Search
Total
25555 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2001-0560 | 1 Paul Vixie | 1 Vixie Cron | 2017-10-10 | 4.6 MEDIUM | N/A |
| Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters). | |||||
| CVE-2001-0563 | 1 Electrosoft | 1 Electrocomm | 2017-10-10 | 5.0 MEDIUM | N/A |
| ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via large (> 160000 character) strings sent to port 23. | |||||
| CVE-2001-0564 | 1 Apc | 1 Ap9606 | 2017-10-10 | 5.0 MEDIUM | N/A |
| APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of service via repeated failed logon attempts which temporarily locks the card. | |||||
| CVE-2001-0567 | 1 Zope | 1 Zope | 2017-10-10 | 4.6 MEDIUM | N/A |
| Digital Creations Zope 2.3.2 and earlier allows a local attacker to gain additional privileges via the changing of ZClass permission mappings for objects and methods in the ZClass. | |||||
| CVE-2001-0573 | 1 Ibm | 1 Aix | 2017-10-10 | 4.6 MEDIUM | N/A |
| lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory. | |||||
| CVE-2001-0574 | 1 Jason Rahaim | 1 Mp3mystic | 2017-10-10 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot) in the URL. | |||||
| CVE-2001-0717 | 1 Tooltalk | 1 Tooltalk Database Server | 2017-10-10 | 10.0 HIGH | N/A |
| Format string vulnerability in ToolTalk database server rpc.ttdbserverd allows remote attackers to execute arbitrary commands via format string specifiers that are passed to the syslog function. | |||||
| CVE-2001-0585 | 1 Gordano | 1 Ntmail | 2017-10-10 | 5.0 MEDIUM | N/A |
| Gordano NTMail 6.0.3c allows a remote attacker to create a denial of service via a long (>= 255 characters) URL request to port 8000 or port 9000. | |||||
| CVE-2001-0586 | 1 Trend Micro | 1 Scanmail Exchange | 2017-10-10 | 4.6 MEDIUM | N/A |
| TrendMicro ScanMail for Exchange 3.5 Evaluation allows a local attacker to recover the administrative credentials for ScanMail via a combination of unprotected registry keys and weakly encrypted passwords. | |||||
| CVE-2001-0792 | 1 Xchat | 1 Xchat | 2017-10-10 | 7.5 HIGH | N/A |
| Format string vulnerability in XChat 1.2.x allows remote attackers to execute arbitrary code via a malformed nickname. | |||||
| CVE-2001-0589 | 1 Juniper | 1 Netscreen Screenos | 2017-10-10 | 2.1 LOW | N/A |
| NetScreen ScreenOS prior to 2.5r6 on the NetScreen-10 and Netscreen-100 can allow a local attacker to bypass the DMZ 'denial' policy via specific traffic patterns. | |||||
| CVE-2001-0590 | 1 Apache | 1 Tomcat | 2017-10-10 | 5.0 MEDIUM | N/A |
| Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0). | |||||
| CVE-2001-0596 | 1 Netscape | 1 Communicator | 2017-10-10 | 7.5 HIGH | N/A |
| Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript. | |||||
| CVE-2001-0611 | 1 Rimarts Inc. | 1 Becky Internet Mail | 2017-10-10 | 7.5 HIGH | N/A |
| Becky! 2.00.05 and earlier can allow a remote attacker to gain additional privileges via a buffer overflow attack on long messages without newline characters. | |||||
| CVE-2001-0612 | 1 Mcafee | 1 Remote Desktop 32 | 2017-10-10 | 5.0 MEDIUM | N/A |
| McAfee Remote Desktop 3.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of packets to port 5045. | |||||
| CVE-2001-0613 | 1 Omnicron | 1 Omnihttpd | 2017-10-10 | 5.0 MEDIUM | N/A |
| Omnicron Technologies OmniHTTPD Professional 2.08 and earlier allows a remote attacker to create a denial of service via a long POST URL request. | |||||
| CVE-2001-0616 | 1 Faust Informatics | 1 Freestyle Chat | 2017-10-10 | 5.0 MEDIUM | N/A |
| Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (e.g., GET /aux HTTP/1.0). | |||||
| CVE-2001-0621 | 1 Cisco | 1 Content Services Switch 11000 | 2017-10-10 | 7.5 HIGH | N/A |
| The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands. | |||||
| CVE-2001-0622 | 1 Cisco | 1 Content Services Switch 11000 | 2017-10-10 | 7.5 HIGH | N/A |
| The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the interface. | |||||
| CVE-2001-0626 | 1 Oreilly | 1 Website Professional | 2017-10-10 | 7.5 HIGH | N/A |
| O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character. | |||||
| CVE-2001-0627 | 1 Sco | 1 Openserver | 2017-10-10 | 3.7 LOW | N/A |
| vi as included with SCO OpenServer 5.0 - 5.0.6 allows a local attacker to overwrite arbitrary files via a symlink attack. | |||||
| CVE-2001-0628 | 1 Microsoft | 1 Word | 2017-10-10 | 7.2 HIGH | N/A |
| Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user. | |||||
| CVE-2001-0630 | 1 Mimanet | 1 Source Viewer | 2017-10-10 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in MIMAnet viewsrc.cgi 2.0 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the 'loc' variable. | |||||
| CVE-2001-0631 | 1 Centrinity | 1 Centrinity Firstclass | 2017-10-10 | 5.0 MEDIUM | N/A |
| Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users. | |||||
| CVE-2001-0634 | 1 Sun | 1 Chilisoft | 2017-10-10 | 7.2 HIGH | N/A |
| Sun Chili!Soft ASP has weak permissions on various configuration files, which allows a local attacker to gain additional privileges and create a denial of service. | |||||
