| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2001-0835 | 0.00 | — | 0.03 | Dec 6, 2001 | Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS… | |||
| CVE-2001-0836 | 0.04 | — | 0.15 | Dec 6, 2001 | Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. | |||
| CVE-2001-0837 | 0.00 | — | 0.00 | Dec 6, 2001 | DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-readable locations in the installation directory, which allows local users to read the information in (1) temp.html, (2) the log folder, and (3) the PhoneBook folder. | |||
| CVE-2001-0838 | 0.04 | — | 0.07 | Dec 6, 2001 | Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command. | |||
| CVE-2001-0839 | 0.04 | — | 0.07 | Dec 6, 2001 | ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing. | |||
| CVE-2001-0840 | 0.01 | — | 0.09 | Dec 6, 2001 | Buffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI. | |||
| CVE-2001-0841 | 0.00 | — | 0.03 | Dec 6, 2001 | Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie. | |||
| CVE-2001-0842 | 0.00 | — | 0.03 | Dec 6, 2001 | Directory traversal vulnerability in Search.cgi in Leoboard LB5000 LB5000II 1029 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie. | |||
| CVE-2001-0843 | 0.00 | — | 0.03 | Dec 6, 2001 | Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request. | |||
| CVE-2001-0844 | 0.00 | — | 0.04 | Dec 6, 2001 | Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter. | |||
| CVE-2001-0845 | 0.00 | — | 0.00 | Dec 6, 2001 | Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources. | |||
| CVE-2001-0846 | 0.00 | — | 0.06 | Dec 6, 2001 | Lotus Domino 5.x allows remote attackers to read files or execute arbitrary code by requesting the ReplicaID of the Web Administrator template file (webadmin.ntf). | |||
| CVE-2001-0847 | 0.00 | — | 0.02 | Dec 6, 2001 | Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the ReplicaID. | |||
| CVE-2001-0848 | 0.00 | — | 0.00 | Dec 6, 2001 | join.cfm in e-Zone Media Fuse Talk allows a local user to execute arbitrary SQL code via a semi-colon (;) in a form variable. | |||
| CVE-2001-0849 | 0.00 | — | 0.03 | Dec 6, 2001 | viralator CGI script in Viralator 0.9pre1 and earlier allows remote attackers to execute arbitrary code via a URL for a file being downloaded, which is insecurely passed to a call to wget. | |||
| CVE-2001-0850 | 0.00 | — | 0.02 | Dec 6, 2001 | A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allow local or remote users to exploit those functions with a buffer overflow. | |||
| CVE-2001-0851 | 0.00 | — | 0.03 | Dec 6, 2001 | Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie. | |||
| CVE-2001-0852 | 0.04 | — | 0.09 | Dec 6, 2001 | TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header. | |||
| CVE-2001-0853 | 0.00 | — | 0.04 | Dec 6, 2001 | Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) AboutBox.gas.bat. | |||
| CVE-2001-0854 | 0.00 | — | 0.01 | Dec 6, 2001 | PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of the user. | |||
| CVE-2001-0855 | 0.03 | — | 0.01 | Dec 6, 2001 | Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM environment variable. | |||
| CVE-2001-0856 | — | 0.00 | — | 0.00 | Dec 6, 2001 | Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a brute force attack to create a 3DES exporter key. | ||
| CVE-2001-0857 | 0.03 | — | 0.03 | Dec 6, 2001 | Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter. | |||
| CVE-2001-0858 | 0.00 | — | 0.00 | Dec 6, 2001 | Buffer overflow in pppattach and other linked PPP utilities in Caldera Open Unix 8.0 and UnixWare 7.1.0 and 7.1.1 allows local users to gain privileges. | |||
| CVE-2001-0859 | 0.00 | — | 0.02 | Dec 6, 2001 | 2.4.3-12 kernel in Red Hat Linux 7.1 Korean installation program sets the setting default umask for init to 000, which installs files with world-writeable permissions. | |||
| CVE-2001-0860 | 0.00 | — | 0.05 | Dec 6, 2001 | Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Address Translation (NAT). | |||
| CVE-2001-0861 | 0.00 | — | 0.02 | Dec 6, 2001 | Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic that generates a large number of ICMP Unreachable replies. | |||
| CVE-2001-0862 | 0.00 | — | 0.02 | Dec 6, 2001 | Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL. | |||
