Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1221 1 D-link 1 Dwl-1000ap 2008-09-05 5.0 MEDIUM N/A
D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of 'public' which allows remote attackers to gain sensitive information.
CVE-2001-1131 1 Whitsoft Development 1 Slimftpd 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in WhitSoft Development SlimFTPd 2.2 allows an attacker to read arbitrary files and directories via a ... (modified dot dot) in the CD command.
CVE-2001-1222 1 Plesk 1 Plesk Server Administrator 2008-09-05 5.0 MEDIUM N/A
Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.
CVE-2001-1223 1 Elsa 1 Lancom 1100 Office 2008-09-05 10.0 HIGH N/A
The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server.
CVE-2001-1155 1 Freebsd 1 Freebsd 2008-09-05 7.5 HIGH N/A
TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spoofing.
CVE-2001-1150 1 Trend Micro 2 Officescan, Virus Buster 2008-09-05 5.0 MEDIUM N/A
Vulnerability in cgiWebupdate.exe in Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.5.2 through 3.5.4 allows remote attackers to read arbitrary files.
CVE-2001-0971 1 Aci 1 4d Webserver 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in ACI 4d webserver allows remote attackers to read arbitrary files via a .. (dot dot) or drive letter (e.g., C:) in an HTTP request.
CVE-2001-1156 1 Typsoft 1 Typsoft Ftp Server 2008-09-05 5.0 MEDIUM N/A
TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1) STOR or (2) RETR.
CVE-2001-1147 1 Andries Brouwer 1 Util-linux 2008-09-05 7.2 HIGH N/A
The PAM implementation in /bin/login of the util-linux package before 2.11 causes a password entry to be rewritten across multiple PAM calls, which could provide the credentials of one user to a different user, when used in certain PAM modules such as pam_limits.
CVE-2001-1157 1 Baltimore Technologies 1 Websweeper 2008-09-05 7.5 HIGH N/A
Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using Unicode.
CVE-2001-0968 1 Knox Software 1 Arkeia 2008-09-05 10.0 HIGH N/A
Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges.
CVE-2001-0967 1 Knox Software 1 Arkeia 2008-09-05 7.5 HIGH N/A
Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.
CVE-2001-0966 1 Nudester.org 1 Nudester 2008-09-05 10.0 HIGH N/A
Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the CD (CWD) command.
CVE-2001-1159 1 Squirrelmail 1 Squirrelmail 2008-09-05 7.5 HIGH N/A
load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary code by using options_order.php to upload a message that could be interpreted as PHP.
CVE-2001-1161 1 Lotus 1 Domino R5 Server 2008-09-05 7.5 HIGH N/A
Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.
CVE-2001-1163 1 Munica 1 Netsql 2008-09-05 10.0 HIGH N/A
Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.
CVE-2001-1164 1 Caldera 1 Unixware 2008-09-05 7.2 HIGH N/A
Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.
CVE-2001-0965 1 Glftpd 1 Glftpd 2008-09-05 5.0 MEDIUM N/A
glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.
CVE-2001-1110 1 Khamil Landross And Zack Jones 1 Eftp 2008-09-05 5.0 MEDIUM N/A
EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.
CVE-2001-0976 1 Hp 1 Process Resource Manager 2008-09-05 7.2 HIGH N/A
Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables.
CVE-2001-0978 1 Hp 1 Hp-ux 2008-09-05 7.5 HIGH N/A
login in HP-UX 10.26 does not record failed login attempts in /var/adm/btmp, which could allow attackers to conduct brute force password guessing attacks without being detected or observed using the lastb program.
CVE-2001-1165 1 Intego 2 Diskguard, Fileguard 2008-09-05 4.6 MEDIUM N/A
Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by decrypting the information, e.g., with the Disengage tool.
CVE-2001-1025 1 Francisco Burzi 1 Php-nuke 2008-09-05 10.0 HIGH N/A
PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.
CVE-2001-1166 1 Freebsd 1 Freebsd 2008-09-05 5.0 MEDIUM N/A
linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.
