78330 |
CVE-2001-0893 |
Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /. |
|
2 |
5 |
Medium |
2017-01-05 |
2016-10-17 |
View
|
13050 |
CVE-2010-1526 |
Multiple integer overflows in libgdiplus 2.6.7, as used in Mono, allow attackers to execute arbitrary code via (1) a crafted TIFF file, related to the gdip_load_tiff_image function in tiffcodec.c; (2) a crafted JPEG file, related to the gdip_load_jpeg_image_internal function in jpegcodec.c; or (3) a crafted BMP file, related to the gdip_read_bmp_image function in bmpcodec.c, leading to heap-based buffer overflows. |
|
2 |
6.8 |
Medium |
2017-01-18 |
2010-12-07 |
View
|
78586 |
CVE-2001-1151 |
Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.53 allows remote attackers to access sensitive information from the hotdownload directory without authentication, such as the ofcscan.ini configuration file, which contains a weakly encrypted password. |
|
2 |
5 |
Medium |
2017-01-05 |
2008-09-05 |
View
|
78842 |
CVE-2001-1408 |
Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the mailbox parameter. |
|
2 |
5 |
Medium |
2017-01-05 |
2008-09-05 |
View
|
13562 |
CVE-2010-2074 |
istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a " |