Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 316 770

Количество 316 770

nvd логотип

CVE-2001-1464

почти 25 лет назад

Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1463

почти 24 года назад

The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1462

около 24 лет назад

WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1461

около 24 лет назад

Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to access restricted resources via URL-encoded (1) /.. or (2) \.. sequences.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1460

около 24 лет назад

SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1459

больше 24 лет назад

OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1458

около 24 лет назад

Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1457

почти 24 года назад

Buffer overflow in CrazyWWWBoard 2000p4 and 2000LEp5 allows remote attackers to execute arbitrary code via a long HTTP_USER_AGENT CGI environment variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1456

около 24 лет назад

Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1455

около 24 лет назад

Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1454

больше 24 лет назад

Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2001-1453

больше 24 лет назад

Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2001-1452

около 24 лет назад

By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1451

около 23 лет назад

Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2001-1450

больше 24 лет назад

Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./".

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2001-1449

почти 24 года назад

The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1448

почти 24 года назад

Magic eDeveloper Enterprise Edition 8.30-5 and earlier allows local users to overwrite arbitrary files and possibly execute code via a symlink attack on temporary files created by the (1) mkuserproc, (2) mgrnt, and (3) mgdatasrvr.sc scripts.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1447

около 24 лет назад

NetInfo Manager for Mac OS X 10.0 through 10.1 allows local users to gain root privileges by opening applications using the (1) "recent items" and (2) "services" menus, which causes the applications to run with root privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-1446

около 24 лет назад

Find-By-Content in Mac OS X 10.0 through 10.0.4 creates world-readable index files named .FBCIndex in every directory, which allows remote attackers to learn the contents of files in web accessible directories.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1445

больше 24 лет назад

Unknown vulnerability in the SMTP server in Lotus Domino 5.0 through 5.7 allows remote attackers to bypass mail relaying restrictions via crafted e-mail addresses in "RCPT TO" commands.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1464

Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.

CVSS2: 7.5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1463

The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1462

WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information.

CVSS2: 7.5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1461

Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to access restricted resources via URL-encoded (1) /.. or (2) \.. sequences.

CVSS2: 7.5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1460

SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter.

CVSS2: 7.5
4%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1459

OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.

CVSS2: 7.5
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1458

Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character.

CVSS2: 5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1457

Buffer overflow in CrazyWWWBoard 2000p4 and 2000LEp5 allows remote attackers to execute arbitrary code via a long HTTP_USER_AGENT CGI environment variable.

CVSS2: 7.5
6%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1456

Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message.

CVSS2: 7.5
9%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1455

Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters.

CVSS2: 7.5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1454

Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.

CVSS2: 7.5
12%
Средний
больше 24 лет назад
nvd логотип
CVE-2001-1453

Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.

CVSS2: 7.5
12%
Средний
больше 24 лет назад
nvd логотип
CVE-2001-1452

By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.

CVSS3: 7.5
4%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1451

Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.

CVSS2: 5
13%
Средний
около 23 лет назад
nvd логотип
CVE-2001-1450

Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./".

CVSS2: 2.6
9%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1449

The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.

CVSS2: 7.5
5%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1448

Magic eDeveloper Enterprise Edition 8.30-5 and earlier allows local users to overwrite arbitrary files and possibly execute code via a symlink attack on temporary files created by the (1) mkuserproc, (2) mgrnt, and (3) mgdatasrvr.sc scripts.

CVSS2: 4.6
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1447

NetInfo Manager for Mac OS X 10.0 through 10.1 allows local users to gain root privileges by opening applications using the (1) "recent items" and (2) "services" menus, which causes the applications to run with root privileges.

CVSS2: 7.2
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1446

Find-By-Content in Mac OS X 10.0 through 10.0.4 creates world-readable index files named .FBCIndex in every directory, which allows remote attackers to learn the contents of files in web accessible directories.

CVSS2: 7.5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1445

Unknown vulnerability in the SMTP server in Lotus Domino 5.0 through 5.7 allows remote attackers to bypass mail relaying restrictions via crafted e-mail addresses in "RCPT TO" commands.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад

Уязвимостей на страницу