| CVE-2001-0863 | 0.00 | — | 0.02 | Dec 6, 2001 | Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not handle the "fragment" keyword in a compiled ACL (Turbo ACL) for packets that are sent to the router, which allows remote attackers to cause a denial of service via a flood of fragments. | |||
| CVE-2001-0864 | 0.00 | — | 0.01 | Dec 6, 2001 | Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions. | |||
| CVE-2001-0865 | 0.00 | — | 0.01 | Dec 6, 2001 | Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not support the "fragment" keyword in an outgoing ACL, which could allow fragmented packets in violation of the intended access. | |||
| CVE-2001-0866 | 0.00 | — | 0.02 | Dec 6, 2001 | Cisco 12000 with IOS 12.0 and lines card based on Engine 2 does not properly handle an outbound ACL when an input ACL is not configured on all the interfaces of a multi port line card, which could allow remote attackers to bypass the intended access controls. | |||
| CVE-2001-0867 | 0.00 | — | 0.02 | Dec 6, 2001 | Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly filter does not properly filter packet fragments even when the "fragment" keyword is used in an ACL, which allows remote attackers to bypass the intended access controls. | |||
| CVE-2001-1247 | 0.01 | — | 0.09 | Dec 6, 2001 | PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files. | |||
| CVE-2001-1272 | 0.00 | — | 0.00 | Dec 6, 2001 | wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option. | |||
| CVE-2001-0946 | 0.00 | — | 0.00 | Dec 4, 2001 | apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification dates of arbitrary files via a symlink attack on the LOW_POWER temporary file, which could be used to cause a denial of service, e.g. by creating /etc/nologin and disabling logins. | |||
| CVE-2001-0947 | 0.00 | — | 0.02 | Dec 4, 2001 | Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path. | |||
| CVE-2001-0948 | 0.00 | — | 0.02 | Dec 4, 2001 | Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the… | |||
| CVE-2001-0949 | 0.00 | — | 0.04 | Dec 4, 2001 | Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4)… | |||
| CVE-2001-0950 | Hig | 0.49 | 7.5 | 0.02 | Dec 4, 2001 | ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which… | ||
| CVE-2001-0945 | 0.02 | — | 0.20 | Dec 3, 2001 | Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line. | |||
| CVE-2001-0944 | 0.00 | — | 0.00 | Dec 2, 2001 | DDE in mIRC allows local users to launch applications under another user's account via a DDE message that executes a command, which may be executed by the other user's process. | |||
| CVE-2001-1437 | 0.00 | — | 0.02 | Dec 1, 2001 | easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out. | |||
| CVE-2001-0550 | 0.09 | — | 0.75 | Nov 30, 2001 | wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob). | |||
| CVE-2001-0896 | 0.00 | — | 0.02 | Nov 30, 2001 | Inetd in OpenServer 5.0.5 allows remote attackers to cause a denial of service (crash) via a port scan, e.g. with nmap -PO. | |||
| CVE-2001-0912 | 0.00 | — | 0.00 | Nov 30, 2001 | Packaging error for expect 8.3.3 in Mandrake Linux 8.1 causes expect to search for its libraries in the /home/snailtalk directory before other directories, which could allow a local user to gain root privileges. | |||
| CVE-2001-0936 | 0.00 | — | 0.02 | Nov 30, 2001 | Buffer overflow in Frox transparent FTP proxy 0.6.6 and earlier, with the local caching method selected, allows remote FTP servers to run arbitrary code via a long response to an MDTM request. | |||
| CVE-2001-0937 | 0.00 | — | 0.02 | Nov 30, 2001 | PGPMail.pl 1.31 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) recipient or (2) pgpuserid parameters. | |||
| CVE-2001-0938 | 0.00 | — | 0.03 | Nov 30, 2001 | Directory traversal vulnerability in AspUpload 2.1, in certain configurations, allows remote attackers to upload and read arbitrary files, and list arbitrary directories, via a .. (dot dot) in the Filename parameter in (1) UploadScript11.asp or (2) DirectoryListing.asp. | |||
| CVE-2001-0939 | 0.00 | — | 0.02 | Nov 30, 2001 | Lotus Domino 5.08 and earlier allows remote attackers to cause a denial of service (crash) via a SunRPC NULL command to port 443. |
- CVE-2001-0835Dec 6, 2001risk 0.00cvss —epss 0.03
Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS…
- CVE-2001-0836Dec 6, 2001risk 0.04cvss —epss 0.15
Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.
