276451
|
6.4 |
MEDIUM
|
fraunhofer_fit
|
bscw
|
BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space.
|
NVD-CWE-Other
|
CVE-2001-0973
|
2008-09-6 05:25 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276452
|
7.2 |
HIGH
|
hp
|
process_resource_manager
|
Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment var…
|
NVD-CWE-Other
|
CVE-2001-0976
|
2008-09-6 05:25 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276453
|
7.5 |
HIGH
|
hp
|
hp-ux
|
login in HP-UX 10.26 does not record failed login attempts in /var/adm/btmp, which could allow attackers to conduct brute force password guessing attacks without being detected or observed using the …
|
NVD-CWE-Other
|
CVE-2001-0978
|
2008-09-6 05:25 |
2001-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276454
|
7.2 |
HIGH
|
richard_everitt
|
pileup
|
Buffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or (2) a long callsign.
|
NVD-CWE-Other
|
CVE-2001-0989
|
2008-09-6 05:25 |
2001-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276455
|
5.0 |
MEDIUM
|
gnutella
|
gnutella_client
|
Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name contains the script ta…
|
NVD-CWE-Other
|
CVE-2001-1004
|
2008-09-6 05:25 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276456
|
7.5 |
HIGH
|
starfish
|
truesync_desktop
|
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registry key to decrypt the…
|
NVD-CWE-Other
|
CVE-2001-1005
|
2008-09-6 05:25 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276457
|
5.0 |
MEDIUM
|
starfish
|
truesync_desktop
|
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to restrict access, which allows an attacker to read the files us…
|
NVD-CWE-Other
|
CVE-2001-1006
|
2008-09-6 05:25 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276458
|
5.0 |
MEDIUM
|
starfish
|
truesync_desktop
|
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly g…
|
NVD-CWE-Other
|
CVE-2001-1007
|
2008-09-6 05:25 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276459
|
7.5 |
HIGH
|
sun
|
java_plug-in jre
|
Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an …
|
NVD-CWE-Other
|
CVE-2001-1008
|
2008-09-6 05:25 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276460
|
7.2 |
HIGH
|
snes9x.com
|
snes9x
|
Buffer overflow in Snes9x 1.37, when installed setuid root, allows local users to gain root privileges via a long command line argument.
|
NVD-CWE-Other
|
CVE-2001-1015
|
2008-09-6 05:25 |
2001-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276461
|
10.0 |
HIGH
|
francisco_burzi
|
php-nuke
|
PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including…
|
NVD-CWE-Other
|
CVE-2001-1025
|
2008-09-6 05:25 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276462
|
7.2 |
HIGH
|
redhat
|
linux
|
Buffer overflow in ultimate_source function of man 1.5 and earlier allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2001-1028
|
2008-09-6 05:25 |
2001-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276463
|
7.5 |
HIGH
|
hp
|
jetadmin
|
The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer.
|
NVD-CWE-Other
|
CVE-2001-1039
|
2008-09-6 05:25 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276464
|
6.4 |
MEDIUM
|
hp
|
jetadmin
|
HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password.
|
NVD-CWE-Other
|
CVE-2001-1040
|
2008-09-6 05:25 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276465
|
7.5 |
HIGH
|
topher1kenobe
|
awol
|
AWOL PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
|
NVD-CWE-Other
|
CVE-2001-1048
|
2008-09-6 05:25 |
2001-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276466
|
10.0 |
HIGH
|
ibm
|
aix
|
Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.
|
NVD-CWE-Other
|
CVE-2001-1061
|
2008-09-6 05:25 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276467
|
7.5 |
HIGH
|
lucent simon_horms
|
radius
|
Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via format specifiers th…
|
NVD-CWE-Other
|
CVE-2001-1081
|
2008-09-6 05:25 |
2001-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276468
|
5.0 |
MEDIUM
|
lucent simon_horms
|
radius
|
Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack.
