Latest CVE Feed
-
5.0
MEDIUMCVE-2001-0286
Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.... Read more
Affected Products : http_server- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0281
Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.... Read more
Affected Products : windows_nt- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0288
Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.... Read more
Affected Products : ios- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2001-0273
pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in cleartext.... Read more
Affected Products : pgp4pine- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0294
Directory traversal vulnerability in TYPSoft FTP Server 0.85 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in a GET command, or (2) a ... in a CWD command.... Read more
Affected Products : typsoft_ftp_server- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0280
Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command.... Read more
Affected Products : mercur- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0234
NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.... Read more
Affected Products : newsdaemon- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0153
Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2001-0198
Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.... Read more
Affected Products : quicktime- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0218
Format string vulnerability in mars_nwe 0.99.pl19 allows remote attackers to execute arbitrary commands.... Read more
Affected Products : mars_nwe- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0326
Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the <<ALL FILES>> FilePe... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0304
Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request.... Read more
Affected Products : resin- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0305
Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in the StartID parameter.... Read more
Affected Products : es.one- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0272
Directory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the templ parameter.... Read more
Affected Products : sendtemp.pl- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0191
gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a ... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0270
Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set.... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0316
Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.... Read more
Affected Products : linux_kernel- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0283
Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.... Read more
Affected Products : sun_ftp- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1442
Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privileges via a long -c command line argument.... Read more
Affected Products : inn- Published: Apr. 21, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1325
Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulner... Read more
- Published: Apr. 20, 2001
- Modified: Apr. 03, 2025