National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

There are 133,780 matching records.
Displaying matches 130961 through 130980.
Vuln ID Summary CVSS Severity
CVE-2001-0045

The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-2001-0046

The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 4.6 MEDIUM
CVE-2001-0047

The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-2001-0049

WatchGuard SOHO FireWall 2.2.1 and earlier allows remote attackers to cause a denial of service via a large number of GET requests.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-2001-0050

Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address that resolves to a long DNS hostname or domain name.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-2001-0051

IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-2001-0052

IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 2.1 LOW
CVE-2001-0054

Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-2001-0055

CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-2001-0056

The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-2001-0057

Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-2001-0058

The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-2001-0066

Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 7.2 HIGH
CVE-2001-0088

common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-2001-0089

Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 2.6 LOW
CVE-2001-0090

The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the "Browser Print Template" vulnerability.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 5.1 MEDIUM
CVE-2001-0091

The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 2.6 LOW
CVE-2001-0092

A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 2.6 LOW
CVE-2001-1439

Buffer overflow in the text editor functionality in HP-UX 10.01 through 11.04 on HP9000 Series 700 and Series 800 allows local users to cause a denial of service ("system availability") via text editors such as (1) e, (2) ex, (3) vi, (4) edit, (5) view, and (6) vedit.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 2.1 LOW
CVE-2000-0889

Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun.

Published: February 12, 2001; 12:00:00 AM -05:00
    V2: 5.1 MEDIUM