Vulnerabilities (CVE)

Total 304758 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0312 1 Ibm 1 Websphere Plugin 2008-09-05 5.0 MEDIUM N/A
IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.
CVE-2001-0306 1 Itafrica 1 Webactive 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
CVE-2001-0074 1 Technote Inc 1 Technote 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter.
CVE-2001-0354 1 Thenet 1 Checkbo 2008-09-05 5.0 MEDIUM N/A
TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on.
CVE-2001-0232 1 Ibrow 1 News Desk 2008-09-05 5.0 MEDIUM N/A
newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters.
CVE-2001-0212 1 His 1 Auktion 2008-09-05 7.5 HIGH N/A
Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.
CVE-2001-0163 1 Cisco 1 Aironet Ap340 2008-09-05 4.6 MEDIUM N/A
Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.
CVE-2001-0298 1 Sapio Design Ltd 1 Webreflex 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.
CVE-2001-0389 1 Ibm 2 Net.commerce, Websphere Application Server 2008-09-05 5.0 MEDIUM N/A
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.
CVE-2001-0160 2 Lucent, Orinoco 2 Wavelan, Orinoco Wavelan 2008-09-05 5.0 MEDIUM N/A
Lucent/ORiNOCO WaveLAN cards generate predictable Initialization Vector (IV) values for the Wireless Encryption Protocol (WEP) which allows remote attackers to quickly compile information that will let them decrypt messages.
CVE-2001-0114 1 Omnicron 1 Omnihttpd 2008-09-05 5.0 MEDIUM N/A
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.
CVE-2001-0327 1 Iplanet 1 Iplanet Web Server 2008-09-05 5.0 MEDIUM N/A
iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server.
CVE-2001-0208 1 Microfocus 1 Cobol 2008-09-05 4.6 MEDIUM N/A
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.
CVE-2001-0270 1 Marconi 2 Asx-1000, Forethought 2008-09-05 5.0 MEDIUM N/A
Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set.
CVE-2001-0192 1 Davide Libenzi 1 Xmail 2008-09-05 10.0 HIGH N/A
Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.
CVE-2001-0079 1 Hp 1 Support Tools Manager 2008-09-05 2.1 LOW N/A
Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.
CVE-2001-0133 1 Trend Micro 1 Interscan Viruswall 2008-09-05 10.0 HIGH N/A
The web administration interface for Interscan VirusWall 3.6.x and earlier does not use encryption, which could allow remote attackers to obtain the administrator password to sniff the administrator password via the setpasswd.cgi program or other HTTP GET requests that contain base64 encoded usernames and passwords.
CVE-2001-0186 1 Free Java Web Server 1 Free Java Web Server 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2001-0211 1 Silverplatter 1 Webspirs 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.
CVE-2001-0293 1 Datawizard 1 Ftpxq 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.