Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2001-01-09 CVE-2000-0897 Unspecified vulnerability in MAX Feoktistov Small Http Server 2.01
Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is completed.
network
low complexity
max-feoktistov
5.0
2001-01-08 CVE-2001-1037 Unspecified vulnerability in Cisco SN 5420 Storage Router Firmware 1.1(2)/1.1(3)
Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and execute certain restricted commands without being logged.
local
low complexity
cisco
4.6
2001-01-01 CVE-2001-0163 Unspecified vulnerability in Cisco Aironet Ap340
Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.
local
low complexity
cisco
4.6
2001-01-01 CVE-2001-0161 Unspecified vulnerability in Cisco Aironet 340Series
Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption, which makes it easier for remote attackers to mount brute force attacks.
network
low complexity
cisco
5.0
2001-01-01 CVE-2001-0160 Lucent/ORiNOCO WaveLAN cards generate predictable Initialization Vector (IV) values for the Wireless Encryption Protocol (WEP) which allows remote attackers to quickly compile information that will let them decrypt messages.
network
low complexity
lucent orinoco
5.0
2000-12-31 CVE-2000-1243 Unspecified vulnerability in Dansie Shopping Cart 3.04
Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product developers.
network
low complexity
dansie
5.0
2000-12-31 CVE-2000-1240 Unspecified vulnerability in Anyportal PHP Anyportal PHP
Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive information via unknown attack vectors, which reveal the absolute path.
network
low complexity
anyportal-php
5.0
2000-12-31 CVE-2000-1237 Unspecified vulnerability in Floosietek Ftgate
The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing.
network
low complexity
floosietek
5.0
2000-12-31 CVE-2000-1235 Unspecified vulnerability in Oracle Application Server
The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.
network
low complexity
oracle
5.0
2000-12-31 CVE-2000-1234 Unspecified vulnerability in Phorum 3.0.7
violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters.
network
low complexity
phorum
5.0