Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,951 CVEs tagged with CWE-201,639 Critical, 5,069 High, 5,717 Medium, 522 Low, 4 Unrated.

CVE-2002-2406

Published Dec 31, 2002

Buffer overflow in HTTP server in LiteServe 2.0, 2.0.1 and 2.0.2 allows remote attackers to cause a denial of service (hang) via a large number of percent characters (%) in an HTT…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2421

Published Dec 31, 2002

acWEB 1.14 allows remote attackers to cause a denial of service (crash) via an HTTP request for a MS-DOS device name such as COM2.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2423

Published Dec 31, 2002

Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being logged via a long IDENT respon…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1175

Published Oct 11, 2002

The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DNS server, which allows remote…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0146

Published Jun 25, 2002

fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to overwrite memory via a message count th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1584

Published Dec 31, 2001

CardBoard 2.4 greeting card CGI by Michael Barretto allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient field.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0748

Published Oct 18, 2001

Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several / (slash) characters to the URI.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0566

Published Aug 14, 2001

Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disabled.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0400

Published May 13, 2000

The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0380

Published Apr 26, 2000

The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0995

Published Dec 16, 1999

Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "M…

CVSS 7.8 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-1547

Published Nov 25, 1999

Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0999

Published Nov 19, 1999

Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.

CVSS 4.3 · Medium
Buzz score
8.4
Public PoC observedOTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 12,926-12,950 of 12,951 CVEsPage 518 of 519