Export limit exceeded: 29991 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (29991 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2001-0557 | 1 T. Hauck | 1 Jana Web Server | 2026-04-16 | N/A |
| T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e). | ||||
| CVE-2001-1367 | 1 Phpslice | 1 Phpslice | 2026-04-16 | N/A |
| The checkAccess function in PHPSlice 0.1.4, and all other versions between 0.1.1 and 0.1.6, does not properly verify the administrative access level, which could allow remote attackers to gain privileges. | ||||
| CVE-1999-0195 | 2 Linux, Sgi | 2 Linux Kernel, Irix | 2026-04-16 | N/A |
| Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1. | ||||
| CVE-2000-0488 | 1 Ithouse | 1 Ithouse Mail Server | 2026-04-16 | N/A |
| Buffer overflow in ITHouse mail server 1.04 allows remote attackers to execute arbitrary commands via a long RCPT TO mail command. | ||||
| CVE-2001-0558 | 1 T. Hauck | 1 Jana Web Server | 2026-04-16 | N/A |
| T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0). | ||||
| CVE-2001-1368 | 1 Iplanet | 1 Iplanet Web Server | 2026-04-16 | N/A |
| Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data. | ||||
| CVE-1999-0196 | 1 Webgais Development Team | 1 Webgais | 2026-04-16 | N/A |
| websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable). | ||||
| CVE-1999-0215 | 1 Sgi | 1 Irix | 2026-04-16 | N/A |
| Routed allows attackers to append data to files. | ||||
| CVE-2000-0489 | 3 Freebsd, Netbsd, Openbsd | 3 Freebsd, Netbsd, Openbsd | 2026-04-16 | N/A |
| FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers. | ||||
| CVE-2001-0559 | 1 Paul Vixie | 1 Vixie Cron | 2026-04-16 | N/A |
| crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error. | ||||
| CVE-1999-0268 | 1 Metainfo | 1 Metaweb | 2026-04-16 | N/A |
| MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. | ||||
| CVE-2000-0490 | 1 Netwin | 1 Dmail | 2026-04-16 | N/A |
| Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request. | ||||
| CVE-2001-0560 | 2 Paul Vixie, Redhat | 2 Vixie Cron, Linux | 2026-04-16 | N/A |
| Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters). | ||||
| CVE-1999-0286 | 2026-04-16 | N/A | ||
| In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages. | ||||
| CVE-2000-0491 | 3 Caldera, Gnome, Suse | 3 Openlinux, Gdm, Suse Linux | 2026-04-16 | N/A |
| Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request. | ||||
| CVE-2000-0492 | 1 Passwd | 1 Passwd | 2026-04-16 | N/A |
| PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords. | ||||
| CVE-2000-0493 | 1 Atrius Trivalie Sn | 1 Time Sync | 2026-04-16 | N/A |
| Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long string. | ||||
| CVE-2001-0561 | 1 Drummond Miles | 1 A1stats | 2026-04-16 | N/A |
| Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi. | ||||
| CVE-2001-1372 | 1 Oracle | 1 Application Server | 2026-04-16 | N/A |
| Oracle 9i Application Server 1.0.2 allows remote attackers to obtain the physical path of a file under the server root via a request for a non-existent .JSP file, which leaks the pathname in an error message. | ||||
| CVE-2000-0494 | 1 Symantec Veritas | 1 Volume Manager | 2026-04-16 | N/A |
| Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server script. | ||||