- CVE-2001-0837Dec 6, 2001risk 0.00cvss —epss 0.00
DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-readable locations in the installation directory, which allows local users to read the information in (1) temp.html, (2) the log folder, and (3) the PhoneBook folder.
- CVE-2001-0838Dec 6, 2001risk 0.04cvss —epss 0.07
Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.
- CVE-2001-0839Dec 6, 2001risk 0.04cvss —epss 0.07
ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing.
- CVE-2001-0840Dec 6, 2001risk 0.01cvss —epss 0.09
Buffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI.
- CVE-2001-0841Dec 6, 2001risk 0.00cvss —epss 0.03
Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.
- CVE-2001-0842Dec 6, 2001risk 0.00cvss —epss 0.03
Directory traversal vulnerability in Search.cgi in Leoboard LB5000 LB5000II 1029 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.
- CVE-2001-0843Dec 6, 2001risk 0.00cvss —epss 0.03
Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request.
- CVE-2001-0844Dec 6, 2001risk 0.00cvss —epss 0.04
Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter.
- CVE-2001-0845Dec 6, 2001risk 0.00cvss —epss 0.00
Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources.
- CVE-2001-0846Dec 6, 2001risk 0.00cvss —epss 0.06
Lotus Domino 5.x allows remote attackers to read files or execute arbitrary code by requesting the ReplicaID of the Web Administrator template file (webadmin.ntf).
- CVE-2001-0847Dec 6, 2001risk 0.00cvss —epss 0.02
Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the ReplicaID.
- CVE-2001-0848Dec 6, 2001risk 0.00cvss —epss 0.00
join.cfm in e-Zone Media Fuse Talk allows a local user to execute arbitrary SQL code via a semi-colon (;) in a form variable.
- CVE-2001-0849Dec 6, 2001risk 0.00cvss —epss 0.03
viralator CGI script in Viralator 0.9pre1 and earlier allows remote attackers to execute arbitrary code via a URL for a file being downloaded, which is insecurely passed to a call to wget.
- CVE-2001-0850Dec 6, 2001risk 0.00cvss —epss 0.02
A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allow local or remote users to exploit those functions with a buffer overflow.
- CVE-2001-0851Dec 6, 2001risk 0.00cvss —epss 0.03
Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie.
- CVE-2001-0852Dec 6, 2001risk 0.04cvss —epss 0.09
TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header.
- CVE-2001-0853Dec 6, 2001risk 0.00cvss —epss 0.04
Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) AboutBox.gas.bat.
- CVE-2001-0854Dec 6, 2001risk 0.00cvss —epss 0.01
PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of the user.
- CVE-2001-0855Dec 6, 2001risk 0.03cvss —epss 0.01
Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM environment variable.
- CVE-2001-0856Dec 6, 2001risk 0.00cvss —epss 0.00
Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a brute force attack to create a 3DES exporter key.
- CVE-2001-0857Dec 6, 2001risk 0.03cvss —epss 0.03
Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter.
- CVE-2001-0858Dec 6, 2001risk 0.00cvss —epss 0.00
Buffer overflow in pppattach and other linked PPP utilities in Caldera Open Unix 8.0 and UnixWare 7.1.0 and 7.1.1 allows local users to gain privileges.
- CVE-2001-0859Dec 6, 2001risk 0.00cvss —epss 0.02
2.4.3-12 kernel in Red Hat Linux 7.1 Korean installation program sets the setting default umask for init to 000, which installs files with world-writeable permissions.
- CVE-2001-0860Dec 6, 2001risk 0.00cvss —epss 0.05
Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Address Translation (NAT).
- CVE-2001-0861Dec 6, 2001risk 0.00cvss —epss 0.02
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic that generates a large number of ICMP Unreachable replies.
