|
346251
|
7.5 |
HIGH
|
astart_technologies
|
lprng
|
The default configuration of LPRng print spooler in Red Hat Linux 7.0 through 7.3, Mandrake 8.1 and 8.2, and other operating systems, accepts print jobs from arbitrary remote hosts.
|
NVD-CWE-Other
|
CVE-2002-0378
|
2008-09-11 04:11 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346252
|
7.5 |
HIGH
|
rob_flynn
|
gaim
|
Buffer overflow in Jabber plug-in for Gaim client before 0.58 allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2002-0384
|
2008-09-11 04:11 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346253
|
5.0 |
MEDIUM
|
oracle
|
application_server
|
The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request containing a ".." (d…
|
NVD-CWE-Other
|
CVE-2002-0386
|
2008-09-11 04:11 |
2002-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346254
|
5.0 |
MEDIUM
|
isc
|
bind
|
ISC BIND 9 before 9.2.1 allows remote attackers to cause a denial of service (shutdown) via a malformed DNS packet that triggers an error condition that is not properly handled when the rdataset para…
|
NVD-CWE-Other
|
CVE-2002-0400
|
2008-09-11 04:11 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346255
|
7.5 |
HIGH
|
peaceworks_computer_consulting
|
phormation
|
Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable.
|
NVD-CWE-Other
|
CVE-2001-1237
|
2008-09-11 04:10 |
2001-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346256
|
5.0 |
MEDIUM
|
connect_inc.
|
powernet_ix
|
PowerNet IX allows remote attackers to cause a denial of service via a port scan.
|
NVD-CWE-Other
|
CVE-2001-1239
|
2008-09-11 04:10 |
2001-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346257
|
7.5 |
HIGH
|
steve_grimm
|
un-cgi
|
Un-CGI 1.9 and earlier does not verify that a CGI script has the execution bits set before executing it, which allows remote attackers to execute arbitrary commands by directing Un-CGI to a document …
|
NVD-CWE-Other
|
CVE-2001-1241
|
2008-09-11 04:10 |
2001-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346258
|
7.5 |
HIGH
|
steve_grimm
|
un-cgi
|
Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form.
|
NVD-CWE-Other
|
CVE-2001-1242
|
2008-09-11 04:10 |
2001-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346259
|
5.0 |
MEDIUM
|
vwebserver
|
vwebserver
|
vWebServer 1.2.0 allows remote attackers to view arbitrary ASP scripts via a request for an ASP script that ends with a URL-encoded space character (%20).
|
NVD-CWE-Other
|
CVE-2001-1248
|
2008-09-11 04:10 |
2001-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346260
|
5.0 |
MEDIUM
|
vwebserver
|
vwebserver
|
vWebServer 1.2.0 allows remote attackers to cause a denial of service via a URL that contains MS-DOS device names.
|
NVD-CWE-Other
|
CVE-2001-1249
|
2008-09-11 04:10 |
2001-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346261
|
5.0 |
MEDIUM
|
vwebserver
|
vwebserver
|
vWebServer 1.2.0 allows remote attackers to cause a denial of service (hang) via a small number of long URL requests, possibly due to a buffer overflow.
|
NVD-CWE-Other
|
CVE-2001-1250
|
2008-09-11 04:10 |
2001-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346262
|
5.0 |
MEDIUM
|
max_feoktistov vwebserver
|
small_http_server vwebserver
|
SmallHTTP 1.204 through 3.00 beta 8 allows remote attackers to cause a denial of service via multiple long URL requests.
|
NVD-CWE-Other
|
CVE-2001-1251
|
2008-09-11 04:10 |
2001-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346263
|
10.0 |
HIGH
|
pgp
|
keyserver
|
Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs that directly access cgi-bin instead of keyserver/cgi-bin fo…
|
NVD-CWE-Other
|
CVE-2001-1252
|
2008-09-11 04:10 |
2001-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346264
|
7.5 |
HIGH
|
com2001
|
alexis_server
|
Web Access component for COM2001 Alexis 2.0 and 2.1 in InternetPBX sends username and voice mail passwords in the clear via a Java applet that sends the information to port 8888 of the server, which …
|
NVD-CWE-Other
|
CVE-2001-1254
|
2008-09-11 04:10 |
2001-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346265
|
7.5 |
HIGH
|
zope
|
zope
|
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
|
NVD-CWE-Other
|
CVE-2001-1278
|
2008-09-11 04:10 |
2001-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346266
|
7.5 |
HIGH
|
lbl
|
tcpdump
|
Buffer overflow in print-rx.c of tcpdump 3.x (probably 3.6x) allows remote attackers to cause a denial of service and possibly execute arbitrary code via AFS RPC packets with invalid lengths that tri…
|
NVD-CWE-Other
|
CVE-2001-1279
|
2008-09-11 04:10 |
2001-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346267
|
5.0 |
MEDIUM
|
ipswitch
|
imail
|
POP3 Server for Ipswitch IMail 7.04 and earlier generates different responses to valid and invalid user names, which allows remote attackers to determine users on the system.
