Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 316 770

Количество 316 770

nvd логотип

CVE-2001-1484

почти 24 года назад

Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1483

почти 24 года назад

One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1482

почти 24 года назад

SQL injection vulnerability in bb_memberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL queries via the $sortby variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1481

почти 24 года назад

Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2001-1480

почти 24 года назад

Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1479

почти 24 года назад

smcboot in Sun SMC (Sun Management Center) 2.0 in Solaris 8 allows local users to delete arbitrary files via a symlink attack on /tmp/smc$SMC_PORT.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1478

почти 24 года назад

Buffer overflow in xlock in UnixWare 7.1.0 and 7.1.1 and Open Unix 8.0.0 allows local users to execute arbitrary code.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-1477

почти 24 года назад

The Domain gateway in BEA Tuxedo 7.1 does not perform authorization checks for imported services and qspaces on remote domains, even when an ACL exists, which allows users to access services in a remote domain.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1476

почти 25 лет назад

SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1475

почти 25 лет назад

SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is generated.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1474

почти 25 лет назад

SSH before 2.0 disables host key checking when connecting to the localhost, which allows remote attackers to silently redirect connections to the localhost by poisoning the client's DNS cache.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1473

почти 25 лет назад

The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1472

больше 24 лет назад

SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1471

больше 24 лет назад

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2001-1470

почти 25 лет назад

The IDEA cipher as implemented by SSH1 does not protect the final block of a message against modification, which allows remote attackers to modify the block without detection by changing its cyclic redundancy check (CRC) to match the modifications to the message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1469

почти 25 лет назад

The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message's cyclic redundancy check (CRC) with the CRC of a mask consisting of all the bits of the original message that were modified.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1468

больше 24 лет назад

PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1467

больше 24 лет назад

mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1466

почти 24 года назад

Buffer overflow in VanDyke SecureCRT before 3.4.2, when using the SSH-1 protocol, allows remote attackers to execute arbitrary code via a long (1) username or (2) password.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1465

больше 23 лет назад

SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements.

CVSS2: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1484

Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication.

CVSS2: 7.5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1483

One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.

CVSS2: 5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1482

SQL injection vulnerability in bb_memberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL queries via the $sortby variable.

CVSS2: 7.5
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1481

Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.

CVSS3: 9.8
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1480

Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1479

smcboot in Sun SMC (Sun Management Center) 2.0 in Solaris 8 allows local users to delete arbitrary files via a symlink attack on /tmp/smc$SMC_PORT.

CVSS2: 2.1
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1478

Buffer overflow in xlock in UnixWare 7.1.0 and 7.1.1 and Open Unix 8.0.0 allows local users to execute arbitrary code.

CVSS2: 7.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1477

The Domain gateway in BEA Tuxedo 7.1 does not perform authorization checks for imported services and qspaces on remote domains, even when an ACL exists, which allows users to access services in a remote domain.

CVSS2: 4.6
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1476

SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.

CVSS2: 7.5
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1475

SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is generated.

CVSS2: 7.5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1474

SSH before 2.0 disables host key checking when connecting to the localhost, which allows remote attackers to silently redirect connections to the localhost by poisoning the client's DNS cache.

CVSS2: 5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1473

The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target.

CVSS2: 7.5
5%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1472

SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.

CVSS2: 4.6
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1471

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

CVSS3: 8.8
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1470

The IDEA cipher as implemented by SSH1 does not protect the final block of a message against modification, which allows remote attackers to modify the block without detection by changing its cyclic redundancy check (CRC) to match the modifications to the message.

CVSS2: 5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1469

The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message's cyclic redundancy check (CRC) with the CRC of a mask consisting of all the bits of the original message that were modified.

CVSS2: 5
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1468

PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1467

mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1466

Buffer overflow in VanDyke SecureCRT before 3.4.2, when using the SSH-1 protocol, allows remote attackers to execute arbitrary code via a long (1) username or (2) password.

CVSS2: 7.5
5%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1465

SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements.

CVSS2: 4.6
0%
Низкий
больше 23 лет назад

Уязвимостей на страницу