Search
Total
86024 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2001-0465 | 1 Intuit | 1 Turbo Tax | 2017-10-10 | 4.6 MEDIUM | N/A |
| TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive information. | |||||
| CVE-2001-0467 | 1 Robtex | 1 Viking Server | 2017-10-10 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a \... (modified dot dot) in an HTTP URL request. | |||||
| CVE-2001-0469 | 1 Freebsd | 1 Freebsd | 2017-10-10 | 5.0 MEDIUM | N/A |
| rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length. | |||||
| CVE-2001-0473 | 5 Conectiva, Immunix, Mandrakesoft and 2 more | 5 Linux, Immunix, Mandrake Linux and 2 more | 2017-10-10 | 7.5 HIGH | N/A |
| Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands. | |||||
| CVE-2001-0474 | 2 Brian Paul, Mandrakesoft | 2 Mesa, Mandrake Linux | 2017-10-10 | 2.1 LOW | N/A |
| Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file. | |||||
| CVE-2001-0475 | 1 Jelsoft | 1 Vbulletin | 2017-10-10 | 7.5 HIGH | N/A |
| index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter. | |||||
| CVE-2001-0481 | 1 Mandrakesoft | 1 Mandrake Linux | 2017-10-10 | 7.2 HIGH | N/A |
| Vulnerability in rpmdrake in Mandrake Linux 8.0 related to insecure temporary file handling. | |||||
| CVE-2001-0482 | 1 Argus Systems | 1 Pitbull Lx | 2017-10-10 | 7.2 HIGH | N/A |
| Configuration error in Argus PitBull LX allows root users to bypass specified access control restrictions and cause a denial of service or execute arbitrary commands by modifying kernel variables such as MaxFiles, MaxInodes, and ModProbePath in /proc/sys via calls to sysctl. | |||||
| CVE-2001-0485 | 1 Sgi | 1 Irix | 2017-10-10 | 7.2 HIGH | N/A |
| Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option. | |||||
| CVE-2001-0486 | 1 Novell | 1 Bordermanager | 2017-10-10 | 5.0 MEDIUM | N/A |
| Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353. | |||||
| CVE-2001-0488 | 1 Hp | 1 Hp-ux | 2017-10-10 | 2.1 LOW | N/A |
| pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service. | |||||
| CVE-2001-0493 | 1 Max Feoktistov | 1 Small Http Server | 2017-10-10 | 5.0 MEDIUM | N/A |
| Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux. | |||||
| CVE-2001-0494 | 1 Ipswitch | 1 Imail | 2017-10-10 | 7.5 HIGH | N/A |
| Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header. | |||||
| CVE-2001-0495 | 1 Datawizard | 1 Webxq | 2017-10-10 | 5.0 MEDIUM | N/A |
| Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack. | |||||
| CVE-2001-0513 | 1 Oracle | 1 Oracle9i | 2017-10-10 | 5.0 MEDIUM | N/A |
| Oracle listener process on Windows NT redirects connection requests to another port and creates a separate thread to process the request, which allows remote attackers to cause a denial of service by repeatedly connecting to the Oracle listener but not connecting to the redirected port. | |||||
| CVE-2001-0514 | 3 Atmel, Linksys, Netgear | 3 802.11b Vnet-b Access Point, Wap11, Me102 | 2017-10-10 | 7.5 HIGH | N/A |
| SNMP service in Atmel 802.11b VNET-B Access Point 1.3 and earlier, as used in Netgear ME102 and Linksys WAP11, accepts arbitrary community strings with requested MIB modifications, which allows remote attackers to obtain sensitive information such as WEP keys, cause a denial of service, or gain access to the network. | |||||
| CVE-2001-0517 | 1 Oracle | 1 Oracle8i | 2017-10-10 | 5.0 MEDIUM | N/A |
| Oracle listener in Oracle 8i on Solaris allows remote attackers to cause a denial of service via a malformed connection packet with a maximum transport data size that is set to 0. | |||||
| CVE-2001-0518 | 1 Oracle | 1 Oracle9i | 2017-10-10 | 5.0 MEDIUM | N/A |
| Oracle listener before Oracle 9i allows attackers to cause a denial of service by repeatedly sending the first portion of a fragmented Oracle command without sending the remainder of the command, which causes the listener to hang. | |||||
| CVE-2001-0525 | 1 Suse | 1 Suse Linux | 2017-10-10 | 7.2 HIGH | N/A |
| Buffer overflow in dsh in dqs 3.2.7 in SuSE Linux 7.0 and earlier, and possibly other operating systems, allows local users to gain privileges via a long first command line argument. | |||||
| CVE-2001-0527 | 1 Dcscripts | 2 Dcforum, Dcforum 2000 | 2017-10-10 | 10.0 HIGH | N/A |
| DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database. | |||||
| CVE-2001-0528 | 1 Oracle | 1 E-business Suite | 2017-10-10 | 7.2 HIGH | N/A |
| Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain privileges. | |||||
| CVE-2001-0529 | 1 Openbsd | 1 Openssh | 2017-10-10 | 7.2 HIGH | N/A |
| OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack. | |||||
| CVE-2001-0530 | 1 Spearhead | 2 Netgap 200, Netgap 300 | 2017-10-10 | 5.0 MEDIUM | N/A |
| Spearhead NetGAP 200 and 300 before build 78 allow a remote attacker to bypass file blocking and content inspection via specially encoded URLs which include '%' characters. | |||||
| CVE-2001-0533 | 1 Ibm | 1 Aix | 2017-10-10 | 7.2 HIGH | N/A |
| Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable. | |||||