CVE-2001-0866 1 Cisco 1 12000 Router 2008-09-05 7.5 HIGH N/A
Cisco 12000 with IOS 12.0 and lines card based on Engine 2 does not properly handle an outbound ACL when an input ACL is not configured on all the interfaces of a multi port line card, which could allow remote attackers to bypass the intended access controls.
CVE-2001-0840 1 Compaq 1 Insight Manager Xe 2008-09-05 10.0 HIGH N/A
Buffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI.
CVE-2001-1143 1 Ibm 1 Db2 Universal Database 2008-09-05 5.0 MEDIUM N/A
IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.
CVE-2001-0943 1 Oracle 1 Database Server 2008-09-05 7.2 HIGH N/A
dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse programs.
CVE-2001-1039 1 Hp 1 Jetadmin 2008-09-05 7.5 HIGH N/A
The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer.
CVE-2001-1040 1 Hp 1 Jetadmin 2008-09-05 6.4 MEDIUM N/A
HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password.
CVE-2001-1048 1 Topher1kenobe 1 Awol 2008-09-05 7.5 HIGH N/A
AWOL PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
CVE-2001-1082 2 Lucent, Simon Horms 2 Radius, Radius 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2001-1081 2 Lucent, Simon Horms 2 Radius, Radius 2008-09-05 7.5 HIGH N/A
Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via format specifiers that are injected into log messages.
CVE-2001-1169 1 Bell Communications Research 1 S Key 2008-09-05 7.5 HIGH N/A
keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo.
CVE-2001-1171 1 Checkpoint 1 Firewall-1 2008-09-05 7.2 HIGH N/A
Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy.
CVE-2001-0989 1 Richard Everitt 1 Pileup 2008-09-05 7.2 HIGH N/A
Buffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or (2) a long callsign.
CVE-2001-1179 1 Xfree86 Project 1 X11r6 2008-09-05 7.2 HIGH N/A
xman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters.
CVE-2001-1004 1 Gnutella 1 Gnutella Client 2008-09-05 5.0 MEDIUM N/A
Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name contains the script tags.
CVE-2001-1142 1 Argosoft 1 Ftp Server 2008-09-05 5.0 MEDIUM N/A
ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the password file to gain privileges.
CVE-2001-1061 1 Ibm 1 Aix 2008-09-05 10.0 HIGH N/A
Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.
CVE-2001-0742 1 Computalynx 1 Cmail 2008-09-05 7.5 HIGH N/A
Buffer overflow in Computalynx CMail POP3 mail server 2.4.9 allows remote attackers to run arbitrary code via a long HELO command.
CVE-2001-0420 1 Way To The Web 1 Talkback 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.
CVE-2001-0418 1 Ncm 1 Ncm Content Management System 2008-09-05 5.0 MEDIUM N/A
content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.
CVE-2001-0688 1 Transsoft 1 Broker Ftp Server 2008-09-05 5.0 MEDIUM N/A
Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command.
CVE-2001-0689 1 Trend Micro 1 Virus Control System 2008-09-05 7.5 HIGH N/A
Vulnerability in TrendMicro Virus Control System 1.8 allows a remote attacker to view configuration files and change the configuration via a certain CGI program.
CVE-2001-0691 1 University Of Washington 1 Imapd 2008-09-05 4.6 MEDIUM N/A
Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.
CVE-2001-0480 1 Alex Linde 1 Alexs Ftp Server 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Alex's FTP Server 0.7 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the (1) GET or (2) CD commands.
CVE-2001-0795 1 Perception 1 Liteserve 2008-09-05 5.0 MEDIUM N/A
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names.
CVE-2001-0713 1 Sendmail 1 Sendmail 2008-09-05 4.6 MEDIUM N/A
Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the high bit set, such as (1) macro names that are one character long, (2) a variable setting which is processed by the setoption function, or (3) a Modifiers setting which is processed by the getmodifiers function.
CVE-2001-0743 1 Oreilly 1 Webboard 2008-09-05 5.0 MEDIUM N/A
Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followed by JavaScript commands.