URL.... Read more
- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0589
NetScreen ScreenOS prior to 2.5r6 on the NetScreen-10 and Netscreen-100 can allow a local attacker to bypass the DMZ 'denial' policy via specific traffic patterns.... Read more
Affected Products : netscreen_screenos- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0580
Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting to port 6070, sending some data, and closing the connection.... Read more
Affected Products : dsl_vdns- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0394
Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory.... Read more
Affected Products : website_pro- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0560
Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters).... Read more
Affected Products : vixie_cron- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0556
The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users' files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file.... Read more
Affected Products : nedit- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0357
FormMail.pl in FormMail 1.6 and earlier allows a remote attacker to send anonymous email (spam) by modifying the recipient and message parameters.... Read more
Affected Products : formmail- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0586
TrendMicro ScanMail for Exchange 3.5 Evaluation allows a local attacker to recover the administrative credentials for ScanMail via a combination of unprotected registry keys and weakly encrypted passwords.... Read more
Affected Products : scanmail_exchange- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0582
Ben Spink CrushFTP FTP Server 2.1.6 and earlier allows a local attacker to access arbitrary files via a '..' (dot dot) attack, or variations, in (1) GET, (2) CD, (3) NLST, (4) SIZE, (5) RETR.... Read more
Affected Products : crushftp_ftp_server- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025