Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0636 1 Raytheon 1 Silentrunner 2008-09-05 7.5 HIGH N/A
Buffer overflows in Raytheon SilentRunner allow remote attackers to (1) cause a denial of service in the collector (cle.exe) component of SilentRunner 2.0 via traffic containing long passwords, or (2) execute arbitrary commands via long HTTP queries in the Knowledge Browser component in SilentRunner 2.0 and 2.0.1. NOTE: It is highly likely that this candidate will be split into multiple candidates.
CVE-2001-0568 1 Zope 1 Zope 2008-09-05 2.1 LOW N/A
Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes.
CVE-2001-0689 1 Trend Micro 1 Virus Control System 2008-09-05 7.5 HIGH N/A
Vulnerability in TrendMicro Virus Control System 1.8 allows a remote attacker to view configuration files and change the configuration via a certain CGI program.
CVE-2001-0478 1 Phpmyadmin 1 Phpmyadmin 2008-09-05 7.5 HIGH N/A
Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.
CVE-2001-0432 1 Trend Micro 1 Interscan Viruswall 2008-09-05 10.0 HIGH N/A
Buffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote attackers to execute arbitrary commands.
CVE-2001-0425 1 Adcycle 1 Adcycle 2008-09-05 7.5 HIGH N/A
AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to verify login information.
CVE-2001-0490 1 Nullsoft 1 Winamp 2008-09-05 7.5 HIGH N/A
Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file.
CVE-2001-0477 1 Webcalendar 1 Webcalendar 2008-09-05 7.5 HIGH N/A
Vulnerability in WebCalendar 0.9.26 allows remote command execution.
CVE-2001-0572 2 Openbsd, Ssh 2 Openssh, Ssh 2008-09-05 7.5 HIGH N/A
The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker to obtain the following information via sniffing: (1) password lengths or ranges of lengths, which simplifies brute force password guessing, (2) whether RSA or DSA authentication is being used, (3) the number of authorized_keys in RSA authentication, or (4) the lengths of shell commands.
CVE-2001-0471 1 Ssh 1 Ssh 2008-09-05 7.5 HIGH N/A
SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.
CVE-2001-0691 1 University Of Washington 1 Imapd 2008-09-05 4.6 MEDIUM N/A
Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.
CVE-2001-0400 1 Matt Tourtillott 1 Nph-maillist 2008-09-05 7.5 HIGH N/A
nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.
CVE-2001-0800 1 Sgi 1 Irix 2008-09-05 10.0 HIGH N/A
lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.
CVE-2001-0647 1 Orange Software 1 Orange Web Server 2008-09-05 5.0 MEDIUM N/A
Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version.
CVE-2001-0671 1 Ibm 1 Aix 2008-09-05 10.0 HIGH N/A
Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges.
CVE-2001-0743 1 Oreilly 1 Webboard 2008-09-05 5.0 MEDIUM N/A
Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followed by JavaScript commands.
CVE-2001-0633 1 Sun 1 Chilisoft 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a '..' (dot dot) attack in the sample script 'codebrws.asp'.
CVE-2001-0420 1 Way To The Web 1 Talkback 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.
CVE-2001-0418 1 Ncm 1 Ncm Content Management System 2008-09-05 5.0 MEDIUM N/A
content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.
CVE-2001-0483 1 Symantec 1 Raptor Firewall 2008-09-05 7.5 HIGH N/A
Configuration error in Axent Raptor Firewall 6.5 allows remote attackers to use the firewall as a proxy to access internal web resources when the http.noproxy Rule is not set.
CVE-2001-0406 1 Samba 1 Samba 2008-09-05 2.1 LOW N/A
Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.
CVE-2001-0632 1 Sun 1 Chilisoft 2008-09-05 7.5 HIGH N/A
Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.
CVE-2001-0742 1 Computalynx 1 Cmail 2008-09-05 7.5 HIGH N/A
Buffer overflow in Computalynx CMail POP3 mail server 2.4.9 allows remote attackers to run arbitrary code via a long HELO command.
CVE-2001-0453 1 Brs 1 Webweaver 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) scripts directories.
