Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 316 770

Количество 316 770

nvd логотип

CVE-2001-1507

почти 24 года назад

OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1506

почти 24 года назад

Unknown vulnerability in the file system protection subsystem in HP Secure OS Software for Linux 1.0 allows additional user privileges on some files beyond what is specified in the file system protection rules, which allows local users to conduct unauthorized operations on restricted files.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1505

почти 24 года назад

tinc 1.0pre3 and 1.0pre4 allows remote attackers to inject data into user sessions by sniffing and replaying packets.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1504

почти 24 года назад

Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user processes the e-mail message.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1503

почти 24 года назад

The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1502

почти 24 года назад

webcart.cgi in Mountain Network Systems WebCart 8.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the NEXTPAGE parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1501

почти 24 года назад

The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/" sequences in the argument.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1500

почти 24 года назад

ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1499

почти 24 года назад

Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1498

почти 24 года назад

Buffer overflow in mod_bf 0.2 allows local users to execute arbitrary commands via a long script.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-1497

почти 24 года назад

Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1496

почти 24 года назад

Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2001-1495

почти 24 года назад

network_query.php in Network Query Tool 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the target parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1494

почти 24 года назад

script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2001-1492

почти 24 года назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2001-1460. Reason: This candidate is a refinement duplicate of CVE-2001-1460. Notes: All CVE users should reference CVE-2001-1460 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2001-1491

почти 24 года назад

Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1490

почти 24 года назад

Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1489

почти 24 года назад

Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2001-1488

почти 24 года назад

Open Projects Network Internet Relay Chat (IRC) daemon u2.10.05.18 does not perform a double-reverse DNS lookup, which allows remote attackers to spoof any valid hostname on the Internet. NOTE: a followup post suggests that this is not an issue in the daemon.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1487

почти 24 года назад

popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option.

CVSS2: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1507

OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1506

Unknown vulnerability in the file system protection subsystem in HP Secure OS Software for Linux 1.0 allows additional user privileges on some files beyond what is specified in the file system protection rules, which allows local users to conduct unauthorized operations on restricted files.

CVSS2: 4.6
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1505

tinc 1.0pre3 and 1.0pre4 allows remote attackers to inject data into user sessions by sniffing and replaying packets.

CVSS2: 5
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1504

Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user processes the e-mail message.

CVSS2: 7.5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1503

The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.

CVSS2: 2.1
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1502

webcart.cgi in Mountain Network Systems WebCart 8.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the NEXTPAGE parameter.

CVSS2: 7.5
9%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1501

The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/" sequences in the argument.

CVSS2: 5
8%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1500

ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1499

Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks.

CVSS2: 5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1498

Buffer overflow in mod_bf 0.2 allows local users to execute arbitrary commands via a long script.

CVSS2: 7.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1497

Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.

CVSS2: 2.1
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1496

Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS3: 9.8
18%
Средний
почти 24 года назад
nvd логотип
CVE-2001-1495

network_query.php in Network Query Tool 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the target parameter.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1494

script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.

CVSS3: 5.5
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1492

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2001-1460. Reason: This candidate is a refinement duplicate of CVE-2001-1460. Notes: All CVE users should reference CVE-2001-1460 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

почти 24 года назад
nvd логотип
CVE-2001-1491

Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS2: 5
5%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1490

Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS2: 5
5%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1489

Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS2: 5
13%
Средний
почти 24 года назад
nvd логотип
CVE-2001-1488

Open Projects Network Internet Relay Chat (IRC) daemon u2.10.05.18 does not perform a double-reverse DNS lookup, which allows remote attackers to spoof any valid hostname on the Internet. NOTE: a followup post suggests that this is not an issue in the daemon.

CVSS2: 5
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1487

popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option.

CVSS2: 4.6
0%
Низкий
почти 24 года назад

Уязвимостей на страницу