|
NVD-CWE-Other
|
CVE-2001-1280
|
2008-09-11 04:10 |
2001-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346268
|
5.0 |
MEDIUM
|
ipswitch
|
imail
|
Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser parameter in the "Change User Information" we…
|
NVD-CWE-Other
|
CVE-2001-1281
|
2008-09-11 04:10 |
2001-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346269
|
5.0 |
MEDIUM
|
ipswitch
|
imail
|
Ipswitch IMail 7.04 and earlier records the physical path of attachments in an e-mail message header, which could allow remote attackers to obtain potentially sensitive configuration information.
|
NVD-CWE-Other
|
CVE-2001-1282
|
2008-09-11 04:10 |
2001-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346270
|
7.5 |
HIGH
|
ipswitch
|
imail
|
The webmail interface for Ipswitch IMail 7.04 and earlier allows remote authenticated users to cause a denial of service (crash) via a mailbox name that contains a large number of . (dot) or other ch…
|
NVD-CWE-Other
|
CVE-2001-1283
|
2008-09-11 04:10 |
2001-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346271
|
7.5 |
HIGH
|
ipswitch
|
imail
|
Ipswitch IMail 7.04 and earlier uses predictable session IDs for authentication, which allows remote attackers to hijack sessions of other users.
|
NVD-CWE-Other
|
CVE-2001-1284
|
2008-09-11 04:10 |
2001-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346272
|
5.0 |
MEDIUM
|
ipswitch
|
imail
|
Directory traversal vulnerability in readmail.cgi for Ipswitch IMail 7.04 and earlier allows remote attackers to access the mailboxes of other users via a .. (dot dot) in the mbx parameter.
|
NVD-CWE-Other
|
CVE-2001-1285
|
2008-09-11 04:10 |
2001-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346273
|
7.5 |
HIGH
|
ipswitch
|
imail
|
Ipswitch IMail 7.04 and earlier stores a user's session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. via an HTML email that causes the Referrer to be …
|
NVD-CWE-Other
|
CVE-2001-1286
|
2008-09-11 04:10 |
2001-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346274
|
7.5 |
HIGH
|
ipswitch
|
imail
|
Buffer overflow in Web Calendar in Ipswitch IMail 7.04 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
|
NVD-CWE-Other
|
CVE-2001-1287
|
2008-09-11 04:10 |
2001-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346275
|
5.0 |
MEDIUM
|
id_software
|
quake_3_arena
|
Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters.
|
NVD-CWE-Other
|
CVE-2001-1289
|
2008-09-11 04:10 |
2001-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346276
|
5.0 |
MEDIUM
|
3com
|
3cr29223
|
Buffer overflow in web server of 3com HomeConnect Cable Modem External with USB (#3CR29223) allows remote attackers to cause a denial of service (crash) via a long HTTP request.
|
NVD-CWE-Other
|
CVE-2001-1293
|
2008-09-11 04:10 |
2001-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346277
|
5.0 |
MEDIUM
|
avtronics
|
inetserv
|
Buffer overflow in A-V Tronics Inetserv 3.2.1 and earlier allows remote attackers to cause a denial of service (crash) in the Webmail interface via a long username and password.
|
NVD-CWE-Other
|
CVE-2001-1294
|
2008-09-11 04:10 |
2001-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346278
|
5.0 |
MEDIUM
|
marc_logemann
|
more.groupware
|
More.groupware PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
|
NVD-CWE-Other
|
CVE-2001-1296
|
2008-09-11 04:10 |
2001-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346279
|
7.5 |
HIGH
|
actionpoll
|
actionpoll
|
PHP remote file inclusion vulnerability in Actionpoll PHP script before 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter.
|
NVD-CWE-Other
|
CVE-2001-1297
|
2008-09-11 04:10 |
2001-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346280
|
5.0 |
MEDIUM
|
grant_horwood
|
webodex
|
Webodex PHP script 1.0 and earlier allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
|
NVD-CWE-Other
|
CVE-2001-1298
|
2008-09-11 04:10 |
2001-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346281
|
3.6 |
LOW
|
xinetd
|
xinetd
|
xinetd 2.1.8 and earlier runs with a default umask of 0, which could allow local users to read or modify files that are created by an application that runs under xinetd but does not set its own safe …
|
NVD-CWE-Other
|
CVE-2001-1322
|
2008-09-11 04:10 |
2001-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346282
|
4.6 |
MEDIUM
|
paul_jarc
|
idtools
|
cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID…
|
NVD-CWE-Other
|
CVE-2001-1324
|
2008-09-11 04:10 |
2001-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346283
|
1.2 |
LOW
|
debian progeny
|
debian_linux debian
|
mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.
|
NVD-CWE-Other
|
CVE-2001-1331
|
2008-09-11 04:10 |
2001-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346284
|
5.0 |
MEDIUM
|
aclogic
|
cesarftp
|
Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contains a ...%5c (modifie…
|
NVD-CWE-Other
|
CVE-2001-1335
|
2008-09-11 04:10 |
2001-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346285
|
7.5 |
HIGH
|
aclogic
|
cesarftp
|
CesarFTP 0.98b and earlier stores usernames and passwords in plaintext in the settings.ini file, which allows attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2001-1336
|
2008-09-11 04:10 |
2001-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346286
|
5.0 |
MEDIUM
|
beck_ipc_gmbh
|
ipc_at_chip_telnetd_server
|
Beck GmbH IPC@Chip TelnetD service supports only one connection and does not disconnect a user who does not complete the login process, which allows remote attackers to lock out the administrator acc…
|
NVD-CWE-Other
|
CVE-2001-1340
|
2008-09-11 04:10 |
2002-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346287
|
5.0 |
MEDIUM
|
beck_ipc_gmbh
|
ipc_at_chip_embedded-webserver
|
The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program.
|
NVD-CWE-Other
|
CVE-2001-1341
|
2008-09-11 04:10 |
2001-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346288
|
7.5 |
HIGH
|
leon_j_breedt
|
pam-pgsql
|
Leon J Breedt pam-pgsql before 0.5.2 allows remote attackers to execute arbitrary SQL code and bypass authentication or modify user account records by injecting SQL statements into user or password f…
|
NVD-CWE-Other
|
CVE-2001-1369
|
2008-09-11 04:10 |
2001-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346289
|
6.2 |
MEDIUM
|
redhat
|
linux
|
initscript in setserial 2.17-4 and earlier uses predictable temporary file names, which could allow local users to conduct unauthorized operations on files.
|
NVD-CWE-Other
|
CVE-2001-1383
|
2008-09-11 04:10 |
2001-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346290
|
5.0 |
MEDIUM
|
proftpd_project
|
proftpd
|
The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and …
|
NVD-CWE-Other
|
CVE-2001-1501
|
2008-09-11 04:10 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346291
|
7.5 |
HIGH
|
openbsd
|
openssh
|
OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.
|
NVD-CWE-Other
|
CVE-2001-1507
|
2008-09-11 04:10 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346292
|
6.4 |
MEDIUM
|
macromedia
|
jrun
|
Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Pages (JSP), a variant of CVE-2000-1050.
|
NVD-CWE-Other
|
CVE-2001-1512
|
2008-09-11 04:10 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346293
|
7.5 |
HIGH
|
macromedia
|
jrun
|
Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trai…
|
NVD-CWE-Other
|
CVE-2001-1513
|
2008-09-11 04:10 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346294
|
2.6 |
LOW
|
postnuke_software_foundation
|
postnuke
|
Cross-site scripting (XSS) vulnerability in user.php in PostNuke 0.64 allows remote attackers to inject arbitrary web script or HTML via the uname parameter.
|
NVD-CWE-Other
|
CVE-2001-1521
|
2008-09-11 04:10 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346295
|
4.3 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and f…
|
NVD-CWE-Other
|
CVE-2001-1524
|
2008-09-11 04:10 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346296
|
5.0 |
MEDIUM
|
microsoft
|
windows_me
|
ssdpsrv.exe in Windows ME allows remote attackers to cause a denial of service by sending multiple newlines in a Simple Service Discovery Protocol (SSDP) message. NOTE: multiple replies to the origi…
|
NVD-CWE-Other
|
CVE-2001-1552
|
2008-09-11 04:10 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346297
|
7.5 |
HIGH
|
ibm
|
websphere_application_server
|
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to …
|
NVD-CWE-Other
|
CVE-2001-0824
|
2008-09-11 04:09 |
2001-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346298
|
5.0 |
MEDIUM
|
grant_averett
|
ceberus_ftp_server
|
Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.
|
NVD-CWE-Other
|
CVE-2001-0827
|
2008-09-11 04:09 |
2001-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346299
|
5.1 |
MEDIUM
|
apache
|
tomcat
|
A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error mes…
|
NVD-CWE-Other
|
CVE-2001-0829
|
2008-09-11 04:09 |
2001-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346300
|
2.1 |
LOW
|
sane
|
sane
|
Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2001-0890
|
2008-09-11 04:09 |
2001-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|