Latest CVE Feed
-
5.0
MEDIUMCVE-2001-1434
Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topology information via an "snmp-server host" command, which creates a readable "community" community string if one has not been previously created.... Read more
Affected Products : ios- Published: Feb. 28, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1776
Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data via the cable-docsis read-write community string used by the Data Over Cable Service Interface Specification (DOCSIS) standard.... Read more
Affected Products : ios- Published: Feb. 28, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1435
inetd in Compaq Tru64 UNIX 5.1 allows attackers to cause a denial of service (network connection loss) by causing one of the services handled by inetd to core dump during startup, which causes inetd to stop accepting connections to all of its services.... Read more
Affected Products : tru64- Published: Feb. 23, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0036
KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.... Read more
Affected Products : kth_kerberos- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0033
KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges... Read more
- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0056
The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.... Read more
Affected Products : broadband_operating_system- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0054
Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.... Read more
Affected Products : serv-u_file_server- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2001-0090
The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the "Browser Print Template" vulnerability.... Read more
Affected Products : internet_explorer- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0088
common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.... Read more
Affected Products : phpweblog- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0046
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permiss... Read more
- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0031
BroadVision One-To-One Enterprise allows remote attackers to determine the physical path of server files by requesting a .JSP file name that does not exist.... Read more
Affected Products : one-to-one_enterprise_server- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0039
IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.... Read more
Affected Products : imail- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0047
The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilit... Read more
Affected Products : windows_nt- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0045
The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.... Read more
Affected Products : windows_nt- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0057
Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.... Read more
- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2001-0091
The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.... Read more
Affected Products : internet_explorer- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0038
Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in the requested URL.... Read more
Affected Products : offline_explorer- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0035
Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request.... Read more
Affected Products : kth_kerberos- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0058
The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character.... Read more
- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0052
IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.... Read more
Affected Products : db2_universal_database- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025