Total
28799 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2001-1048 | 1 Topher1kenobe | 1 Awol | 2008-09-05 | 7.5 HIGH | N/A |
AWOL PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | |||||
CVE-2001-1040 | 1 Hp | 1 Jetadmin | 2008-09-05 | 6.4 MEDIUM | N/A |
HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password. | |||||
CVE-2001-1039 | 1 Hp | 1 Jetadmin | 2008-09-05 | 7.5 HIGH | N/A |
The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer. | |||||
CVE-2001-1028 | 1 Redhat | 1 Linux | 2008-09-05 | 7.2 HIGH | N/A |
Buffer overflow in ultimate_source function of man 1.5 and earlier allows local users to gain privileges. | |||||
CVE-2001-1025 | 1 Francisco Burzi | 1 Php-nuke | 2008-09-05 | 10.0 HIGH | N/A |
PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php. | |||||
CVE-2001-1015 | 1 Snes9x.com | 1 Snes9x | 2008-09-05 | 7.2 HIGH | N/A |
Buffer overflow in Snes9x 1.37, when installed setuid root, allows local users to gain root privileges via a long command line argument. | |||||
CVE-2001-1008 | 1 Sun | 2 Java Plug-in, Jre | 2008-09-05 | 7.5 HIGH | N/A |
Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate. | |||||
CVE-2001-1007 | 1 Starfish | 1 Truesync Desktop | 2008-09-05 | 5.0 MEDIUM | N/A |
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly guess the key via a brute force attack. | |||||
CVE-2001-1006 | 1 Starfish | 1 Truesync Desktop | 2008-09-05 | 5.0 MEDIUM | N/A |
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to restrict access, which allows an attacker to read the files using a different application. | |||||
CVE-2001-1005 | 1 Starfish | 1 Truesync Desktop | 2008-09-05 | 7.5 HIGH | N/A |
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registry key to decrypt the password and gain privileges. | |||||
CVE-2001-1004 | 1 Gnutella | 1 Gnutella Client | 2008-09-05 | 5.0 MEDIUM | N/A |
Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name contains the script tags. | |||||
CVE-2001-0989 | 1 Richard Everitt | 1 Pileup | 2008-09-05 | 7.2 HIGH | N/A |
Buffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or (2) a long callsign. | |||||
CVE-2001-0978 | 1 Hp | 1 Hp-ux | 2008-09-05 | 7.5 HIGH | N/A |
login in HP-UX 10.26 does not record failed login attempts in /var/adm/btmp, which could allow attackers to conduct brute force password guessing attacks without being detected or observed using the lastb program. | |||||
CVE-2001-0976 | 1 Hp | 1 Process Resource Manager | 2008-09-05 | 7.2 HIGH | N/A |
Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables. | |||||
CVE-2001-0973 | 1 Fraunhofer Fit | 1 Bscw | 2008-09-05 | 6.4 MEDIUM | N/A |
BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space. | |||||
CVE-2001-0971 | 1 Aci | 1 4d Webserver | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in ACI 4d webserver allows remote attackers to read arbitrary files via a .. (dot dot) or drive letter (e.g., C:) in an HTTP request. | |||||
CVE-2001-0968 | 1 Knox Software | 1 Arkeia | 2008-09-05 | 10.0 HIGH | N/A |
Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges. | |||||
CVE-2001-0966 | 1 Nudester.org | 1 Nudester | 2008-09-05 | 10.0 HIGH | N/A |
Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the CD (CWD) command. | |||||
CVE-2001-0965 | 1 Glftpd | 1 Glftpd | 2008-09-05 | 5.0 MEDIUM | N/A |
glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters. | |||||
CVE-2001-0943 | 1 Oracle | 1 Database Server | 2008-09-05 | 7.2 HIGH | N/A |
dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse programs. |