Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-1242 1 Apc 1 Powerchute 2008-09-05 9.0 HIGH N/A
The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access.
CVE-2001-0210 1 Carey Internet Service 1 Commerce.cgi 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page parameter.
CVE-2001-0212 1 His 1 Auktion 2008-09-05 7.5 HIGH N/A
Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.
CVE-2001-0324 1 Microsoft 2 Windows 2000, Windows 98 2008-09-05 2.6 LOW N/A
Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.
CVE-2001-0325 1 Qnx 1 Rtp 2008-09-05 7.5 HIGH N/A
Buffer overflow in QNX RTP 5.60 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large number of arguments to the stat command.
CVE-2001-0229 1 Sun 1 Chilisoft 2008-09-05 7.2 HIGH N/A
Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts.
CVE-2001-0214 1 Way 1 Way-board 2008-09-05 5.0 MEDIUM N/A
Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.
CVE-2001-0294 1 Typsoft 1 Typsoft Ftp Server 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in TYPSoft FTP Server 0.85 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in a GET command, or (2) a ... in a CWD command.
CVE-2001-0293 1 Datawizard 1 Ftpxq 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.
CVE-2001-0292 1 Francisco Burzi 1 Php-nuke 2008-09-05 7.5 HIGH N/A
PHP-Nuke 4.4.1a allows remote attackers to modify a user's email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator.
CVE-2001-0160 2 Lucent, Orinoco 2 Wavelan, Orinoco Wavelan 2008-09-05 5.0 MEDIUM N/A
Lucent/ORiNOCO WaveLAN cards generate predictable Initialization Vector (IV) values for the Wireless Encryption Protocol (WEP) which allows remote attackers to quickly compile information that will let them decrypt messages.
CVE-2001-0155 1 Van Dyke Technologies 1 Vshell 2008-09-05 7.5 HIGH N/A
Format string vulnerability in VShell SSH gateway 1.0.1 and earlier allows remote attackers to execute arbitrary commands via a user name that contains format string specifiers.
CVE-2001-0093 1 Freebsd 1 Freebsd 2008-09-05 7.2 HIGH N/A
Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.
CVE-2001-0075 1 Technote Inc 1 Technote 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter.
CVE-2001-0079 1 Hp 1 Support Tools Manager 2008-09-05 2.1 LOW N/A
Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.
CVE-2001-0384 1 Siemens 1 Reliant Unix 2008-09-05 2.1 LOW N/A
ppd in Reliant Sinix allows local users to corrupt arbitrary files via a symlink attack in the /tmp/ppd.trace file.
CVE-2001-0354 1 Thenet 1 Checkbo 2008-09-05 5.0 MEDIUM N/A
TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on.
CVE-2001-0320 1 Francisco Burzi 1 Php-nuke 2008-09-05 10.0 HIGH N/A
bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.
CVE-2001-0312 1 Ibm 1 Websphere Plugin 2008-09-05 5.0 MEDIUM N/A
IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.
CVE-2001-0308 1 Bajie 1 Java Http Server 2008-09-05 7.5 HIGH N/A
UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.
CVE-2001-0289 1 Joseph Allen 1 Joe 2008-09-05 4.6 MEDIUM N/A
Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory.
CVE-2001-0288 1 Cisco 1 Ios 2008-09-05 7.5 HIGH N/A
Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.
CVE-2001-0287 1 Symantec Veritas 1 Cluster Server 2008-09-05 2.1 LOW N/A
VERITAS Cluster Server (VCS) 1.3.0 on Solaris allows local users to cause a denial of service (system panic) via the -L option to the lltstat command.
CVE-2001-0286 1 A1webserver 1 Http Server 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.
CVE-2001-0285 1 A1webserver 1 Http Server 2008-09-05 10.0 HIGH N/A
Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.
CVE-2001-0266 1 Hp 1 Hp-ux 2008-09-05 7.2 HIGH N/A
Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges.
CVE-2001-0264 1 Gene6 1 G6 Ftp Server 2008-09-05 5.0 MEDIUM N/A
Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.
CVE-2001-0262 1 Netscape 1 Smartdownload 2008-09-05 7.5 HIGH N/A
Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.
CVE-2001-0019 1 Cisco 2 Arrowpoint, Content Services Switch 2008-09-05 2.1 LOW N/A
Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands.
CVE-2001-0283 1 Sun 1 Sun Ftp 2008-09-05 6.4 MEDIUM N/A
Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.
CVE-2001-0186 1 Free Java Web Server 1 Free Java Web Server 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2001-0161 1 Cisco 1 Aironet 2008-09-05 5.0 MEDIUM N/A
Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption, which makes it easier for remote attackers to mount brute force attacks.
CVE-2001-0074 1 Technote Inc 1 Technote 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter.
CVE-2000-1102 1 Ptlink 2 Ptlink Irc Services, Ptlink Ircd 2008-09-05 5.0 MEDIUM N/A
PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode +owgscfxeb" and "oper" commands.
CVE-2000-1231 1 Phorum 1 Phorum 2008-09-05 5.0 MEDIUM N/A
code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string.
CVE-2000-1230 1 Phorum 1 Phorum 2008-09-05 5.0 MEDIUM N/A
Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".
CVE-2000-1229 1 Phorum 1 Phorum 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.
CVE-2000-1228 1 Phorum 1 Phorum 2008-09-05 5.0 MEDIUM N/A
Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.
CVE-2000-1172 1 Rob Flynn 1 Gaim 2008-09-05 10.0 HIGH N/A
Buffer overflow in Gaim 0.10.3 and earlier using the OSCAR protocol allows remote attackers to conduct a denial of service and possibly execute arbitrary commands via a long HTML tag.
CVE-2000-1110 1 Ibm 1 Net.data 2008-09-05 5.0 MEDIUM N/A
document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.
CVE-2000-1105 1 Microsoft 1 Indexing Service 2008-09-05 4.3 MEDIUM N/A
The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled.
CVE-2000-1103 1 Bsdi 1 Bsd Os 2008-09-05 7.2 HIGH N/A
rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.
CVE-2000-1101 1 Texas Imperial Software 1 Wftpd 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack.
CVE-2000-1185 1 Itserv Incorporated 1 Ridewaypn 2008-09-05 5.0 MEDIUM N/A
The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests.
CVE-2000-1046 1 Lotus 1 Domino 2008-09-05 10.0 HIGH N/A
Multiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via long (1) "RCPT TO," (2) "SAML FROM," or (3) "SOML FROM" commands.
CVE-2000-1017 1 Webteacher 1 Webdata 2008-09-05 5.0 MEDIUM N/A
Webteachers Webdata allows remote attackers with valid Webdata accounts to read arbitrary files by posting a request to import the file into the WebData database.
CVE-2000-0999 1 Openbsd 1 Openssh 2008-09-05 10.0 HIGH N/A
Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges.
CVE-2000-0918 1 Kde 1 Kvt 2008-09-05 7.2 HIGH N/A
Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.
CVE-2000-0916 1 Freebsd 1 Freebsd 2008-09-05 7.5 HIGH N/A
FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.
CVE-2000-0855 1 Xs4all Data 1 Xs4all Data Sunftp 2008-09-05 5.0 MEDIUM N/A
SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline.