Skip to main content

Severity archive

High severity CVEs

High

124,916 high severity CVEs — 43,425 Critical, 124,916 High, 163,415 Medium, 17,960 Low, 2,012 Unrated across the current result set.

CVE-2001-1475

Published Jan 18, 2001

SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is generated.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1476

Published Jan 18, 2001

SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user se…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1044

Published Jan 11, 2001

Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1464

Published Jan 10, 2001

Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1093

Published Jan 9, 2001

Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1094

Published Jan 9, 2001

Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" command with a long "src" argument.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1100

Published Jan 9, 2001

The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive info…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1103

Published Jan 9, 2001

rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse scri…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1113

Published Jan 9, 2001

Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the ".ASX Buffer…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-1115

Published Jan 9, 2001

Buffer overflow in remote web administration component (webprox.dll) of 602Pro LAN SUITE before 2000.0.1.33 allows remote attackers to cause a denial of service and possibly execu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1116

Published Jan 9, 2001

Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long command.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1118

Published Jan 9, 2001

24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1120

Published Jan 9, 2001

Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1121

Published Jan 9, 2001

Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1122

Published Jan 9, 2001

Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.

CVSS 7.2 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-1123

Published Jan 9, 2001

Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1124

Published Jan 9, 2001

Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1125

Published Jan 9, 2001

restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying th…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1130

Published Jan 9, 2001

McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1131

Published Jan 9, 2001

Bill Kendrick web site guestbook (GBook) allows remote attackers to execute arbitrary commands via shell metacharacters in the _MAILTO form variable.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1138

Published Jan 9, 2001

Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker to modify the email in transit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1139

Published Jan 9, 2001

The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Acco…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 124,301-124,325 of 124,916 CVEsPage 4973 of 4997