Unknown · CVSS Not scored
Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting to port 6070, sending some data, and closing the connection.
Published Jul 27, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in iPlanet Web Server Enterprise Edition 4.x.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the '-u' command line parameter.
Published Jul 27, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activities such as mail relaying.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters).
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0).
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
minicom 1.83.1 and earlier allows a local attacker to gain additional privileges via numerous format string attacks.
Published Jul 27, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.
Published Sep 1, 2004 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) scripts directories.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users' files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file.
Published Jul 27, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Spearhead NetGAP 200 and 300 before build 78 allow a remote attacker to bypass file blocking and content inspection via specially encoded URLs which include '%' characters.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in WebCalendar 0.9.26 allows remote command execution.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco Aironet 340 Series wireless bridge before 8.55 does not properly disable access to the web interface, which allows remote attackers to modify its configuration.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in the HTTP request.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Oracle listener in Oracle 8i on Solaris allows remote attackers to cause a denial of service via a malformed connection packet with a maximum transport data size that is set to 0.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.
Published Oct 12, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.
Published Feb 18, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.
Published Jul 27, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP command.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in FTPFS allows local users to gain root privileges via a long user name.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.
Published May 24, 2001 · Updated Aug 8, 2024