Total
27865 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2001-1164 | 1 Caldera | 1 Unixware | 2008-09-05 | 7.2 HIGH | N/A |
Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt. | |||||
CVE-2001-1165 | 1 Intego | 2 Diskguard, Fileguard | 2008-09-05 | 4.6 MEDIUM | N/A |
Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by decrypting the information, e.g., with the Disengage tool. | |||||
CVE-2001-1184 | 1 Denicomp | 1 Winsock Rshd Nt | 2008-09-05 | 5.0 MEDIUM | N/A |
wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a negative number, which causes a connection attempt to that port and all ports below 1024, and (2) in 2.21.00, a port number of 1024. | |||||
CVE-2001-1189 | 1 Ibm | 1 Websphere Application Server | 2008-09-05 | 4.6 MEDIUM | N/A |
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script. | |||||
CVE-2001-1190 | 1 Mandrakesoft | 1 Mandrake Linux | 2008-09-05 | 4.6 MEDIUM | N/A |
The default PAM files included with passwd in Mandrake Linux 8.1 do not support MD5 passwords, which could result in a lower level of password security than intended. | |||||
CVE-2001-1185 | 1 Freebsd | 1 Freebsd | 2008-09-05 | 6.2 MEDIUM | N/A |
Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges. | |||||
CVE-2001-1191 | 1 Ibm | 1 Tivoli Secureway Policy Director | 2008-09-05 | 5.0 MEDIUM | N/A |
WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e. | |||||
CVE-2001-1200 | 1 Microsoft | 1 Windows Xp | 2008-09-05 | 7.2 HIGH | N/A |
Microsoft Windows XP allows local users to bypass a locked screen and run certain programs that are associated with Hot Keys. | |||||
CVE-2001-1199 | 1 Steve Kneizys | 1 Agora.cgi | 2008-09-05 | 7.5 HIGH | N/A |
Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter. | |||||
CVE-2001-1207 | 1 Daydream | 1 Daydream Bbs | 2008-09-05 | 7.5 HIGH | N/A |
Buffer overflows in DayDream BBS 2.9 through 2.13 allow remote attackers to possibly execute arbitrary code via the control codes (1) ~#MC, (2) ~#TF, or (3) ~#RA. | |||||
CVE-2001-1211 | 1 Ipswitch | 1 Imail | 2008-09-05 | 7.5 HIGH | N/A |
Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain. | |||||
CVE-2001-1217 | 1 Oracle | 1 Application Server | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences. | |||||
CVE-2001-1222 | 1 Plesk | 1 Plesk Server Administrator | 2008-09-05 | 5.0 MEDIUM | N/A |
Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain. | |||||
CVE-2001-1220 | 1 D-link | 1 Dwl-1000ap | 2008-09-05 | 10.0 HIGH | N/A |
D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point stores the administrative password in plaintext in the default Management Information Base (MIB), which allows remote attackers to gain administrative privileges. | |||||
CVE-2001-1221 | 1 D-link | 1 Dwl-1000ap | 2008-09-05 | 5.0 MEDIUM | N/A |
D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of 'public' which allows remote attackers to gain sensitive information. | |||||
CVE-2001-1223 | 1 Elsa | 1 Lancom 1100 Office | 2008-09-05 | 10.0 HIGH | N/A |
The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server. | |||||
CVE-2001-0840 | 1 Compaq | 1 Insight Manager Xe | 2008-09-05 | 10.0 HIGH | N/A |
Buffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI. | |||||
CVE-2001-1169 | 1 Bell Communications Research | 1 S Key | 2008-09-05 | 7.5 HIGH | N/A |
keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo. | |||||
CVE-2001-1171 | 1 Checkpoint | 1 Firewall-1 | 2008-09-05 | 7.2 HIGH | N/A |
Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy. | |||||
CVE-2001-1149 | 1 Panda | 1 Panda Antivirus Platinum | 2008-09-05 | 5.0 MEDIUM | N/A |
Panda Antivirus Platinum before 6.23.00 allows a remore attacker to cause a denial of service (crash) when a user selects an action for a malformed UPX packed executable file. |