VYPR

CVEs

335,219 total · page 6639 of 6,705

  • CVE-2001-0386Jul 2, 2001
    risk 0.04cvss epss 0.06

    AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.

  • CVE-2001-0387Jul 2, 2001
    risk 0.00cvss epss 0.00

    Format string vulnerability in hfaxd in HylaFAX before 4.1.b2_2 allows local users to gain privileges via the -q command line argument.

  • CVE-2001-0389Jul 2, 2001
    risk 0.00cvss epss 0.01

    IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.

  • CVE-2001-0390Jul 2, 2001
    risk 0.04cvss epss 0.07

    IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.

  • CVE-2001-0391Jul 2, 2001
    risk 0.00cvss epss 0.01

    Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory.

  • CVE-2001-0395CriJul 2, 2001
    risk 0.64cvss 9.8epss 0.01

    Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.

  • CVE-2001-0396Jul 2, 2001
    risk 0.00cvss epss 0.01

    The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.

  • CVE-2001-0400Jul 2, 2001
    risk 0.04cvss epss 0.13

    nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.

  • CVE-2001-0405Jul 2, 2001
    risk 0.04cvss epss 0.14

    ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.

  • CVE-2001-0406Jul 2, 2001
    risk 0.03cvss epss 0.00

    Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.

  • CVE-2001-0418Jul 2, 2001
    risk 0.03cvss epss 0.04

    content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.

  • CVE-2001-0419Jul 2, 2001
    risk 0.04cvss epss 0.18

    Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.

  • CVE-2001-0421Jul 2, 2001
    risk 0.03cvss epss 0.02

    FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive…

  • CVE-2001-0422Jul 2, 2001
    risk 0.03cvss epss 0.00

    Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.

  • CVE-2001-0423Jul 2, 2001
    risk 0.03cvss epss 0.01

    Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.

  • CVE-2001-0424Jul 2, 2001
    risk 0.00cvss epss 0.00

    BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.

  • CVE-2001-0426Jul 2, 2001
    risk 0.03cvss epss 0.00

    Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.

  • CVE-2001-0428Jul 2, 2001
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option.

  • CVE-2001-0429Jul 2, 2001
    risk 0.00cvss epss 0.01

    Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service.

  • CVE-2001-0430Jul 2, 2001
    risk 0.00cvss epss 0.00

    Vulnerability in exuberant-ctags before 3.2.4-0.1 insecurely creates temporary files.

  • CVE-2001-0431Jul 2, 2001
    risk 0.00cvss epss 0.00

    Vulnerability in iPlanet Web Server Enterprise Edition 4.x.

  • CVE-2001-0432Jul 2, 2001
    risk 0.03cvss epss 0.06

    Buffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote attackers to execute arbitrary commands.

  • CVE-2001-0434Jul 2, 2001
    risk 0.00cvss epss 0.01

    The LogDataListToFile ActiveX function used in (1) Knowledge Center and (2) Back web components of Compaq Presario computers allows remote attackers to modify arbitrary files and cause a denial of service.

  • CVE-2001-0435Jul 2, 2001
    risk 0.00cvss epss 0.00

    The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on" option and capturing the passphrases of other share holders as they authenticate.

  • CVE-2001-0436Jul 2, 2001
    risk 0.00cvss epss 0.02

    dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.

  • CVE-2001-0437Jul 2, 2001
    risk 0.00cvss epss 0.01

    upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.

  • CVE-2001-0438Jul 2, 2001
    risk 0.00cvss epss 0.00

    Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu.

  • CVE-2001-0439Jul 2, 2001
    risk 0.00cvss epss 0.01

    licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

  • CVE-2001-0440Jul 2, 2001
    risk 0.04cvss epss 0.15

    Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.

  • CVE-2001-0443Jul 2, 2001
    risk 0.00cvss epss 0.01

    Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password.

  • CVE-2001-0444Jul 2, 2001
    risk 0.00cvss epss 0.00

    Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information.

  • CVE-2001-0464Jul 2, 2001
    risk 0.04cvss epss 0.07

    Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter.

  • CVE-2001-0486Jul 2, 2001
    risk 0.04cvss epss 0.16

    Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353.

  • CVE-2001-1042HigJul 2, 2001
    risk 0.49cvss 7.5epss 0.02

    Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.

  • CVE-2001-1084Jul 2, 2001
    risk 0.00cvss epss 0.00

    Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.

  • CVE-2001-1159Jul 2, 2001
    risk 0.00cvss epss 0.02

    load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary code by using…

  • CVE-2001-1161Jul 2, 2001
    risk 0.00cvss epss 0.04

    Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.

  • CVE-2001-1441Jul 2, 2001
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in VisualAge for Java 3.5 Professional allows remote attackers to execute JavaScript on other clients via the URL, which injects the script in the resulting error message.

  • CVE-2001-1043HigJul 1, 2001
    risk 0.49cvss 7.5epss 0.02

    ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.

  • CVE-2001-1386HigJul 1, 2001
    risk 0.49cvss 7.5epss 0.01

    WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension.

  • CVE-2001-1246Jun 30, 2001
    risk 0.03cvss epss 0.05

    PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

  • CVE-2001-1239Jun 29, 2001
    risk 0.00cvss epss 0.01

    PowerNet IX allows remote attackers to cause a denial of service via a port scan.

  • CVE-2001-1248Jun 29, 2001
    risk 0.00cvss epss 0.01

    vWebServer 1.2.0 allows remote attackers to view arbitrary ASP scripts via a request for an ASP script that ends with a URL-encoded space character (%20).

  • CVE-2001-1249Jun 29, 2001
    risk 0.00cvss epss 0.01

    vWebServer 1.2.0 allows remote attackers to cause a denial of service via a URL that contains MS-DOS device names.

  • CVE-2001-1250Jun 29, 2001
    risk 0.00cvss epss 0.01

    vWebServer 1.2.0 allows remote attackers to cause a denial of service (hang) via a small number of long URL requests, possibly due to a buffer overflow.

  • CVE-2001-1251Jun 29, 2001
    risk 0.00cvss epss 0.01

    SmallHTTP 1.204 through 3.00 beta 8 allows remote attackers to cause a denial of service via multiple long URL requests.

  • CVE-2001-1290Jun 28, 2001
    risk 0.03cvss epss 0.03

    admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration, gain privileges, and execute arbitrary Perl code via the table_width parameter.

  • CVE-2001-0237Jun 27, 2001
    risk 0.02cvss epss 0.29

    Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.

  • CVE-2001-0240Jun 27, 2001
    risk 0.00cvss epss 0.01

    Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.

  • CVE-2001-0241Jun 27, 2001
    risk 0.10cvss epss 0.86

    Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.