Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2001-1005 | 1 Starfish | 1 Truesync Desktop | 2008-09-05 | 7.5 HIGH | N/A |
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registry key to decrypt the password and gain privileges. | |||||
CVE-2001-1006 | 1 Starfish | 1 Truesync Desktop | 2008-09-05 | 5.0 MEDIUM | N/A |
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to restrict access, which allows an attacker to read the files using a different application. | |||||
CVE-2001-1007 | 1 Starfish | 1 Truesync Desktop | 2008-09-05 | 5.0 MEDIUM | N/A |
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly guess the key via a brute force attack. | |||||
CVE-2001-1008 | 1 Sun | 2 Java Plug-in, Jre | 2008-09-05 | 7.5 HIGH | N/A |
Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate. | |||||
CVE-2001-1015 | 1 Snes9x.com | 1 Snes9x | 2008-09-05 | 7.2 HIGH | N/A |
Buffer overflow in Snes9x 1.37, when installed setuid root, allows local users to gain root privileges via a long command line argument. | |||||
CVE-2001-1025 | 1 Francisco Burzi | 1 Php-nuke | 2008-09-05 | 10.0 HIGH | N/A |
PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php. | |||||
CVE-2001-1028 | 1 Redhat | 1 Linux | 2008-09-05 | 7.2 HIGH | N/A |
Buffer overflow in ultimate_source function of man 1.5 and earlier allows local users to gain privileges. | |||||
CVE-2001-1039 | 1 Hp | 1 Jetadmin | 2008-09-05 | 7.5 HIGH | N/A |
The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer. | |||||
CVE-2001-1040 | 1 Hp | 1 Jetadmin | 2008-09-05 | 6.4 MEDIUM | N/A |
HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password. | |||||
CVE-2001-1048 | 1 Topher1kenobe | 1 Awol | 2008-09-05 | 7.5 HIGH | N/A |
AWOL PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | |||||
CVE-2001-1061 | 1 Ibm | 1 Aix | 2008-09-05 | 10.0 HIGH | N/A |
Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error. | |||||
CVE-2001-1081 | 2 Lucent, Simon Horms | 2 Radius, Radius | 2008-09-05 | 7.5 HIGH | N/A |
Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via format specifiers that are injected into log messages. | |||||
CVE-2001-1082 | 2 Lucent, Simon Horms | 2 Radius, Radius | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack. | |||||
CVE-2001-1110 | 1 Khamil Landross And Zack Jones | 1 Eftp | 2008-09-05 | 5.0 MEDIUM | N/A |
EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection. | |||||
CVE-2001-1131 | 1 Whitsoft Development | 1 Slimftpd | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in WhitSoft Development SlimFTPd 2.2 allows an attacker to read arbitrary files and directories via a ... (modified dot dot) in the CD command. | |||||
CVE-2001-1133 | 1 Bsdi | 1 Bsd Os | 2008-09-05 | 2.1 LOW | N/A |
Vulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kernel via a particular sequence of instructions. | |||||
CVE-2001-1139 | 1 Ascii Nt | 1 Winwrapper Professional | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in ASCII NT WinWrapper Professional allows remote attackers to read arbitrary files via a .. (dot dot) in the server request. | |||||
CVE-2001-1142 | 1 Argosoft | 1 Ftp Server | 2008-09-05 | 5.0 MEDIUM | N/A |
ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the password file to gain privileges. | |||||
CVE-2001-1143 | 1 Ibm | 1 Db2 Universal Database | 2008-09-05 | 5.0 MEDIUM | N/A |
IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789. | |||||
CVE-2001-1147 | 1 Andries Brouwer | 1 Util-linux | 2008-09-05 | 7.2 HIGH | N/A |
The PAM implementation in /bin/login of the util-linux package before 2.11 causes a password entry to be rewritten across multiple PAM calls, which could provide the credentials of one user to a different user, when used in certain PAM modules such as pam_limits. |