VYPR

CVEs

335,219 total · page 6641 of 6,705

  • CVE-2001-0460Jun 27, 2001
    risk 0.03cvss epss 0.03

    Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header.

  • CVE-2001-0461Jun 27, 2001
    risk 0.03cvss epss 0.05

    template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell metacharacters in the argument to template.cgi.

  • CVE-2001-0462Jun 27, 2001
    risk 0.03cvss epss 0.06

    Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

  • CVE-2001-0463Jun 27, 2001
    risk 0.04cvss epss 0.10

    Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.

  • CVE-2001-0467Jun 27, 2001
    risk 0.03cvss epss 0.06

    Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a \... (modified dot dot) in an HTTP URL request.

  • CVE-2001-0468Jun 27, 2001
    risk 0.03cvss epss 0.00

    Buffer overflow in FTPFS allows local users to gain root privileges via a long user name.

  • CVE-2001-0469Jun 27, 2001
    risk 0.00cvss epss 0.01

    rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length.

  • CVE-2001-0470Jun 27, 2001
    risk 0.00cvss epss 0.00

    Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.

  • CVE-2001-0471Jun 27, 2001
    risk 0.03cvss epss 0.03

    SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.

  • CVE-2001-0472Jun 27, 2001
    risk 0.00cvss epss 0.01

    Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.

  • CVE-2001-0473Jun 27, 2001
    risk 0.00cvss epss 0.01

    Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.

  • CVE-2001-0474Jun 27, 2001
    risk 0.00cvss epss 0.00

    Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file.

  • CVE-2001-0475Jun 27, 2001
    risk 0.00cvss epss 0.01

    index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.

  • CVE-2001-0476Jun 27, 2001
    risk 0.03cvss epss 0.05

    Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter.

  • CVE-2001-0477Jun 27, 2001
    risk 0.00cvss epss 0.02

    Vulnerability in WebCalendar 0.9.26 allows remote command execution.

  • CVE-2001-0478Jun 27, 2001
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.

  • CVE-2001-0479Jun 27, 2001
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.

  • CVE-2001-0480Jun 27, 2001
    risk 0.00cvss epss 0.00

    Directory traversal vulnerability in Alex's FTP Server 0.7 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the (1) GET or (2) CD commands.

  • CVE-2001-0481Jun 27, 2001
    risk 0.00cvss epss 0.00

    Vulnerability in rpmdrake in Mandrake Linux 8.0 related to insecure temporary file handling.

  • CVE-2001-0484Jun 27, 2001
    risk 0.03cvss epss 0.03

    Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages.

  • CVE-2001-0485Jun 27, 2001
    risk 0.03cvss epss 0.00

    Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option.

  • CVE-2001-0487Jun 27, 2001
    risk 0.00cvss epss 0.01

    AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.

  • CVE-2001-0488Jun 27, 2001
    risk 0.00cvss epss 0.00

    pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.

  • CVE-2001-0489Jun 27, 2001
    risk 0.00cvss epss 0.01

    Format string vulnerability in gftp prior to 2.0.8 allows remote malicious FTP servers to execute arbitrary commands.

  • CVE-2001-0490Jun 27, 2001
    risk 0.03cvss epss 0.04

    Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file.

  • CVE-2001-0491Jun 27, 2001
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks, such as (1) .... in CWD, (2) .. in NLST, or (3) ... in NLST.

  • CVE-2001-0492Jun 27, 2001
    risk 0.00cvss epss 0.01

    Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3.

  • CVE-2001-0493Jun 27, 2001
    risk 0.00cvss epss 0.01

    Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.

  • CVE-2001-0494Jun 27, 2001
    risk 0.00cvss epss 0.01

    Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header.

  • CVE-2001-0495Jun 27, 2001
    risk 0.04cvss epss 0.06

    Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack.

  • CVE-2001-0496Jun 27, 2001
    risk 0.00cvss epss 0.00

    kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.

  • CVE-2001-1164Jun 27, 2001
    risk 0.00cvss epss 0.00

    Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.

  • CVE-2001-1083Jun 26, 2001
    risk 0.04cvss epss 0.13

    Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or \ (backward slash).

  • CVE-2001-1324Jun 26, 2001
    risk 0.00cvss epss 0.00

    cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.

  • CVE-2001-1162Jun 23, 2001
    risk 0.06cvss epss 0.32

    Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.

  • CVE-2001-0906Jun 22, 2001
    risk 0.03cvss epss 0.00

    teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produced when printing .dvi files using lpr.

  • CVE-2001-1328Jun 22, 2001
    risk 0.00cvss epss 0.05

    Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.

  • CVE-2001-1078Jun 21, 2001
    risk 0.04cvss epss 0.14

    Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that…

  • CVE-2001-1276Jun 21, 2001
    risk 0.00cvss epss 0.00

    ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file.

  • CVE-2001-1080Jun 19, 2001
    risk 0.03cvss epss 0.03

    diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.

  • CVE-2001-1459Jun 19, 2001
    risk 0.00cvss epss 0.00

    OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.

  • CVE-2001-0247Jun 18, 2001
    risk 0.06cvss epss 0.35

    Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.

  • CVE-2001-0248CriJun 18, 2001
    risk 0.64cvss 9.8epss 0.05

    Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.

  • CVE-2001-0249CriJun 18, 2001
    risk 0.64cvss 9.8epss 0.05

    Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.

  • CVE-2001-0263Jun 18, 2001
    risk 0.03cvss epss 0.04

    Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.

  • CVE-2001-0264Jun 18, 2001
    risk 0.04cvss epss 0.07

    Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff…

  • CVE-2001-0265Jun 18, 2001
    risk 0.03cvss epss 0.01

    ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file.

  • CVE-2001-0371Jun 18, 2001
    risk 0.00cvss epss 0.00

    Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted information.

  • CVE-2001-0372Jun 18, 2001
    risk 0.00cvss epss 0.02

    Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.

  • CVE-2001-0373Jun 18, 2001
    risk 0.00cvss epss 0.01

    The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.