|
NVD-CWE-Other
|
CVE-2001-1082
|
2008-09-6 05:25 |
2001-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276469
|
5.0 |
MEDIUM
|
khamil_landross_and_zack_jones
|
eftp
|
EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that o…
|
NVD-CWE-Other
|
CVE-2001-1110
|
2008-09-6 05:25 |
2001-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276470
|
5.0 |
MEDIUM
|
whitsoft_development
|
slimftpd
|
Directory traversal vulnerability in WhitSoft Development SlimFTPd 2.2 allows an attacker to read arbitrary files and directories via a ... (modified dot dot) in the CD command.
|
NVD-CWE-Other
|
CVE-2001-1131
|
2008-09-6 05:25 |
2001-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276471
|
2.1 |
LOW
|
bsdi
|
bsd_os
|
Vulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kernel via a particular sequence of instructions.
|
NVD-CWE-Other
|
CVE-2001-1133
|
2008-09-6 05:25 |
2001-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276472
|
5.0 |
MEDIUM
|
ascii_nt
|
winwrapper_professional
|
Directory traversal vulnerability in ASCII NT WinWrapper Professional allows remote attackers to read arbitrary files via a .. (dot dot) in the server request.
|
NVD-CWE-Other
|
CVE-2001-1139
|
2008-09-6 05:25 |
2001-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276473
|
5.0 |
MEDIUM
|
argosoft
|
ftp_server
|
ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the password file to gain privileges.
|
NVD-CWE-Other
|
CVE-2001-1142
|
2008-09-6 05:25 |
2001-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276474
|
5.0 |
MEDIUM
|
ibm
|
db2_universal_database
|
IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.
|
NVD-CWE-Other
|
CVE-2001-1143
|
2008-09-6 05:25 |
2001-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276475
|
7.2 |
HIGH
|
andries_brouwer
|
util-linux
|
The PAM implementation in /bin/login of the util-linux package before 2.11 causes a password entry to be rewritten across multiple PAM calls, which could provide the credentials of one user to a diff…
|
NVD-CWE-Other
|
CVE-2001-1147
|
2008-09-6 05:25 |
2001-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276476
|
5.0 |
MEDIUM
|
panda
|
panda_antivirus_platinum
|
Panda Antivirus Platinum before 6.23.00 allows a remore attacker to cause a denial of service (crash) when a user selects an action for a malformed UPX packed executable file.
|
NVD-CWE-Other
|
CVE-2001-1149
|
2008-09-6 05:25 |
2001-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276477
|
5.0 |
MEDIUM
|
trend_micro
|
officescan virus_buster
|
Vulnerability in cgiWebupdate.exe in Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.5.2 through 3.5.4 allows remote attackers to read arbitrary files.
|
NVD-CWE-Other
|
CVE-2001-1150
|
2008-09-6 05:25 |
2001-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276478
|
7.5 |
HIGH
|
baltimore_technologies
|
websweeper
|
Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested…
|
NVD-CWE-Other
|
CVE-2001-1152
|
2008-09-6 05:25 |
2001-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276479
|
5.0 |
MEDIUM
|
typsoft
|
typsoft_ftp_server
|
TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1) STOR or (2) RETR.
|
NVD-CWE-Other
|
CVE-2001-1156
|
2008-09-6 05:25 |
2001-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276480
|
7.5 |
HIGH
|
baltimore_technologies
|
websweeper
|
Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or mo…
|
NVD-CWE-Other
|
CVE-2001-1157
|
2008-09-6 05:25 |
2001-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276481
|
7.5 |
HIGH
|
squirrelmail
|
squirrelmail
|
load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the confi…
|
NVD-CWE-Other
|
CVE-2001-1159
|
2008-09-6 05:25 |
2001-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276482
|
7.5 |
HIGH
|
lotus
|
domino_r5_server
|
Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that …
|
NVD-CWE-Other
|
CVE-2001-1161
|
2008-09-6 05:25 |
2001-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276483
|
10.0 |
HIGH
|
munica
|
netsql
|
Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.
|
NVD-CWE-Other
|
CVE-2001-1163
|
2008-09-6 05:25 |
2001-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276484
|
7.2 |
HIGH
|
caldera
|
unixware
|
Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.
