Latest CVE Feed
-
7.5
HIGHCVE-2001-0292
PHP-Nuke 4.4.1a allows remote attackers to modify a user's email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator.... Read more
Affected Products : php-nuke- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0228
Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request.... Read more
Affected Products : goahead_webserver- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0199
Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the HTTP GET request.... Read more
Affected Products : sedum- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0269
pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password.... Read more
Affected Products : sunos- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0236
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2001-0167
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.... Read more
Affected Products : winvnc- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0147
Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records.... Read more
Affected Products : windows_2000- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0293
Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.... Read more
Affected Products : ftpxq- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0192
Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.... Read more
Affected Products : xmail- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0179
Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed URL that contains a "."... Read more
Affected Products : jrun- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0280
Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command.... Read more
Affected Products : mercur- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2001-0174
Buffer overflow in Trend Micro Virus Buster 2001 8.00 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a large "To" address.... Read more
Affected Products : virus_buster_2001- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0288
Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.... Read more
Affected Products : ios- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0321
opendir.php script in PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter.... Read more
Affected Products : php-nuke- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0234
NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.... Read more
Affected Products : newsdaemon- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0320
bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.... Read more
Affected Products : php-nuke- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0281
Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.... Read more
Affected Products : windows_nt- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0294
Directory traversal vulnerability in TYPSoft FTP Server 0.85 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in a GET command, or (2) a ... in a CWD command.... Read more
Affected Products : typsoft_ftp_server- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0218
Format string vulnerability in mars_nwe 0.99.pl19 allows remote attackers to execute arbitrary commands.... Read more
Affected Products : mars_nwe- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2001-0198
Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.... Read more
Affected Products : quicktime- Published: May. 03, 2001
- Modified: Apr. 03, 2025