Latest CVE Feed
-
5.0
MEDIUMCVE-2001-0337
The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.... Read more
Affected Products : internet_information_server- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0425
AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to verify login information.... Read more
Affected Products : adcycle- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0358
Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.... Read more
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0415
REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts.... Read more
Affected Products : rediplus- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0471
SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.... Read more
Affected Products : ssh- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0416
sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users to read files that are being processed by sgml-tools.... Read more
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0407
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).... Read more
Affected Products : mysql- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0441
Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.... Read more
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0484
Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the p... Read more
Affected Products : phaserlink- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0328
TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN.... Read more
Affected Products :- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0452
BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.... Read more
Affected Products : webweaver- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0378
readline prior to 4.1, in OpenBSD 2.8 and earlier, creates history files with insecure permissions, which allows a local attacker to recover potentially sensitive information via readline history files.... Read more
Affected Products : openbsd- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0241
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.... Read more
Affected Products : windows_2000- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0359
Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.... Read more
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0479
Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.... Read more
Affected Products : phppgadmin- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0339
Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."... Read more
Affected Products : internet_explorer- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0369
Buffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line argument (non-existent printer name).... Read more
Affected Products : unix- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0461
template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell metacharacters in the argument to template.cgi.... Read more
Affected Products : foldoc- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0454
Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in the HTTP request.... Read more
Affected Products : slimserve- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0334
FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.... Read more
Affected Products : internet_information_server- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025