Latest CVE Feed
-
4.6
MEDIUMCVE-2001-0157
Debugging utility in the backdoor mode of Palm OS 3.5.2 and earlier allows attackers with physical access to a Palm device to bypass access restrictions and obtain passwords, even if the system lockout mechanism is enabled.... Read more
Affected Products : palm_os- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0208
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.... Read more
Affected Products : cobol- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0299
Buffer overflow in Voyager web administration server for Nokia IP440 allows local users to cause a denial of service, and possibly execute arbitrary commands, via a long URL.... Read more
Affected Products : ip440_firewall_vpn_appliance- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0322
MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.... Read more
- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0300
oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.... Read more
Affected Products : internet_directory- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0260
Buffer overflow in Lotus Domino Mail Server 5.0.5 and earlier allows a remote attacker to crash the server or execute arbitrary code via a long "RCPT TO" command.... Read more
Affected Products : domino_mail_server- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0252
iPlanet (formerly Netscape) Enterprise Server 4.1 allows remote attackers to cause a denial of service via a long HTTP GET request that contains many "/../" (dot dot) sequences.... Read more
Affected Products : iplanet_enterprise_server- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0225
fortran math component in Infobot 0.44.5.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.... Read more
Affected Products : infobot- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0164
Buffer overflow in Netscape Directory Server 4.12 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed recipient field.... Read more
Affected Products : directory_server- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0206
Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into the requested pathname of an HTTP GET request.... Read more
Affected Products : serverworx- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0221
Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.... Read more
Affected Products : ja-xklock- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0214
Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.... Read more
Affected Products : way-board- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2001-0259
ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker can use to decrypt that user's private key file.... Read more
Affected Products : ssh- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0210
Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page parameter.... Read more
Affected Products : commerce.cgi- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0220
Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.... Read more
- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0251
The Web Publishing feature in Netscape Enterprise Server 3.x allows remote attackers to cause a denial of service via the REVLOG command.... Read more
Affected Products : enterprise_server- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0323
The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to low... Read more
Affected Products : solaris- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0257
Buffer overflow in Easycom/Safecom Print Server Web service, version 404.590 and earlier, allows remote attackers to execute arbitrary commands via (1) a long URL or (2) a long HTTP header field such as "Host:".... Read more
Affected Products : easycom_safecom_print_server- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0311
Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client.... Read more
- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0148
The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.... Read more
- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025