Total
289036 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2002-0350 | 1 Hp | 1 Procurve Switch 4000m | 2025-04-03 | N/A |
HP Procurve Switch 4000M running firmware C.08.22 and C.09.09 allows remote attackers to cause a denial of service via a port scan of the management IP address, which disables the telnet service. | ||||
CVE-2000-0391 | 3 Cygnus, Mit, Redhat | 5 Cygnus Network Security, Kerbnet, Kerberos and 2 more | 2025-04-03 | N/A |
Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges. | ||||
CVE-2001-0609 | 1 Infodrom | 1 Cfingerd | 2025-04-03 | 9.8 Critical |
Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function. | ||||
CVE-2000-0392 | 3 Cygnus, Mit, Redhat | 5 Cygnus Network Security, Kerbnet, Kerberos and 2 more | 2025-04-03 | N/A |
Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges. | ||||
CVE-2001-0611 | 1 Rimarts Inc. | 1 Becky Internet Mail | 2025-04-03 | N/A |
Becky! 2.00.05 and earlier can allow a remote attacker to gain additional privileges via a buffer overflow attack on long messages without newline characters. | ||||
CVE-2000-0393 | 1 Kde | 1 Kde | 2025-04-03 | N/A |
The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute. | ||||
CVE-2000-0395 | 1 Computalynx | 1 Cproxy Server | 2025-04-03 | N/A |
Buffer overflow in CProxy 3.3 allows remote users to cause a denial of service via a long HTTP request. | ||||
CVE-2001-0612 | 1 Mcafee | 1 Remote Desktop 32 | 2025-04-03 | N/A |
McAfee Remote Desktop 3.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of packets to port 5045. | ||||
CVE-2001-1335 | 1 Aclogic | 1 Cesarftp | 2025-04-03 | N/A |
Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contains a ...%5c (modified dot dot). | ||||
CVE-2000-0396 | 1 Pacific Software | 1 Carello | 2025-04-03 | N/A |
The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files. | ||||
CVE-2001-0616 | 1 Faust Informatics | 1 Freestyle Chat | 2025-04-03 | N/A |
Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (e.g., GET /aux HTTP/1.0). | ||||
CVE-2001-1341 | 1 Beck Ipc Gmbh | 1 Ipc At Chip Embedded-webserver | 2025-04-03 | N/A |
The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program. | ||||
CVE-2000-0400 | 1 Microsoft | 1 Internet Explorer | 2025-04-03 | N/A |
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post. | ||||
CVE-2001-0617 | 1 Alliedtelesyn | 1 At-ar220e | 2025-04-03 | N/A |
Allied Telesyn AT-AR220e cable/DSL router firmware 1.08a RC14 with the portmapper and the 'Virtual Server' enabled can allow a remote attacker to gain access to mapped services even though the single portmappings may be disabled. | ||||
CVE-2001-1342 | 1 Apache | 1 Http Server | 2025-04-03 | N/A |
Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer. | ||||
CVE-2002-0075 | 1 Microsoft | 2 Internet Information Server, Internet Information Services | 2025-04-03 | N/A |
Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message. | ||||
CVE-2000-0402 | 1 Microsoft | 1 Sql Server | 2025-04-03 | N/A |
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability. | ||||
CVE-2001-0618 | 1 Lucent | 1 Orinoco Rg-1000 | 2025-04-03 | N/A |
Orinoco RG-1000 wireless Residential Gateway uses the last 5 digits of the 'Network Name' or SSID as the default Wired Equivalent Privacy (WEP) encryption key. Since the SSID occurs in the clear during communications, a remote attacker could determine the WEP key and decrypt RG-1000 traffic. | ||||
CVE-2001-1343 | 1 Cgicentral | 2 Webstore 400, Webstore 400cs | 2025-04-03 | N/A |
ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter. | ||||
CVE-2000-0403 | 1 Microsoft | 1 Windows Nt | 2025-04-03 | N/A |
The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the "HostAnnouncement Flooding" or "HostAnnouncement Frame" vulnerability. |