Latest CVE Feed
-
10.0
HIGHCVE-2001-0060
Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.... Read more
Affected Products : stunnel- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0106
Vulnerability in inetd server in HP-UX 11.04 and earlier allows attackers to cause a denial of service when the "swait" state is used by a server.... Read more
Affected Products : hp-ux- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0048
The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service... Read more
Affected Products : windows_2000- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0094
Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library) in NetBSD 1.5 and FreeBSD 4.2 and earlier, as used in Kerberised applications such as telnetd and login, allows local users to gain root privileges.... Read more
Affected Products : freebsd- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0061
procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by forking a child process and executing a privileged process from the child, while... Read more
Affected Products : freebsd- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0004
IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading v... Read more
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0095
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.... Read more
Affected Products : sunos- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0100
bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.... Read more
Affected Products : bslist.cgi- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0026
rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option.... Read more
Affected Products : pppoe- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0072
gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.... Read more
Affected Products : privacy_guard- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0025
ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.... Read more
Affected Products : ad.cgi- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0003
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka... Read more
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0028
Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of " (quotation) characters.... Read more
Affected Products : oops_proxy_server- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0097
The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request.... Read more
Affected Products : infinite_interchange- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0064
Webconfig, IMAP, and other services in MDaemon 3.5.0 and earlier allows remote attackers to cause a denial of service via a long URL terminated by a "\r\n" string.... Read more
Affected Products : mdaemon- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0012
BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.... Read more
Affected Products : bind- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0075
Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter.... Read more
Affected Products : technote- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0022
simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter.... Read more
Affected Products : simplestguest.cgi- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0104
MDaemon Pro 3.5.1 and earlier allows local users to bypass the "lock server" security setting by pressing the Cancel button at the password prompt, then pressing the enter key.... Read more
Affected Products : mdaemon- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2001-0068
Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter.... Read more
Affected Products : mac_os_runtime_for_java- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025