| CVE-2001-0635 | 1 Redhat | 1 Linux | 2017-10-10 | 4.6 MEDIUM | N/A |
| Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can allow a local attacker to gain additional privileges by reading sensitive information from the swap file, such as passwords. | |||||
| CVE-2001-0641 | 3 Immunix, Redhat, Suse | 3 Immunix, Linux, Suse Linux | 2017-10-10 | 4.6 MEDIUM | N/A |
| Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group man via a long -S option. | |||||
| CVE-2001-0644 | 1 Maxum Development Corporation | 1 Rumpus Ftp Server | 2017-10-10 | 7.5 HIGH | N/A |
| Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 stores passwords in plaintext in the "Rumpus User Database" file in the prefs folder, which could allow attackers to gain privileges on the server. | |||||
| CVE-2001-0646 | 1 Maxum Development Corporation | 1 Rumpus Ftp Server | 2017-10-10 | 5.0 MEDIUM | N/A |
| Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specific length. | |||||
| CVE-2001-0648 | 1 Phprojekt | 1 Phprojekt | 2017-10-10 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in PHProjekt 2.1 and earlier allows a remote attacker to conduct unauthorized activities via a dot dot (..) attack on the file module. | |||||
| CVE-2001-0650 | 1 Cisco | 1 Ios | 2017-10-10 | 5.0 MEDIUM | N/A |
| Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute. | |||||
| CVE-2001-0816 | 1 Openbsd | 1 Openssh | 2017-10-10 | 7.5 HIGH | N/A |
| OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypass authorized_keys2 command= restrictions using sftp commands. | |||||
| CVE-2001-0823 | 1 Sgi | 1 Performance Co-pilot | 2017-10-10 | 7.2 HIGH | N/A |
| The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCP_LOG_DIR). | |||||
| CVE-2001-0843 | 1 Squid | 1 Squid Web Proxy | 2017-10-10 | 5.0 MEDIUM | N/A |
| Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request. | |||||
| CVE-2001-0668 | 1 Hp | 1 Hp-ux | 2017-10-10 | 7.5 HIGH | N/A |
| Buffer overflow in line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to execute arbitrary commands. | |||||
| CVE-2001-0670 | 4 Bsd, Freebsd, Netbsd and 1 more | 4 Bsd, Freebsd, Netbsd and 1 more | 2017-10-10 | 7.5 HIGH | N/A |
| Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue. | |||||
| CVE-2001-0675 | 1 Ritlabs | 1 The Bat | 2017-10-10 | 5.0 MEDIUM | N/A |
| Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a carriage return <CR> that is not followed by a line feed <LF>. | |||||
| CVE-2001-0676 | 1 Ritlabs | 1 The Bat | 2017-10-10 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in Rit Research Labs The Bat! 1.48f and earlier allows a remote attacker to create arbitrary files via a "dot dot" attack in the filename for an attachment. | |||||
| CVE-2001-0677 | 1 Qualcomm | 1 Eudora | 2017-10-10 | 5.0 MEDIUM | N/A |
| Eudora 5.0.2 allows a remote attacker to read arbitrary files via an email with the path of the target file in the "Attachment Converted" MIME header, which sends the file when the email is forwarded to the attacker by the user. | |||||
| CVE-2001-0741 | 1 Cisco | 1 Hsrp | 2017-10-10 | 2.1 LOW | N/A |
| Cisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets. | |||||
| CVE-2001-0680 | 1 Qpc Software | 2 Avt Term, Qvt Net | 2017-10-10 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a "dot dot" attack in a LIST (ls) command. | |||||
| CVE-2001-0682 | 1 Zonelabs | 1 Zonealarm | 2017-10-10 | 2.1 LOW | N/A |
| ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting. | |||||
| CVE-2001-0685 | 1 Thibault Godouet | 1 Fcron | 2017-10-10 | 2.6 LOW | N/A |
| Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file. | |||||
| CVE-2001-0690 | 4 Conectiva, Debian, Redhat and 1 more | 4 Linux, Debian Linux, Linux and 1 more | 2017-10-10 | 7.5 HIGH | N/A |
| Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers. | |||||
| CVE-2001-0692 | 1 Watchguard | 2 Firebox 2500, Firebox 4500 | 2017-10-10 | 7.5 HIGH | N/A |
| SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and 4.6 allows a remote attacker to bypass firewall filtering via a base64 MIME encoded email attachment whose boundary name ends in two dashes. | |||||
| CVE-2001-0873 | 1 Ian Lance Taylor | 1 Taylor Uucp | 2017-10-10 | 7.2 HIGH | N/A |
| uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privileges by calling uux and specifying an alternate configuration file with the --config option. | |||||
| CVE-2001-0696 | 1 Netwin | 1 Surgeftp | 2017-10-10 | 5.0 MEDIUM | N/A |
| NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con. | |||||
| CVE-2001-0697 | 1 Netwin | 1 Surgeftp | 2017-10-10 | 5.0 MEDIUM | N/A |
| NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command. | |||||
| CVE-2001-0698 | 1 Netwin | 1 Surgeftp | 2017-10-10 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command. | |||||
| CVE-2001-0700 | 1 W3m | 1 W3m | 2017-10-10 | 7.5 HIGH | N/A |
| Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header. | |||||
