Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 316 542

Количество 316 542

nvd логотип

CVE-2001-1115

около 24 лет назад

generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1114

около 24 лет назад

book.cgi in NetCode NC Book 0.2b allows remote attackers to execute arbitrary commands via shell metacharacters in the "current" parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1113

около 24 лет назад

Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-1112

около 24 лет назад

Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1111

около 24 лет назад

EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1110

около 24 лет назад

EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1109

около 24 лет назад

Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1108

больше 24 лет назад

Directory traversal vulnerability in SnapStream PVS 1.2a allows remote attackers to read arbitrary files via a .. (dot dot) attack in the requested URL.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1107

больше 24 лет назад

SnapStream PVS 1.2a stores its passwords in plaintext in the file SSD.ini, which could allow a remote attacker to gain privileges on the server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1106

больше 24 лет назад

The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1105

около 24 лет назад

RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1104

больше 24 лет назад

SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1103

больше 24 лет назад

FTP Voyager ActiveX control before 8.0, when it is marked as safe for scripting (the default) or if allowed by the IObjectSafety interface, allows remote attackers to execute arbitrary commands.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1102

около 24 лет назад

Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-2001-1101

около 24 лет назад

The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2001-1100

около 24 лет назад

sendmessage.cgi in W3Mail 1.0.2, and possibly other CGI programs, allows remote attackers to execute arbitrary commands via shell metacharacters in any field of the 'Compose Message' page.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1099

около 24 лет назад

The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1098

около 24 лет назад

Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1097

больше 24 лет назад

Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2001-1096

около 24 лет назад

Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code.

CVSS2: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1115

generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.

CVSS2: 5
3%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1114

book.cgi in NetCode NC Book 0.2b allows remote attackers to execute arbitrary commands via shell metacharacters in the "current" parameter.

CVSS2: 7.5
3%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1113

Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command.

CVSS2: 10
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1112

Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters.

CVSS2: 7.5
5%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1111

EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file.

CVSS2: 4.6
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1110

EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.

CVSS2: 5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1109

Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.

CVSS2: 7.5
6%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1108

Directory traversal vulnerability in SnapStream PVS 1.2a allows remote attackers to read arbitrary files via a .. (dot dot) attack in the requested URL.

CVSS2: 7.5
4%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1107

SnapStream PVS 1.2a stores its passwords in plaintext in the file SSD.ini, which could allow a remote attacker to gain privileges on the server.

CVSS2: 5
4%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1106

The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1105

RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure.

CVSS2: 7.5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1104

SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions.

CVSS2: 7.5
4%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1103

FTP Voyager ActiveX control before 8.0, when it is marked as safe for scripting (the default) or if allowed by the IObjectSafety interface, allows remote attackers to execute arbitrary commands.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1102

Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable.

CVSS2: 6.2
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1101

The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack.

CVSS2: 6.4
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1100

sendmessage.cgi in W3Mail 1.0.2, and possibly other CGI programs, allows remote attackers to execute arbitrary commands via shell metacharacters in any field of the 'Compose Message' page.

CVSS2: 7.5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1099

The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.

CVSS2: 5
3%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1098

Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file.

CVSS2: 2.1
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1097

Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.

CVSS2: 5
17%
Средний
больше 24 лет назад
nvd логотип
CVE-2001-1096

Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code.

CVSS2: 4.6
0%
Низкий
около 24 лет назад

Уязвимостей на страницу