Latest CVE Feed
-
4.6
MEDIUMCVE-2001-0316
Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.... Read more
Affected Products : linux_kernel- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0270
Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set.... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0283
Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.... Read more
Affected Products : sun_ftp- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0180
Lars Ellingsen guestserver.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the "email" parameter.... Read more
Affected Products : guestserver- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0325
Buffer overflow in QNX RTP 5.60 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large number of arguments to the stat command.... Read more
Affected Products : rtp- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0200
HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled.... Read more
Affected Products : hsweb- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0305
Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in the StartID parameter.... Read more
Affected Products : es.one- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0326
Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the <<ALL FILES>> FilePe... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0320
bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.... Read more
Affected Products : php-nuke- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0192
Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.... Read more
Affected Products : xmail- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2001-0174
Buffer overflow in Trend Micro Virus Buster 2001 8.00 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a large "To" address.... Read more
Affected Products : virus_buster_2001- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0205
Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested pathname, a modified .. (dot dot) attack.... Read more
Affected Products : aol_server- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0218
Format string vulnerability in mars_nwe 0.99.pl19 allows remote attackers to execute arbitrary commands.... Read more
Affected Products : mars_nwe- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2001-0273
pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in cleartext.... Read more
Affected Products : pgp4pine- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0234
NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.... Read more
Affected Products : newsdaemon- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0179
Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed URL that contains a "."... Read more
Affected Products : jrun- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0293
Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.... Read more
Affected Products : ftpxq- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0281
Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.... Read more
Affected Products : windows_nt- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0275
Moby Netsuite Web Server 1.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.... Read more
Affected Products : netsuite_web_server- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2001-0198
Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.... Read more
Affected Products : quicktime- Published: May. 03, 2001
- Modified: Apr. 03, 2025