Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 316 043

Количество 316 043

nvd логотип

CVE-2001-0409

больше 24 лет назад

vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-0408

больше 24 лет назад

vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when another user opens a file containing malicious VIM control codes.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2001-0407

больше 24 лет назад

Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-0406

больше 24 лет назад

Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-0405

больше 24 лет назад

ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2001-0404

больше 24 лет назад

Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0403

больше 24 лет назад

/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0402

больше 24 лет назад

IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted port.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0401

больше 24 лет назад

Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0400

больше 24 лет назад

nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2001-0399

больше 24 лет назад

Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0398

больше 24 лет назад

The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT! to misrepresent the attachment's type with a different icon.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0397

больше 24 лет назад

Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0396

больше 24 лет назад

The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0395

больше 24 лет назад

Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2001-0394

около 24 лет назад

Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0393

больше 24 лет назад

Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0392

больше 24 лет назад

Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0391

больше 24 лет назад

Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0390

больше 24 лет назад

IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-0409

vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory.

CVSS2: 2.1
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0408

vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when another user opens a file containing malicious VIM control codes.

CVSS2: 5.1
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0407

Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).

CVSS2: 4.6
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0406

Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.

CVSS2: 2.1
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0405

ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.

CVSS2: 7.5
14%
Средний
больше 24 лет назад
nvd логотип
CVE-2001-0404

Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0403

/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.

CVSS2: 7.2
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0402

IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted port.

CVSS2: 7.5
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0401

Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.

CVSS2: 7.2
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0400

nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.

CVSS2: 7.5
13%
Средний
больше 24 лет назад
nvd логотип
CVE-2001-0399

Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.

CVSS2: 5
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0398

The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT! to misrepresent the attachment's type with a different icon.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0397

Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0396

The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0395

Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.

CVSS3: 9.8
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0394

Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory.

CVSS2: 5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-0393

Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0392

Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0391

Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0390

IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.

CVSS2: 5
7%
Низкий
больше 24 лет назад

Уязвимостей на страницу