275751
|
7.5 |
HIGH
|
lotus
|
domino_r5_server
|
Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that …
|
NVD-CWE-Other
|
CVE-2001-1161
|
2008-09-6 05:25 |
2001-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275752
|
10.0 |
HIGH
|
munica
|
netsql
|
Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.
|
NVD-CWE-Other
|
CVE-2001-1163
|
2008-09-6 05:25 |
2001-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275753
|
7.2 |
HIGH
|
caldera
|
unixware
|
Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.
|
NVD-CWE-Other
|
CVE-2001-1164
|
2008-09-6 05:25 |
2001-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275754
|
4.6 |
MEDIUM
|
intego
|
diskguard fileguard
|
Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by decrypting the information, e.g., with the Disengage tool.
|
NVD-CWE-Other
|
CVE-2001-1165
|
2008-09-6 05:25 |
2002-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275755
|
5.0 |
MEDIUM
|
freebsd
|
freebsd
|
linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that pro…
|
NVD-CWE-Other
|
CVE-2001-1166
|
2008-09-6 05:25 |
2001-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275756
|
7.5 |
HIGH
|
bell_communications_research
|
s_key
|
keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for …
|
NVD-CWE-Other
|
CVE-2001-1169
|
2008-09-6 05:25 |
2001-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275757
|
7.2 |
HIGH
|
checkpoint
|
firewall-1
|
Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify t…
|
NVD-CWE-Other
|
CVE-2001-1171
|
2008-09-6 05:25 |
2002-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275758
|
7.2 |
HIGH
|
xfree86_project
|
x11r6
|
xman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters.
|
NVD-CWE-Other
|
CVE-2001-1179
|
2008-09-6 05:25 |
2001-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275759
|
5.0 |
MEDIUM
|
denicomp
|
winsock_rshd_nt
|
wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a neg…
|
NVD-CWE-Other
|
CVE-2001-1184
|
2008-09-6 05:25 |
2001-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275760
|
6.2 |
MEDIUM
|
freebsd
|
freebsd
|
Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges.
|
NVD-CWE-Other
|
CVE-2001-1185
|
2008-09-6 05:25 |
2001-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275761
|
7.5 |
HIGH
|
brian_dorricott
|
mailto
|
mailto.exe in Brian Dorricott MAILTO 1.0.9 and earlier allows remote attackers to send SPAM e-mail through remote servers by modifying the sendto, email, server, subject, and resulturl hidden form fi…
|
NVD-CWE-Other
|
CVE-2001-1188
|
2008-09-6 05:25 |
2001-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275762
|
4.6 |
MEDIUM
|
ibm
|
websphere_application_server
|
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
|
NVD-CWE-Other
|
CVE-2001-1189
|
2008-09-6 05:25 |
2001-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275763
|
4.6 |
MEDIUM
|
mandrakesoft
|
mandrake_linux
|
The default PAM files included with passwd in Mandrake Linux 8.1 do not support MD5 passwords, which could result in a lower level of password security than intended.
|
NVD-CWE-Other
|
CVE-2001-1190
|
2008-09-6 05:25 |
2001-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275764
|
5.0 |
MEDIUM
|
ibm
|
tivoli_secureway_policy_director
|
WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.
|
NVD-CWE-Other
|
CVE-2001-1191
|
2008-09-6 05:25 |
2001-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275765
|
7.2 |
HIGH
|
microsoft
|
windows_xp
|
Microsoft Windows XP allows local users to bypass a locked screen and run certain programs that are associated with Hot Keys.
|
NVD-CWE-Other
|
CVE-2001-1200
|
2008-09-6 05:25 |
2001-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275766
|
7.5 |
HIGH
|
daydream
|
daydream_bbs
|
Buffer overflows in DayDream BBS 2.9 through 2.13 allow remote attackers to possibly execute arbitrary code via the control codes (1) ~#MC, (2) ~#TF, or (3) ~#RA.