- CVE-2001-0862Dec 6, 2001risk 0.00cvss —epss 0.02
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL.
- CVE-2001-0863Dec 6, 2001risk 0.00cvss —epss 0.02
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not handle the "fragment" keyword in a compiled ACL (Turbo ACL) for packets that are sent to the router, which allows remote attackers to cause a denial of service via a flood of fragments.
- CVE-2001-0864Dec 6, 2001risk 0.00cvss —epss 0.01
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions.
- CVE-2001-0865Dec 6, 2001risk 0.00cvss —epss 0.01
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not support the "fragment" keyword in an outgoing ACL, which could allow fragmented packets in violation of the intended access.
- CVE-2001-0866Dec 6, 2001risk 0.00cvss —epss 0.02
Cisco 12000 with IOS 12.0 and lines card based on Engine 2 does not properly handle an outbound ACL when an input ACL is not configured on all the interfaces of a multi port line card, which could allow remote attackers to bypass the intended access controls.
- CVE-2001-0867Dec 6, 2001risk 0.00cvss —epss 0.02
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly filter does not properly filter packet fragments even when the "fragment" keyword is used in an ACL, which allows remote attackers to bypass the intended access controls.
- CVE-2001-1247Dec 6, 2001risk 0.01cvss —epss 0.09
PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files.
- CVE-2001-1272Dec 6, 2001risk 0.00cvss —epss 0.00
wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option.
- CVE-2001-0946Dec 4, 2001risk 0.00cvss —epss 0.00
apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification dates of arbitrary files via a symlink attack on the LOW_POWER temporary file, which could be used to cause a denial of service, e.g. by creating /etc/nologin and disabling logins.
- CVE-2001-0947Dec 4, 2001risk 0.00cvss —epss 0.02
Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path.
- CVE-2001-0948Dec 4, 2001risk 0.00cvss —epss 0.02
Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the…
- CVE-2001-0949Dec 4, 2001risk 0.00cvss —epss 0.04
Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4)…
- risk 0.49cvss 7.5epss 0.02
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which…
- CVE-2001-0945Dec 3, 2001risk 0.02cvss —epss 0.20
Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line.
- CVE-2001-0944Dec 2, 2001risk 0.00cvss —epss 0.00
DDE in mIRC allows local users to launch applications under another user's account via a DDE message that executes a command, which may be executed by the other user's process.
- CVE-2001-1437Dec 1, 2001risk 0.00cvss —epss 0.02
easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out.
- CVE-2001-0550Nov 30, 2001risk 0.09cvss —epss 0.75
wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).
- CVE-2001-0896Nov 30, 2001risk 0.00cvss —epss 0.02
Inetd in OpenServer 5.0.5 allows remote attackers to cause a denial of service (crash) via a port scan, e.g. with nmap -PO.
- CVE-2001-0912Nov 30, 2001risk 0.00cvss —epss 0.00
Packaging error for expect 8.3.3 in Mandrake Linux 8.1 causes expect to search for its libraries in the /home/snailtalk directory before other directories, which could allow a local user to gain root privileges.
- CVE-2001-0936Nov 30, 2001risk 0.00cvss —epss 0.02
Buffer overflow in Frox transparent FTP proxy 0.6.6 and earlier, with the local caching method selected, allows remote FTP servers to run arbitrary code via a long response to an MDTM request.
- CVE-2001-0937Nov 30, 2001risk 0.00cvss —epss 0.02
PGPMail.pl 1.31 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) recipient or (2) pgpuserid parameters.
- CVE-2001-0938Nov 30, 2001risk 0.00cvss —epss 0.03
Directory traversal vulnerability in AspUpload 2.1, in certain configurations, allows remote attackers to upload and read arbitrary files, and list arbitrary directories, via a .. (dot dot) in the Filename parameter in (1) UploadScript11.asp or (2) DirectoryListing.asp.
- CVE-2001-0939Nov 30, 2001risk 0.00cvss —epss 0.02
Lotus Domino 5.08 and earlier allows remote attackers to cause a denial of service (crash) via a SunRPC NULL command to port 443.