|
NVD-CWE-Other
|
CVE-2001-1164
|
2008-09-6 05:25 |
2001-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276485
|
4.6 |
MEDIUM
|
intego
|
diskguard fileguard
|
Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by decrypting the information, e.g., with the Disengage tool.
|
NVD-CWE-Other
|
CVE-2001-1165
|
2008-09-6 05:25 |
2002-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276486
|
5.0 |
MEDIUM
|
freebsd
|
freebsd
|
linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that pro…
|
NVD-CWE-Other
|
CVE-2001-1166
|
2008-09-6 05:25 |
2001-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276487
|
7.5 |
HIGH
|
bell_communications_research
|
s_key
|
keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for …
|
NVD-CWE-Other
|
CVE-2001-1169
|
2008-09-6 05:25 |
2001-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276488
|
7.2 |
HIGH
|
checkpoint
|
firewall-1
|
Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify t…
|
NVD-CWE-Other
|
CVE-2001-1171
|
2008-09-6 05:25 |
2002-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276489
|
7.2 |
HIGH
|
xfree86_project
|
x11r6
|
xman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters.
|
NVD-CWE-Other
|
CVE-2001-1179
|
2008-09-6 05:25 |
2001-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276490
|
5.0 |
MEDIUM
|
denicomp
|
winsock_rshd_nt
|
wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a neg…
|
NVD-CWE-Other
|
CVE-2001-1184
|
2008-09-6 05:25 |
2001-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276491
|
6.2 |
MEDIUM
|
freebsd
|
freebsd
|
Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges.
|
NVD-CWE-Other
|
CVE-2001-1185
|
2008-09-6 05:25 |
2001-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276492
|
7.5 |
HIGH
|
brian_dorricott
|
mailto
|
mailto.exe in Brian Dorricott MAILTO 1.0.9 and earlier allows remote attackers to send SPAM e-mail through remote servers by modifying the sendto, email, server, subject, and resulturl hidden form fi…
|
NVD-CWE-Other
|
CVE-2001-1188
|
2008-09-6 05:25 |
2001-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276493
|
4.6 |
MEDIUM
|
ibm
|
websphere_application_server
|
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
|
NVD-CWE-Other
|
CVE-2001-1189
|
2008-09-6 05:25 |
2001-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276494
|
4.6 |
MEDIUM
|
mandrakesoft
|
mandrake_linux
|
The default PAM files included with passwd in Mandrake Linux 8.1 do not support MD5 passwords, which could result in a lower level of password security than intended.
|
NVD-CWE-Other
|
CVE-2001-1190
|
2008-09-6 05:25 |
2001-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276495
|
5.0 |
MEDIUM
|
ibm
|
tivoli_secureway_policy_director
|
WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.
|
NVD-CWE-Other
|
CVE-2001-1191
|
2008-09-6 05:25 |
2001-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276496
|
7.2 |
HIGH
|
microsoft
|
windows_xp
|
Microsoft Windows XP allows local users to bypass a locked screen and run certain programs that are associated with Hot Keys.
|
NVD-CWE-Other
|
CVE-2001-1200
|
2008-09-6 05:25 |
2001-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276497
|
7.5 |
HIGH
|
daydream
|
daydream_bbs
|
Buffer overflows in DayDream BBS 2.9 through 2.13 allow remote attackers to possibly execute arbitrary code via the control codes (1) ~#MC, (2) ~#TF, or (3) ~#RA.
|
NVD-CWE-Other
|
CVE-2001-1207
|
2008-09-6 05:25 |
2001-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276498
|
7.5 |
HIGH
|
ipswitch
|
imail
|
Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) alia…
|
NVD-CWE-Other
|
CVE-2001-1211
|
2008-09-6 05:25 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276499
|
7.5 |
HIGH
|
oracle
|
application_server
|
Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.
|
NVD-CWE-Other
|
CVE-2001-1216
|
2008-09-6 05:25 |
2001-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276500
|
5.0 |
MEDIUM
|
oracle
|
application_server
|
Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) seq…
|
NVD-CWE-Other
|
CVE-2001-1217
|
2008-09-6 05:25 |
2001-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|