|
NVD-CWE-Other
|
CVE-2001-1207
|
2008-09-6 05:25 |
2001-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275767
|
7.5 |
HIGH
|
ipswitch
|
imail
|
Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) alia…
|
NVD-CWE-Other
|
CVE-2001-1211
|
2008-09-6 05:25 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275768
|
7.5 |
HIGH
|
oracle
|
application_server
|
Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.
|
NVD-CWE-Other
|
CVE-2001-1216
|
2008-09-6 05:25 |
2001-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275769
|
5.0 |
MEDIUM
|
oracle
|
application_server
|
Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) seq…
|
NVD-CWE-Other
|
CVE-2001-1217
|
2008-09-6 05:25 |
2001-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275770
|
10.0 |
HIGH
|
d-link
|
dwl-1000ap
|
D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point stores the administrative password in plaintext in the default Management Information Base (MIB), which allows remote attackers to gai…
|
NVD-CWE-Other
|
CVE-2001-1220
|
2008-09-6 05:25 |
2001-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275771
|
5.0 |
MEDIUM
|
d-link
|
dwl-1000ap
|
D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of 'public' which allows remote attackers to gain sensitive information.
|
NVD-CWE-Other
|
CVE-2001-1221
|
2008-09-6 05:25 |
2001-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275772
|
5.0 |
MEDIUM
|
plesk
|
plesk_server_administrator
|
Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.
|
NVD-CWE-Other
|
CVE-2001-1222
|
2008-09-6 05:25 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275773
|
10.0 |
HIGH
|
elsa
|
lancom_1100_office
|
The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server.
|
NVD-CWE-Other
|
CVE-2001-1223
|
2008-09-6 05:25 |
2001-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275774
|
5.0 |
MEDIUM
|
lightwave
|
consoleserver
|
The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.
|
NVD-CWE-Other
|
CVE-2001-0396
|
2008-09-6 05:24 |
2001-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275775
|
7.5 |
HIGH
|
silent_runner
|
silent_runner_collector_src
|
Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.
|
NVD-CWE-Other
|
CVE-2001-0397
|
2008-09-6 05:24 |
2001-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275776
|
7.5 |
HIGH
|
ritlabs
|
the_bat
|
The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also caus…
|
NVD-CWE-Other
|
CVE-2001-0398
|
2008-09-6 05:24 |
2001-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275777
|
7.5 |
HIGH
|
matt_tourtillott
|
nph-maillist
|
nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.
|
NVD-CWE-Other
|
CVE-2001-0400
|
2008-09-6 05:24 |
2001-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275778
|
2.1 |
LOW
|
samba
|
samba
|
Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.
|
NVD-CWE-Other
|
CVE-2001-0406
|
2008-09-6 05:24 |
2001-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275779
|
5.0 |
MEDIUM
|
ncm
|
ncm_content_management_system
|
content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.
|
NVD-CWE-Other
|
CVE-2001-0418
|
2008-09-6 05:24 |
2001-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275780
|
5.0 |
MEDIUM
|
way_to_the_web
|
talkback
|
Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.
|
NVD-CWE-Other
|
CVE-2001-0420
|
2008-09-6 05:24 |
2001-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275781
|
7.5 |
HIGH
|
adcycle
|
adcycle
|
AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to ver…
|
NVD-CWE-Other
|
CVE-2001-0425
|
2008-09-6 05:24 |
2001-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275782
|
10.0 |
HIGH
|
trend_micro
|
interscan_viruswall
|
Buffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-2001-0432
|
2008-09-6 05:24 |
2001-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275783
|
2.1 |
LOW
|
netopia
|
timbuktu_mac
|
Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu.
|
NVD-CWE-Other
|
CVE-2001-0438
|
2008-09-6 05:24 |
2001-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275784
|
7.5 |
HIGH
|
david_harris
|
mercury_nlm
|
Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP command.