| CVE-2001-0537 | 1 Cisco | 1 Ios | 2017-10-10 | 9.3 HIGH | N/A |
| HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL. | |||||
| CVE-2001-0549 | 1 Symantec | 1 Liveupdate | 2017-10-10 | 4.6 MEDIUM | N/A |
| Symantec LiveUpdate 1.5 stores proxy passwords in cleartext in a registry key, which could allow local users to obtain the passwords. | |||||
| CVE-2001-0553 | 1 Ssh | 1 Secure Shell | 2017-10-10 | 7.2 HIGH | N/A |
| SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field. | |||||
| CVE-2001-0558 | 1 T. Hauck | 1 Jana Web Server | 2017-10-10 | 5.0 MEDIUM | N/A |
| T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0). | |||||
| CVE-2001-0559 | 1 Paul Vixie | 1 Vixie Cron | 2017-10-10 | 7.2 HIGH | N/A |
| crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error. | |||||
| CVE-2001-0560 | 1 Paul Vixie | 1 Vixie Cron | 2017-10-10 | 4.6 MEDIUM | N/A |
| Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters). | |||||
| CVE-2001-0563 | 1 Electrosoft | 1 Electrocomm | 2017-10-10 | 5.0 MEDIUM | N/A |
| ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via large (> 160000 character) strings sent to port 23. | |||||
| CVE-2001-0564 | 1 Apc | 1 Ap9606 | 2017-10-10 | 5.0 MEDIUM | N/A |
| APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of service via repeated failed logon attempts which temporarily locks the card. | |||||
| CVE-2001-0567 | 1 Zope | 1 Zope | 2017-10-10 | 4.6 MEDIUM | N/A |
| Digital Creations Zope 2.3.2 and earlier allows a local attacker to gain additional privileges via the changing of ZClass permission mappings for objects and methods in the ZClass. | |||||
| CVE-2001-0573 | 1 Ibm | 1 Aix | 2017-10-10 | 4.6 MEDIUM | N/A |
| lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory. | |||||
| CVE-2001-0574 | 1 Jason Rahaim | 1 Mp3mystic | 2017-10-10 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot) in the URL. | |||||
| CVE-2001-0585 | 1 Gordano | 1 Ntmail | 2017-10-10 | 5.0 MEDIUM | N/A |
| Gordano NTMail 6.0.3c allows a remote attacker to create a denial of service via a long (>= 255 characters) URL request to port 8000 or port 9000. | |||||
| CVE-2001-0586 | 1 Trend Micro | 1 Scanmail Exchange | 2017-10-10 | 4.6 MEDIUM | N/A |
| TrendMicro ScanMail for Exchange 3.5 Evaluation allows a local attacker to recover the administrative credentials for ScanMail via a combination of unprotected registry keys and weakly encrypted passwords. | |||||
| CVE-2001-0589 | 1 Juniper | 1 Netscreen Screenos | 2017-10-10 | 2.1 LOW | N/A |
| NetScreen ScreenOS prior to 2.5r6 on the NetScreen-10 and Netscreen-100 can allow a local attacker to bypass the DMZ 'denial' policy via specific traffic patterns. | |||||
| CVE-2001-0590 | 1 Apache | 1 Tomcat | 2017-10-10 | 5.0 MEDIUM | N/A |
| Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0). | |||||
| CVE-2001-0611 | 1 Rimarts Inc. | 1 Becky Internet Mail | 2017-10-10 | 7.5 HIGH | N/A |
| Becky! 2.00.05 and earlier can allow a remote attacker to gain additional privileges via a buffer overflow attack on long messages without newline characters. | |||||
| CVE-2001-0612 | 1 Mcafee | 1 Remote Desktop 32 | 2017-10-10 | 5.0 MEDIUM | N/A |
| McAfee Remote Desktop 3.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of packets to port 5045. | |||||
| CVE-2001-0613 | 1 Omnicron | 1 Omnihttpd | 2017-10-10 | 5.0 MEDIUM | N/A |
| Omnicron Technologies OmniHTTPD Professional 2.08 and earlier allows a remote attacker to create a denial of service via a long POST URL request. | |||||
| CVE-2001-0615 | 1 Faust Informatics | 1 Freestyle Chat | 2017-10-10 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'. | |||||
| CVE-2001-0616 | 1 Faust Informatics | 1 Freestyle Chat | 2017-10-10 | 5.0 MEDIUM | N/A |
| Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (e.g., GET /aux HTTP/1.0). | |||||
| CVE-2001-0621 | 1 Cisco | 1 Content Services Switch 11000 | 2017-10-10 | 7.5 HIGH | N/A |
| The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands. | |||||
| CVE-2001-0622 | 1 Cisco | 1 Content Services Switch 11000 | 2017-10-10 | 7.5 HIGH | N/A |
| The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the interface. | |||||
| CVE-2001-0626 | 1 Oreilly | 1 Website Professional | 2017-10-10 | 7.5 HIGH | N/A |
| O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character. | |||||
| CVE-2001-0627 | 1 Sco | 1 Openserver | 2017-10-10 | 3.7 LOW | N/A |
| vi as included with SCO OpenServer 5.0 - 5.0.6 allows a local attacker to overwrite arbitrary files via a symlink attack. | |||||
| CVE-2001-0628 | 1 Microsoft | 1 Word | 2017-10-10 | 7.2 HIGH | N/A |
| Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user. | |||||
| CVE-2001-0629 | 1 Hp | 1 Openview Network Node Manager | 2017-10-10 | 10.0 HIGH | N/A |
| HP Event Correlation Service (ecsd) as included with OpenView Network Node Manager 6.1 allows a remote attacker to gain addition privileges via a buffer overflow attack in the '-restore_config' command line parameter. | |||||
