Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1339 1 Beck Ipc Gmbh 1 Ipc At Chip Embedded-webserver 2008-09-05 7.5 HIGH N/A
Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.
CVE-2001-1348 1 Twig Development Team 1 Twig 2008-09-05 7.5 HIGH N/A
TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter.
CVE-2001-1349 1 Sendmail 1 Sendmail 2008-09-05 3.7 LOW N/A
Sendmail before 8.11.4, and 8.12.0 before 8.12.0.Beta10, allows local users to cause a denial of service and possibly corrupt the heap and gain privileges via race conditions in signal handlers.
CVE-2001-1356 1 Netwin 1 Surgeftp 2008-09-05 10.0 HIGH N/A
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.
CVE-2001-1357 1 Phpheaven 1 Phpmychat 2008-09-05 7.5 HIGH N/A
Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.
CVE-2001-1358 1 Phpheaven 1 Phpmychat 2008-09-05 7.2 HIGH N/A
Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.
CVE-2001-1360 1 Mostang 1 Sane 2008-09-05 7.2 HIGH N/A
Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned.
CVE-2001-1361 1 Twig Development Team 1 Twig 2008-09-05 7.5 HIGH N/A
Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links.
CVE-2001-1362 1 Horsburgh 1 Npulse 2008-09-05 7.5 HIGH N/A
Vulnerability in the server for nPULSE before 0.53p4.
CVE-2001-1363 1 Phpwebsite Development Team 1 Phpwebsite 2008-09-05 10.0 HIGH N/A
Vulnerability in phpWebSite before 0.7.9 related to running multiple instances in the same domain, which may allow attackers to gain administrative privileges.
CVE-2001-1364 1 Project Purple 1 Autodns 2008-09-05 7.5 HIGH N/A
Vulnerability in autodns.pl for AutoDNS before 0.0.4 related to domain names that are not fully qualified.
CVE-2001-1365 1 Osi Codes Inc. 1 Intragnat 2008-09-05 7.5 HIGH N/A
Vulnerability in IntraGnat before 1.4.
CVE-2001-1366 1 Netscript Project 1 Netscript 2008-09-05 5.0 MEDIUM N/A
netscript before 1.6.3 parses dynamic variables, which could allow remote attackers to alter program behavior or obtain sensitive information.
CVE-2001-1375 2 Conectiva, Redhat 2 Linux, Linux 2008-09-05 4.6 MEDIUM N/A
tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before other directories, which could allow local users to execute arbitrary code via a Trojan horse library that is under a user-controlled directory.
CVE-2001-1382 1 Openbsd 1 Openssh 2008-09-05 5.0 MEDIUM N/A
The "echo simulation" traffic analysis countermeasure in OpenSSH before 2.9.9p2 sends an additional echo packet after the password and carriage return is entered, which could allow remote attackers to determine that the countermeasure is being used.
CVE-2001-1416 1 Aol 1 Instant Messenger 2008-09-05 5.1 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in the log messages in certain Alpha versions of AOL Instant Messenger (AIM) 4.4 allow remote attackers to execute arbitrary web script or HTML via an image in the (1) DATA, (2) STYLE, or (3) BINARY tags.
CVE-2001-1465 1 Surfcontrol 1 Superscout Web Filter 2008-09-05 4.6 MEDIUM N/A
SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements.
CVE-2001-1510 1 Macromedia 1 Jrun 2008-09-05 5.0 MEDIUM N/A
Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.
CVE-2001-1511 1 Macromedia 1 Jrun 2008-09-05 5.0 MEDIUM N/A
JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source filename ending in (1) "jsp%00" or (2) "js%2570".
CVE-2001-1514 1 Macromedia 1 Coldfusion 2008-09-05 10.0 HIGH N/A
ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.