VYPR

CVEs

335,217 total · page 6644 of 6,705

  • CVE-2001-1326May 29, 2001
    risk 0.03cvss epss 0.04

    Eudora 5.1 allows remote attackers to execute arbitrary code when the "Use Microsoft Viewer" option is enabled and the "allow executables in HTML content" option is disabled, via an HTML email with a form that is activated from an image that the attacker spoofs as a link, which causes the user to execute the form and access embedded attachments.

  • CVE-2001-1028May 28, 2001
    risk 0.00cvss epss 0.00

    Buffer overflow in ultimate_source function of man 1.5 and earlier allows local users to gain privileges.

  • CVE-2001-1074May 28, 2001
    risk 0.00cvss epss 0.00

    Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges.

  • CVE-2001-1336May 28, 2001
    risk 0.00cvss epss 0.01

    CesarFTP 0.98b and earlier stores usernames and passwords in plaintext in the settings.ini file, which allows attackers to gain privileges.

  • CVE-2001-1348May 28, 2001
    risk 0.00cvss epss 0.01

    TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter.

  • CVE-2001-1349May 28, 2001
    risk 0.00cvss epss 0.00

    Sendmail before 8.11.4, and 8.12.0 before 8.12.0.Beta10, allows local users to cause a denial of service and possibly corrupt the heap and gain privileges via race conditions in signal handlers.

  • CVE-2001-1335May 27, 2001
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contains a ...%5c (modified dot dot).

  • CVE-2001-0749May 24, 2001
    risk 0.00cvss epss 0.01

    Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to read arbitrary files via a webserver root directory set to system root.

  • CVE-2001-1327May 24, 2001
    risk 0.00cvss epss 0.00

    pmake before 2.1.35 in Turbolinux 6.05 and earlier is installed with setuid root privileges, which could allow local users to gain privileges by exploiting vulnerabilities in pmake or programs that are used by pmake.

  • CVE-2001-1338May 24, 2001
    risk 0.00cvss epss 0.04

    Beck IPC GmbH IPC@CHIP TelnetD server generates different responses when given valid and invalid login names, which allows remote attackers to determine accounts on the system.

  • CVE-2001-1339CriMay 24, 2001
    risk 0.69cvss 9.8epss 0.24

    Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.

  • CVE-2001-1341May 24, 2001
    risk 0.00cvss epss 0.02

    The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program.

  • CVE-2001-1347May 24, 2001
    risk 0.03cvss epss 0.01

    Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due to an exception, and allow hijacking of resources such as named pipes.

  • CVE-2001-1428May 24, 2001
    risk 0.00cvss epss 0.04

    The (1) FTP and (2) Telnet services in Beck GmbH IPC@Chip are shipped with a default password, which allows remote attackers to gain unauthorized access.

  • CVE-2001-0551May 22, 2001
    risk 0.00cvss epss 0.00

    Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window.

  • CVE-2001-1337May 21, 2001
    risk 0.00cvss epss 0.01

    Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to cause a denial of service via a long HTTP request.

  • CVE-2001-1346May 18, 2001
    risk 0.03cvss epss 0.01

    Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.

  • CVE-2001-1323May 16, 2001
    risk 0.00cvss epss 0.02

    Buffer overflow in MIT Kerberos 5 (krb5) 1.2.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via base-64 encoded data, which is not properly handled when the radix_encode function processes file glob output from the ftpglob function.

  • CVE-2001-1342May 12, 2001
    risk 0.01cvss epss 0.08

    Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.

  • CVE-2001-1450May 11, 2001
    risk 0.01cvss epss 0.10

    Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./".

  • CVE-2001-1332May 10, 2001
    risk 0.00cvss epss 0.04

    Buffer overflows in Linux CUPS before 1.1.6 may allow remote attackers to execute arbitrary code.

  • CVE-2001-1333May 10, 2001
    risk 0.00cvss epss 0.00

    Linux CUPS before 1.1.6 does not securely handle temporary files, possibly due to a symlink vulnerability that could allow local users to overwrite files.

  • CVE-2001-0145May 3, 2001
    risk 0.01cvss epss 0.12

    Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.

  • CVE-2001-0147May 3, 2001
    risk 0.01cvss epss 0.14

    Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records.

  • CVE-2001-0152May 3, 2001
    risk 0.04cvss epss 0.08

    The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password information to a file, which allows local users to recover the passwords and read the compressed folders.

  • CVE-2001-0153May 3, 2001
    risk 0.00cvss epss 0.03

    Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.

  • CVE-2001-0154May 3, 2001
    risk 0.01cvss epss 0.17

    HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.

  • CVE-2001-0165May 3, 2001
    risk 0.03cvss epss 0.00

    Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.

  • CVE-2001-0167May 3, 2001
    risk 0.08cvss epss 0.65

    Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.

  • CVE-2001-0168May 3, 2001
    risk 0.08cvss epss 0.67

    Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.

  • CVE-2001-0171May 3, 2001
    risk 0.03cvss epss 0.05

    Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request.

  • CVE-2001-0173May 3, 2001
    risk 0.03cvss epss 0.04

    Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header.

  • CVE-2001-0174May 3, 2001
    risk 0.00cvss epss 0.01

    Buffer overflow in Trend Micro Virus Buster 2001 8.00 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a large "To" address.

  • CVE-2001-0179May 3, 2001
    risk 0.00cvss epss 0.03

    Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed URL that contains a "."

  • CVE-2001-0180May 3, 2001
    risk 0.00cvss epss 0.03

    Lars Ellingsen guestserver.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the "email" parameter.

  • CVE-2001-0186May 3, 2001
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

  • CVE-2001-0191May 3, 2001
    risk 0.00cvss epss 0.01

    gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.

  • CVE-2001-0192May 3, 2001
    risk 0.03cvss epss 0.05

    Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.

  • CVE-2001-0193May 3, 2001
    risk 0.03cvss epss 0.00

    Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.

  • CVE-2001-0194May 3, 2001
    risk 0.00cvss epss 0.02

    Buffer overflow in httpGets function in CUPS 1.1.5 allows remote attackers to execute arbitrary commands via a long input line.

  • CVE-2001-0196May 3, 2001
    risk 0.00cvss epss 0.01

    inetd ident server in FreeBSD 4.x and earlier does not properly set group permissions, which allows remote attackers to read the first 16 bytes of files that are accessible by the wheel group.

  • CVE-2001-0198May 3, 2001
    risk 0.04cvss epss 0.07

    Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.

  • CVE-2001-0199May 3, 2001
    risk 0.04cvss epss 0.08

    Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the HTTP GET request.

  • CVE-2001-0200May 3, 2001
    risk 0.03cvss epss 0.03

    HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled.

  • CVE-2001-0202May 3, 2001
    risk 0.03cvss epss 0.04

    Picserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request.

  • CVE-2001-0205May 3, 2001
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested pathname, a modified .. (dot dot) attack.

  • CVE-2001-0213May 3, 2001
    risk 0.00cvss epss 0.03

    Buffer overflow in pi program in PlanetIntra 2.5 allows remote attackers to execute arbitrary commands.

  • CVE-2001-0218May 3, 2001
    risk 0.00cvss epss 0.02

    Format string vulnerability in mars_nwe 0.99.pl19 allows remote attackers to execute arbitrary commands.

  • CVE-2001-0226May 3, 2001
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in BiblioWeb web server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) or ... attack in an HTTP GET request.

  • CVE-2001-0227May 3, 2001
    risk 0.00cvss epss 0.01

    Buffer overflow in BiblioWeb web server 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.