Latest CVE Feed
-
5.0
MEDIUMCVE-2001-1469
The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message's cyclic redundancy check (CRC) with the CRC of a mask consisting of all the bits of the original message that were modified.... Read more
Affected Products : ssh- Published: Jan. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1470
The IDEA cipher as implemented by SSH1 does not protect the final block of a message against modification, which allows remote attackers to modify the block without detection by changing its cyclic redundancy check (CRC) to match the modifications to the ... Read more
Affected Products : ssh- Published: Jan. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1385
The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.... Read more
- Published: Jan. 12, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1044
Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the... Read more
Affected Products : basilix_webmail- Published: Jan. 11, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1464
Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.... Read more
Affected Products : crystal_reports- Published: Jan. 10, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1150
Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.... Read more
Affected Products : felix- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1125
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.... Read more
Affected Products : linux- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-1083
The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an at... Read more
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0899
Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests.... Read more
Affected Products : small_http_server- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1166
Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.... Read more
Affected Products : twig- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1122
Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.... Read more
Affected Products : aix- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1177
bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine the existence of files and user ID's by specifying the target file in the HISTFILE parameter.... Read more
Affected Products : big_brother_network_monitor- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1184
telnetd in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service by specifying an arbitrary large file in the TERMCAP environmental variable, which consumes resources as the server processes th... Read more
Affected Products : freebsd- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1136
elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack.... Read more
Affected Products : elvis_tiny- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1189
Buffer overflow in pam_localuser PAM module in Red Hat Linux 7.x and 6.x allows attackers to gain privileges.... Read more
Affected Products : linux- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2000-1156
StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.... Read more
Affected Products : staroffice- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1165
Balabit syslog-ng allows remote attackers to cause a denial of service (application crash) via a malformed log message that does not have a closing > in the priority specifier.... Read more
Affected Products : syslog-ng- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1149
Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the "Terminal Server Login Buffer Overflow" vulnerability.... Read more
Affected Products : windows_nt- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1161
The installation of AdCycle banner management system leaves the build.cgi program in a web-accessible directory, which allows remote attackers to execute the program and view passwords or delete databases.... Read more
Affected Products : adcycle- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1107
in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request, which causes the server to access a NULL pointer and crash.... Read more
Affected Products : suse_linux- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025