VYPR

CVEs

335,219 total · page 6642 of 6,705

  • CVE-2001-0374Jun 18, 2001
    risk 0.00cvss epss 0.00

    The HTTP server in Compaq web-enabled management software for (1) Foundation Agents, (2) Survey, (3) Power Manager, (4) Availability Agents, (5) Intelligent Cluster Administrator, and (6) Insight Manager can be used as a generic proxy server, which allows remote attackers to…

  • CVE-2001-0375Jun 18, 2001
    risk 0.04cvss epss 0.16

    Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests.

  • CVE-2001-0376Jun 18, 2001
    risk 0.00cvss epss 0.00

    SonicWALL Tele2 and SOHO firewalls with 6.0.0.0 firmware using IPSEC with IKE pre-shared keys do not allow for the use of full 128 byte IKE pre-shared keys, which is the intended design of the IKE pre-shared key, and only support 48 byte keys. This allows a remote attacker to…

  • CVE-2001-0377Jun 18, 2001
    risk 0.00cvss epss 0.01

    Infradig Inframail prior to 3.98a allows a remote attacker to create a denial of service via a malformed POST request which includes a space followed by a large string.

  • CVE-2001-0379Jun 18, 2001
    risk 0.00cvss epss 0.01

    Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.

  • CVE-2001-0380Jun 18, 2001
    risk 0.03cvss epss 0.03

    Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented community string 'ILMI'.

  • CVE-2001-0382Jun 18, 2001
    risk 0.00cvss epss 0.00

    Computer Associates CCC\Harvest 5.0 for Windows NT/2000 uses weak encryption for passwords, which allows a remote attacker to gain privileges on the application.

  • CVE-2001-0383Jun 18, 2001
    risk 0.03cvss epss 0.00

    banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication.

  • CVE-2001-0392Jun 18, 2001
    risk 0.00cvss epss 0.01

    Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.

  • CVE-2001-0393Jun 18, 2001
    risk 0.00cvss epss 0.01

    Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.

  • CVE-2001-0397Jun 18, 2001
    risk 0.00cvss epss 0.01

    Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.

  • CVE-2001-0398Jun 18, 2001
    risk 0.00cvss epss 0.01

    The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT! to misrepresent the attachment's type with a different icon.

  • CVE-2001-0399Jun 18, 2001
    risk 0.03cvss epss 0.05

    Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.

  • CVE-2001-0401Jun 18, 2001
    risk 0.03cvss epss 0.00

    Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.

  • CVE-2001-0402Jun 18, 2001
    risk 0.03cvss epss 0.03

    IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted port.

  • CVE-2001-0403Jun 18, 2001
    risk 0.03cvss epss 0.00

    /opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.

  • CVE-2001-0404Jun 18, 2001
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.

  • CVE-2001-0408Jun 18, 2001
    risk 0.00cvss epss 0.01

    vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when another user opens a file containing malicious VIM control codes.

  • CVE-2001-0409Jun 18, 2001
    risk 0.03cvss epss 0.00

    vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory.

  • CVE-2001-0410Jun 18, 2001
    risk 0.00cvss epss 0.01

    Buffer overflow in Trend Micro Virus Buster 2001 8.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long "From" header.

  • CVE-2001-0411Jun 18, 2001
    risk 0.00cvss epss 0.01

    Reliant Unix 5.44 and earlier allows remote attackers to cause a denial of service via an ICMP port unreachable packet, which causes Reliant to drop all connections to the source address of the packet.

  • CVE-2001-0412Jun 18, 2001
    risk 0.00cvss epss 0.00

    Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode.

  • CVE-2001-0413Jun 18, 2001
    risk 0.00cvss epss 0.01

    BinTec X4000 Access router, and possibly other versions, allows remote attackers to cause a denial of service via a SYN port scan, which causes the router to hang.

  • CVE-2001-0414Jun 18, 2001
    risk 0.09cvss epss 0.81

    Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.

  • CVE-2001-0420Jun 18, 2001
    risk 0.00cvss epss 0.00

    Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.

  • CVE-2001-0427Jun 18, 2001
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.

  • CVE-2001-0433Jun 18, 2001
    risk 0.00cvss epss 0.01

    Buffer overflow in Savant 3.0 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Host HTTP header.

  • CVE-2001-0446Jun 18, 2001
    risk 0.00cvss epss 0.01

    IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.

  • CVE-2001-0447Jun 18, 2001
    risk 0.00cvss epss 0.01

    Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters.

  • CVE-2001-0448Jun 18, 2001
    risk 0.00cvss epss 0.01

    Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.

  • CVE-2001-0465Jun 18, 2001
    risk 0.00cvss epss 0.00

    TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive information.

  • CVE-2001-0466Jun 18, 2001
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

  • CVE-2001-0482Jun 18, 2001
    risk 0.00cvss epss 0.00

    Configuration error in Argus PitBull LX allows root users to bypass specified access control restrictions and cause a denial of service or execute arbitrary commands by modifying kernel variables such as MaxFiles, MaxInodes, and ModProbePath in /proc/sys via calls to sysctl.

  • CVE-2001-0483Jun 18, 2001
    risk 0.00cvss epss 0.01

    Configuration error in Axent Raptor Firewall 6.5 allows remote attackers to use the firewall as a proxy to access internal web resources when the http.noproxy Rule is not set.

  • CVE-2001-1160Jun 18, 2001
    risk 0.04cvss epss 0.07

    udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the category_file field.

  • CVE-2001-1163Jun 16, 2001
    risk 0.03cvss epss 0.04

    Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.

  • CVE-2001-1077Jun 15, 2001
    risk 0.03cvss epss 0.00

    Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name argument.

  • CVE-2001-1148Jun 13, 2001
    risk 0.00cvss epss 0.00

    Multiple buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allow local users to gain privileges via a long TERM environment variable to (1) atcronsh, (2) auditsh, (3) authsh, (4) backupsh, (5) lpsh, (6) sysadm.menu, or (7) termsh.

  • CVE-2001-1343Jun 12, 2001
    risk 0.03cvss epss 0.06

    ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.

  • CVE-2001-1344Jun 12, 2001
    risk 0.03cvss epss 0.02

    WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).

  • CVE-2001-1256Jun 11, 2001
    risk 0.00cvss epss 0.01

    kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.

  • CVE-2001-1277Jun 11, 2001
    risk 0.00cvss epss 0.00

    makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.

  • CVE-2001-1329Jun 11, 2001
    risk 0.00cvss epss 0.00

    Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.

  • CVE-2001-1330Jun 11, 2001
    risk 0.00cvss epss 0.00

    Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.

  • CVE-2001-1368Jun 11, 2001
    risk 0.00cvss epss 0.00

    Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data.

  • CVE-2001-1430Jun 11, 2001
    risk 0.00cvss epss 0.02

    Cayman 3220-H DSL Router 1.0 ship without a password set, which allows remote attackers to gain unauthorized access.

  • CVE-2001-1359Jun 8, 2001
    risk 0.00cvss epss 0.01

    Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server.

  • CVE-2001-1263Jun 6, 2001
    risk 0.03cvss epss 0.05

    telnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large number of characters to port 23, possibly due to a buffer overflow.

  • CVE-2001-1088Jun 5, 2001
    risk 0.07cvss epss 0.48

    Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote…

  • CVE-2001-1345Jun 5, 2001
    risk 0.00cvss epss 0.00

    bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program.