VYPR

CVEs

335,207 total · page 6649 of 6,705

  • CVE-2001-0088Feb 16, 2001
    risk 0.00cvss epss 0.01

    common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.

  • CVE-2001-0089Feb 16, 2001
    risk 0.06cvss epss 0.40

    Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.

  • CVE-2001-0090Feb 16, 2001
    risk 0.01cvss epss 0.08

    The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the "Browser Print Template" vulnerability.

  • CVE-2001-0091Feb 16, 2001
    risk 0.01cvss epss 0.13

    The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.

  • CVE-2001-0092Feb 16, 2001
    risk 0.01cvss epss 0.18

    A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.

  • CVE-2001-1439Feb 16, 2001
    risk 0.00cvss epss 0.02

    Buffer overflow in the text editor functionality in HP-UX 10.01 through 11.04 on HP9000 Series 700 and Series 800 allows local users to cause a denial of service ("system availability") via text editors such as (1) e, (2) ex, (3) vi, (4) edit, (5) view, and (6) vedit.

  • CVE-2000-0889Feb 12, 2001
    risk 0.00cvss epss 0.00

    Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun.

  • CVE-2000-0894Feb 12, 2001
    risk 0.00cvss epss 0.00

    HTTP server on the WatchGuard SOHO firewall does not properly restrict access to administrative functions such as password resets or rebooting, which allows attackers to cause a denial of service or conduct unauthorized activities.

  • CVE-2000-0895Feb 12, 2001
    risk 0.00cvss epss 0.04

    Buffer overflow in HTTP server on the WatchGuard SOHO firewall allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long GET request.

  • CVE-2000-0896Feb 12, 2001
    risk 0.00cvss epss 0.01

    WatchGuard SOHO firewall allows remote attackers to cause a denial of service via a flood of fragmented IP packets, which causes the firewall to drop connections and stop forwarding packets.

  • CVE-2000-1090Feb 12, 2001
    risk 0.01cvss epss 0.13

    Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.

  • CVE-2001-0003Feb 12, 2001
    risk 0.02cvss epss 0.29

    Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.

  • CVE-2001-0004Feb 12, 2001
    risk 0.06cvss epss 0.74

    IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.

  • CVE-2001-0005Feb 12, 2001
    risk 0.00cvss epss 0.00

    Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.

  • CVE-2001-0006HigFeb 12, 2001
    risk 0.49cvss 7.1epss 0.00

    The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.

  • CVE-2001-0007Feb 12, 2001
    risk 0.03cvss epss 0.06

    Buffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web administration interface.

  • CVE-2001-0008Feb 12, 2001
    risk 0.05cvss epss 0.20

    Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.

  • CVE-2001-0009Feb 12, 2001
    risk 0.04cvss epss 0.07

    Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack.

  • CVE-2001-0010Feb 12, 2001
    risk 0.10cvss epss 0.82

    Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.

  • CVE-2001-0011Feb 12, 2001
    risk 0.01cvss epss 0.07

    Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.

  • CVE-2001-0012Feb 12, 2001
    risk 0.01cvss epss 0.17

    BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.

  • CVE-2001-0013Feb 12, 2001
    risk 0.01cvss epss 0.19

    Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.

  • CVE-2001-0014Feb 12, 2001
    risk 0.02cvss epss 0.21

    Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.

  • CVE-2001-0019Feb 12, 2001
    risk 0.00cvss epss 0.00

    Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands.

  • CVE-2001-0020Feb 12, 2001
    risk 0.00cvss epss 0.00

    Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack.

  • CVE-2001-0022Feb 12, 2001
    risk 0.03cvss epss 0.05

    simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter.

  • CVE-2001-0023Feb 12, 2001
    risk 0.03cvss epss 0.03

    everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.

  • CVE-2001-0024Feb 12, 2001
    risk 0.03cvss epss 0.05

    simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter.

  • CVE-2001-0025Feb 12, 2001
    risk 0.03cvss epss 0.05

    ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.

  • CVE-2001-0026Feb 12, 2001
    risk 0.04cvss epss 0.12

    rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option.

  • CVE-2001-0027Feb 12, 2001
    risk 0.00cvss epss 0.01

    mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users.

  • CVE-2001-0028Feb 12, 2001
    risk 0.04cvss epss 0.11

    Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of " (quotation) characters.

  • CVE-2001-0029Feb 12, 2001
    risk 0.04cvss epss 0.07

    Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or domain name that is obtained from a reverse DNS lookup.

  • CVE-2001-0048Feb 12, 2001
    risk 0.00cvss epss 0.00

    The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.

  • CVE-2001-0053Feb 12, 2001
    risk 0.04cvss epss 0.16

    One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.

  • CVE-2001-0059Feb 12, 2001
    risk 0.03cvss epss 0.00

    patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.

  • CVE-2001-0060Feb 12, 2001
    risk 0.00cvss epss 0.01

    Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.

  • CVE-2001-0061Feb 12, 2001
    risk 0.00cvss epss 0.00

    procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by forking a child process and executing a privileged process from the child, while the parent retains access to the child's address space.

  • CVE-2001-0062Feb 12, 2001
    risk 0.00cvss epss 0.00

    procfs in FreeBSD and possibly other operating systems allows local users to cause a denial of service by calling mmap on the process' own mem file, which causes the kernel to hang.

  • CVE-2001-0063Feb 12, 2001
    risk 0.00cvss epss 0.00

    procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges.

  • CVE-2001-0064Feb 12, 2001
    risk 0.00cvss epss 0.01

    Webconfig, IMAP, and other services in MDaemon 3.5.0 and earlier allows remote attackers to cause a denial of service via a long URL terminated by a "\r\n" string.

  • CVE-2001-0065Feb 12, 2001
    risk 0.00cvss epss 0.03

    Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command.

  • CVE-2001-0067Feb 12, 2001
    risk 0.00cvss epss 0.00

    The installation of J-Pilot creates the .jpilot directory with the user's umask, which could allow local attackers to read other users' PalmOS backup information if their umasks are not securely set.

  • CVE-2001-0068Feb 12, 2001
    risk 0.00cvss epss 0.00

    Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter.

  • CVE-2001-0069Feb 12, 2001
    risk 0.00cvss epss 0.00

    dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack.

  • CVE-2001-0070Feb 12, 2001
    risk 0.00cvss epss 0.03

    Buffer overflow in 1st Up Mail Server 4.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long MAIL FROM command.

  • CVE-2001-0071Feb 12, 2001
    risk 0.00cvss epss 0.00

    gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.

  • CVE-2001-0072Feb 12, 2001
    risk 0.00cvss epss 0.01

    gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.

  • CVE-2001-0073Feb 12, 2001
    risk 0.00cvss epss 0.00

    Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory.

  • CVE-2001-0074Feb 12, 2001
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter.