Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 307 024

Количество 307 024

nvd логотип

CVE-2001-1177

около 24 лет назад

ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-2001-1176

около 24 лет назад

Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via format strings in the control connection.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1175

больше 23 лет назад

vipw in the util-linux package before 2.10 causes /etc/shadow to be world-readable in some cases, which would make it easier for local users to perform brute force password guessing.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-1174

больше 23 лет назад

Buffer overflow in Elm 2.5.5 and earlier allows remote attackers to execute arbitrary code via a long Message-ID header.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1173

около 24 лет назад

Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-1172

около 24 лет назад

OmniSecure HTTProtect 1.1.1 allows a superuser without omnish privileges to modify a protected file by creating a symbolic link to that file.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1171

больше 23 лет назад

Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-1170

почти 24 года назад

AmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote attackers to steal account and PIN numbers.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1169

почти 24 года назад

keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1168

почти 24 года назад

Directory traversal vulnerability in index.php in PhpMyExplorer before 1.2.1 allows remote attackers to read arbitrary files via a ..%2F (modified dot dot) in the chemin parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1167

около 24 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2001-0976. Reason: This candidate is a duplicate of CVE-2001-0976. Notes: CVE-2001-0976 should be used instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2001-1166

около 24 лет назад

linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1165

больше 23 лет назад

Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by decrypting the information, e.g., with the Disengage tool.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1164

около 24 лет назад

Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-1163

около 24 лет назад

Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-1162

около 24 лет назад

Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2001-1161

около 24 лет назад

Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1160

около 24 лет назад

udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the category_file field.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1159

около 24 лет назад

load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary code by using options_order.php to upload a message that could be interpreted as PHP.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1158

около 24 лет назад

Check Point VPN-1/FireWall-1 4.1 base.def contains a default macro, accept_fw1_rdp, which can allow remote attackers to bypass intended restrictions with forged RDP (internal protocol) headers to UDP port 259 of arbitrary hosts.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1177

ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 6.2
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1176

Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via format strings in the control connection.

CVSS2: 7.5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1175

vipw in the util-linux package before 2.10 causes /etc/shadow to be world-readable in some cases, which would make it easier for local users to perform brute force password guessing.

CVSS2: 7.2
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2001-1174

Buffer overflow in Elm 2.5.5 and earlier allows remote attackers to execute arbitrary code via a long Message-ID header.

CVSS2: 7.5
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2001-1173

Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases.

CVSS2: 7.2
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1172

OmniSecure HTTProtect 1.1.1 allows a superuser without omnish privileges to modify a protected file by creating a symbolic link to that file.

CVSS2: 4.6
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1171

Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy.

CVSS2: 7.2
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2001-1170

AmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote attackers to steal account and PIN numbers.

CVSS2: 5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1169

keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo.

CVSS2: 7.5
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1168

Directory traversal vulnerability in index.php in PhpMyExplorer before 1.2.1 allows remote attackers to read arbitrary files via a ..%2F (modified dot dot) in the chemin parameter.

CVSS2: 5
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1167

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2001-0976. Reason: This candidate is a duplicate of CVE-2001-0976. Notes: CVE-2001-0976 should be used instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

около 24 лет назад
nvd логотип
CVE-2001-1166

linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.

CVSS2: 5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1165

Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by decrypting the information, e.g., with the Disengage tool.

CVSS2: 4.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2001-1164

Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.

CVSS2: 7.2
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1163

Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.

CVSS2: 10
4%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1162

Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.

CVSS2: 10
30%
Средний
около 24 лет назад
nvd логотип
CVE-2001-1161

Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.

CVSS2: 7.5
4%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1160

udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the category_file field.

CVSS2: 7.5
9%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1159

load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary code by using options_order.php to upload a message that could be interpreted as PHP.

CVSS2: 7.5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1158

Check Point VPN-1/FireWall-1 4.1 base.def contains a default macro, accept_fw1_rdp, which can allow remote attackers to bypass intended restrictions with forged RDP (internal protocol) headers to UDP port 259 of arbitrary hosts.

CVSS2: 7.5
5%
Низкий
около 24 лет назад

Уязвимостей на страницу