Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0160 2 Lucent, Orinoco 2 Wavelan, Orinoco Wavelan 2008-09-05 5.0 MEDIUM N/A
Lucent/ORiNOCO WaveLAN cards generate predictable Initialization Vector (IV) values for the Wireless Encryption Protocol (WEP) which allows remote attackers to quickly compile information that will let them decrypt messages.
CVE-2001-0232 1 Ibrow 1 News Desk 2008-09-05 5.0 MEDIUM N/A
newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters.
CVE-2001-0220 2 Ja-elvis, Ko-helvis 2 Ja-elvis, Ko-helvis 2008-09-05 7.2 HIGH N/A
Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.
CVE-2001-0019 1 Cisco 2 Arrowpoint, Content Services Switch 2008-09-05 2.1 LOW N/A
Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands.
CVE-2001-0161 1 Cisco 1 Aironet 2008-09-05 5.0 MEDIUM N/A
Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption, which makes it easier for remote attackers to mount brute force attacks.
CVE-2001-0064 1 Alt-n 1 Mdaemon 2008-09-05 5.0 MEDIUM N/A
Webconfig, IMAP, and other services in MDaemon 3.5.0 and earlier allows remote attackers to cause a denial of service via a long URL terminated by a "\r\n" string.
CVE-2001-0074 1 Technote Inc 1 Technote 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter.
CVE-2001-0163 1 Cisco 1 Aironet Ap340 2008-09-05 4.6 MEDIUM N/A
Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.
CVE-2001-0192 1 Davide Libenzi 1 Xmail 2008-09-05 10.0 HIGH N/A
Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.
CVE-2001-0075 1 Technote Inc 1 Technote 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter.
CVE-2001-0079 1 Hp 1 Support Tools Manager 2008-09-05 2.1 LOW N/A
Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.
CVE-2001-0082 1 Checkpoint 1 Firewall-1 2008-09-05 7.5 HIGH N/A
Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.
CVE-2001-0084 1 Gtk 1 Gtk\+ 2008-09-05 7.2 HIGH N/A
GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.
CVE-2001-0186 1 Free Java Web Server 1 Free Java Web Server 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2001-0093 1 Freebsd 1 Freebsd 2008-09-05 7.2 HIGH N/A
Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.
CVE-2001-0113 1 Omnicron 1 Omnihttpd 2008-09-05 10.0 HIGH N/A
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script.
CVE-2001-0114 1 Omnicron 1 Omnihttpd 2008-09-05 5.0 MEDIUM N/A
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.
CVE-2001-0073 1 Nsa 1 Security-enhanced Linux 2008-09-05 2.1 LOW N/A
Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory.
CVE-2001-0208 1 Microfocus 1 Cobol 2008-09-05 4.6 MEDIUM N/A
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.
CVE-2001-0210 1 Carey Internet Service 1 Commerce.cgi 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page parameter.
CVE-2001-0132 1 Trend Micro 1 Interscan Viruswall 2008-09-05 1.2 LOW N/A
Interscan VirusWall 3.6.x and earlier follows symbolic links when uninstalling the product, which allows local users to overwrite arbitrary files via a symlink attack.
CVE-2001-0133 1 Trend Micro 1 Interscan Viruswall 2008-09-05 10.0 HIGH N/A
The web administration interface for Interscan VirusWall 3.6.x and earlier does not use encryption, which could allow remote attackers to obtain the administrator password to sniff the administrator password via the setpasswd.cgi program or other HTTP GET requests that contain base64 encoded usernames and passwords.
CVE-2001-0229 1 Sun 1 Chilisoft 2008-09-05 7.2 HIGH N/A
Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts.
CVE-2001-0227 1 Biblioscape 1 Biblioweb Server 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in BiblioWeb web server 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.
CVE-2001-0211 1 Silverplatter 1 Webspirs 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.
CVE-2001-0225 1 Lenzo 1 Infobot 2008-09-05 10.0 HIGH N/A
fortran math component in Infobot 0.44.5.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.
CVE-2001-0206 1 Soft Lite 1 Serverworx 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into the requested pathname of an HTTP GET request.
CVE-2001-0202 1 Informs 1 Picserver 2008-09-05 5.0 MEDIUM N/A
Picserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request.
CVE-2001-0212 1 His 1 Auktion 2008-09-05 7.5 HIGH N/A
Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.
CVE-2001-0214 1 Way 1 Way-board 2008-09-05 5.0 MEDIUM N/A
Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.
CVE-2001-0200 1 Heat-on Software 1 Hsweb 2008-09-05 5.0 MEDIUM N/A
HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled.
CVE-2001-0155 1 Van Dyke Technologies 1 Vshell 2008-09-05 7.5 HIGH N/A
Format string vulnerability in VShell SSH gateway 1.0.1 and earlier allows remote attackers to execute arbitrary commands via a user name that contains format string specifiers.
CVE-2000-1242 1 Apc 1 Powerchute 2008-09-05 9.0 HIGH N/A
The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access.
CVE-2000-0856 1 Xs4all Data 1 Xs4all Data Sunftp 2008-09-05 7.5 HIGH N/A
Buffer overflow in SunFTP build 9(1) allows remote attackers to cause a denial of service or possibly execute arbitrary commands via a long GET request.
CVE-2000-1230 1 Phorum 1 Phorum 2008-09-05 5.0 MEDIUM N/A
Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".
CVE-2000-1201 1 Checkpoint 1 Firewall-1 2008-09-05 5.0 MEDIUM N/A
Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264.
CVE-2000-1118 1 24link 1 24link 2008-09-05 7.5 HIGH N/A
24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request.
CVE-2000-1228 1 Phorum 1 Phorum 2008-09-05 5.0 MEDIUM N/A
Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.
CVE-2000-1226 1 Snort 1 Snort 2008-09-05 5.0 MEDIUM N/A
Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan.
CVE-2000-1225 1 Imatix 1 Xitami 2008-09-05 5.0 MEDIUM N/A
Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program.
CVE-2000-1152 1 Be 1 Beos 2008-09-05 5.0 MEDIUM N/A
Browser IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.
CVE-2000-1223 1 I-soft 1 Quikstore 2008-09-05 7.5 HIGH N/A
quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request.
CVE-2000-1017 1 Webteacher 1 Webdata 2008-09-05 5.0 MEDIUM N/A
Webteachers Webdata allows remote attackers with valid Webdata accounts to read arbitrary files by posting a request to import the file into the WebData database.
CVE-2000-1229 1 Phorum 1 Phorum 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.
CVE-2000-1157 1 Network Associates 1 Sniffer Agent 2008-09-05 10.0 HIGH N/A
Buffer overflow in NAI Sniffer Agent allows remote attackers to execute arbitrary commands via a long SNMP community name.
CVE-2000-1037 1 Checkpoint 1 Firewall-1 2008-09-05 7.5 HIGH N/A
Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack.
CVE-2000-1098 1 Sonicwall 1 Soho Firewall 2008-09-05 5.0 MEDIUM N/A
The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or POST request.
CVE-2000-1158 1 Network Associates 1 Sniffer Agent 2008-09-05 7.5 HIGH N/A
NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords.
CVE-2000-1160 1 Network Associates 1 Sniffer Agent 2008-09-05 5.0 MEDIUM N/A
NAI Sniffer Agent allows remote attackers to cause a denial of service (crash) by sending a large number of login requests.
CVE-2000-1177 1 Bb4 1 Big Brother Network Monitor 2008-09-05 5.0 MEDIUM N/A
bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine the existence of files and user ID's by specifying the target file in the HISTFILE parameter.