CVE-2001-0694 1 Texas Imperial Software 1 Wftpd 2008-09-05 7.5 HIGH N/A
Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.
CVE-2001-0452 1 Brs 1 Webweaver 2008-09-05 5.0 MEDIUM N/A
BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.
CVE-2001-0569 1 Zope 1 Zope 2008-09-05 2.1 LOW N/A
Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) ObjectManager, (2) PropertyManager, and (3) PropertySheet.
CVE-2001-0713 1 Sendmail 1 Sendmail 2008-09-05 4.6 MEDIUM N/A
Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the high bit set, such as (1) macro names that are one character long, (2) a variable setting which is processed by the setoption function, or (3) a Modifiers setting which is processed by the getmodifiers function.
CVE-2001-0688 1 Transsoft 1 Broker Ftp Server 2008-09-05 5.0 MEDIUM N/A
Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command.
CVE-2001-0448 1 Software602 1 602pro Lan Suite 2008-09-05 5.0 MEDIUM N/A
Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.
CVE-2001-0398 1 Ritlabs 1 The Bat 2008-09-05 7.5 HIGH N/A
The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT! to misrepresent the attachment's type with a different icon.
CVE-2001-0397 1 Silent Runner 1 Silent Runner Collector Src 2008-09-05 7.5 HIGH N/A
Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.
CVE-2001-0395 1 Lightwave 1 Consoleserver 2008-09-05 7.5 HIGH N/A
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.
CVE-2001-0791 1 Trend Micro 1 Interscan Viruswall 2008-09-05 5.0 MEDIUM N/A
Trend Micro InterScan VirusWall for Windows NT allows remote attackers to make configuration changes by directly calling certain CGI programs, which do not restrict access.
CVE-2001-0396 1 Lightwave 1 Consoleserver 2008-09-05 5.0 MEDIUM N/A
The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.
CVE-2001-0790 1 Specter 1 Specter Ids 2008-09-05 5.0 MEDIUM N/A
Specter IDS version 4.5 and 5.0 allows a remote attacker to cause a denial of service (CPU exhaustion) via a port scan, which causes the server to consume CPU while preparing alerts.
CVE-2000-1242 1 Apc 1 Powerchute 2008-09-05 9.0 HIGH N/A
The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access.
CVE-2001-0214 1 Way 1 Way-board 2008-09-05 5.0 MEDIUM N/A
Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.
CVE-2001-0073 1 Nsa 1 Security-enhanced Linux 2008-09-05 2.1 LOW N/A
Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory.
CVE-2001-0390 1 Ibm 3 Net.commerce, Net.commerce Hosting Server, Websphere Application Server 2008-09-05 5.0 MEDIUM N/A
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
CVE-2001-0389 1 Ibm 2 Net.commerce, Websphere Application Server 2008-09-05 5.0 MEDIUM N/A
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.
CVE-2001-0384 1 Siemens 1 Reliant Unix 2008-09-05 2.1 LOW N/A
ppd in Reliant Sinix allows local users to corrupt arbitrary files via a symlink attack in the /tmp/ppd.trace file.
CVE-2001-0354 1 Thenet 1 Checkbo 2008-09-05 5.0 MEDIUM N/A
TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on.
CVE-2001-0327 1 Iplanet 1 Iplanet Web Server 2008-09-05 5.0 MEDIUM N/A
iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server.
CVE-2001-0325 1 Qnx 1 Rtp 2008-09-05 7.5 HIGH N/A
Buffer overflow in QNX RTP 5.60 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large number of arguments to the stat command.
CVE-2001-0324 1 Microsoft 2 Windows 2000, Windows 98 2008-09-05 2.6 LOW N/A
Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.
CVE-2001-0320 1 Francisco Burzi 1 Php-nuke 2008-09-05 10.0 HIGH N/A
bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.
CVE-2001-0312 1 Ibm 1 Websphere Plugin 2008-09-05 5.0 MEDIUM N/A
IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.
CVE-2001-0305 1 Thinking Arts 1 Es.one 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in the StartID parameter.
CVE-2001-0303 1 Pi3 1 Pi3web 2008-09-05 5.0 MEDIUM N/A
tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file.