|
NVD-CWE-Other
|
CVE-2001-0442
|
2008-09-6 05:24 |
2001-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275785
|
7.5 |
HIGH
|
software602
|
602pro_lan_suite
|
Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characte…
|
NVD-CWE-Other
|
CVE-2001-0447
|
2008-09-6 05:24 |
2001-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275786
|
5.0 |
MEDIUM
|
software602
|
602pro_lan_suite
|
Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS dev…
|
NVD-CWE-Other
|
CVE-2001-0448
|
2008-09-6 05:24 |
2001-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275787
|
5.0 |
MEDIUM
|
brs
|
webweaver
|
BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.
|
NVD-CWE-Other
|
CVE-2001-0452
|
2008-09-6 05:24 |
2001-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275788
|
5.0 |
MEDIUM
|
brs
|
webweaver
|
Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) scripts directories.
|
NVD-CWE-Other
|
CVE-2001-0453
|
2008-09-6 05:24 |
2001-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275789
|
7.5 |
HIGH
|
ssh
|
ssh
|
SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attac…
|
NVD-CWE-Other
|
CVE-2001-0471
|
2008-09-6 05:24 |
2001-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275790
|
7.5 |
HIGH
|
webcalendar
|
webcalendar
|
Vulnerability in WebCalendar 0.9.26 allows remote command execution.
|
NVD-CWE-Other
|
CVE-2001-0477
|
2008-09-6 05:24 |
2001-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275791
|
7.5 |
HIGH
|
phpmyadmin
|
phpmyadmin
|
Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.
|
NVD-CWE-Other
|
CVE-2001-0478
|
2008-09-6 05:24 |
2001-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275792
|
5.0 |
MEDIUM
|
alex_linde
|
alexs_ftp_server
|
Directory traversal vulnerability in Alex's FTP Server 0.7 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the (1) GET or (2) CD commands.
|
NVD-CWE-Other
|
CVE-2001-0480
|
2008-09-6 05:24 |
2001-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275793
|
7.5 |
HIGH
|
symantec
|
raptor_firewall
|
Configuration error in Axent Raptor Firewall 6.5 allows remote attackers to use the firewall as a proxy to access internal web resources when the http.noproxy Rule is not set.
|
NVD-CWE-Other
|
CVE-2001-0483
|
2008-09-6 05:24 |
2001-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275794
|
7.5 |
HIGH
|
nullsoft
|
winamp
|
Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file.
|
NVD-CWE-Other
|
CVE-2001-0490
|
2008-09-6 05:24 |
2001-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275795
|
7.5 |
HIGH
|
macromedia
|
coldfusion_server
|
Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or exe…
|
NVD-CWE-Other
|
CVE-2001-0535
|
2008-09-6 05:24 |
2001-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275796
|
2.1 |
LOW
|
zope
|
zope
|
Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes.
|
NVD-CWE-Other
|
CVE-2001-0568
|
2008-09-6 05:24 |
2001-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275797
|
2.1 |
LOW
|
zope
|
zope
|
Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) ObjectManager, (2) PropertyManager, and (3) PropertySheet.
|
NVD-CWE-Other
|
CVE-2001-0569
|
2008-09-6 05:24 |
2001-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275798
|
7.5 |
HIGH
|
openbsd ssh
|
openssh ssh
|
The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker to obtain the following information via sniffing: (1) pass…
|
NVD-CWE-Other
|
CVE-2001-0572
|
2008-09-6 05:24 |
2001-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275799
|
7.5 |
HIGH
|
sun
|
chilisoft
|
Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.
|
NVD-CWE-Other
|
CVE-2001-0632
|
2008-09-6 05:24 |
2001-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275800
|
5.0 |
MEDIUM
|
sun
|
chilisoft
|
Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a '..' (dot dot) attack in the sample script 'codebr…
|
NVD-CWE-Other
|
CVE-2001-0633
|
2008-09-6 05:24 |
2001-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|