Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 306 905

Количество 306 905

nvd логотип

CVE-2001-1358

больше 24 лет назад

Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-1357

больше 24 лет назад

Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1356

около 24 лет назад

NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-1355

около 24 лет назад

Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitrary code via long arguments to (1) the -del command or (2) the -lookup command.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-1354

около 24 лет назад

NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1353

почти 24 года назад

ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2001-1352

больше 23 лет назад

Cross-site scripting vulnerability in Namazu 2.0.9 and earlier allows remote attackers to execute arbitrary Javascript as other web users via an error message that is returned when an invalid index file is specified in the idxname parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1351

больше 23 лет назад

Cross-site scripting vulnerability in Namazu 2.0.8 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the index file name that is displayed when displaying hit numbers.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1350

почти 24 года назад

Cross-site scripting vulnerability in namazu.cgi for Namazu 2.0.7 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the lang parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1349

около 24 лет назад

Sendmail before 8.11.4, and 8.12.0 before 8.12.0.Beta10, allows local users to cause a denial of service and possibly corrupt the heap and gain privileges via race conditions in signal handlers.

CVSS2: 3.7
EPSS: Низкий
nvd логотип

CVE-2001-1348

около 24 лет назад

TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1347

больше 24 лет назад

Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due to an exception, and allow hijacking of resources such as named pipes.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1346

больше 24 лет назад

Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.

CVSS2: 1.2
EPSS: Низкий
nvd логотип

CVE-2001-1345

около 24 лет назад

bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1344

около 24 лет назад

WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1343

около 24 лет назад

ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1342

больше 24 лет назад

Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2001-1341

больше 24 лет назад

The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1340

больше 23 лет назад

Beck GmbH IPC@Chip TelnetD service supports only one connection and does not disconnect a user who does not complete the login process, which allows remote attackers to lock out the administrator account by connecting to the service.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1339

больше 24 лет назад

Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1358

Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.

CVSS2: 7.2
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1357

Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.

CVSS2: 7.5
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1356

NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.

CVSS2: 10
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1355

Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitrary code via long arguments to (1) the -del command or (2) the -lookup command.

CVSS2: 10
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1354

NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.

CVSS2: 4.6
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1353

ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.

CVSS2: 2.6
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1352

Cross-site scripting vulnerability in Namazu 2.0.9 and earlier allows remote attackers to execute arbitrary Javascript as other web users via an error message that is returned when an invalid index file is specified in the idxname parameter.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2001-1351

Cross-site scripting vulnerability in Namazu 2.0.8 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the index file name that is displayed when displaying hit numbers.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2001-1350

Cross-site scripting vulnerability in namazu.cgi for Namazu 2.0.7 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the lang parameter.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1349

Sendmail before 8.11.4, and 8.12.0 before 8.12.0.Beta10, allows local users to cause a denial of service and possibly corrupt the heap and gain privileges via race conditions in signal handlers.

CVSS2: 3.7
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1348

TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter.

CVSS2: 7.5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1347

Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due to an exception, and allow hijacking of resources such as named pipes.

CVSS2: 4.6
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1346

Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.

CVSS2: 1.2
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1345

bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program.

CVSS2: 4.6
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1344

WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).

CVSS2: 7.5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1343

ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.

CVSS2: 7.5
9%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1342

Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.

CVSS2: 5
11%
Средний
больше 24 лет назад
nvd логотип
CVE-2001-1341

The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program.

CVSS2: 5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1340

Beck GmbH IPC@Chip TelnetD service supports only one connection and does not disconnect a user who does not complete the login process, which allows remote attackers to lock out the administrator account by connecting to the service.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2001-1339

Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.

CVSS3: 9.8
24%
Средний
больше 24 лет назад

Уязвимостей на страницу