Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 878

Количество 331 878

nvd логотип

CVE-2001-1515

около 24 лет назад

Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1514

около 24 лет назад

ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-1513

около 24 лет назад

Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as demonstrated using ctx.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1512

около 24 лет назад

Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Pages (JSP), a variant of CVE-2000-1050.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2001-1511

около 24 лет назад

JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source filename ending in (1) "jsp%00" or (2) "js%2570".

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1510

около 24 лет назад

Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1509

около 24 лет назад

geteuid in Itanium Architecture (IA) running on HP-UX 11.20 does not properly identify a user's effective user id, which could allow local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1508

около 24 лет назад

Buffer overflow in lpstat in SCO OpenServer 5.0 through 5.0.6a allows local users to execute arbitrary code as group bin via a long command line argument.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1507

около 24 лет назад

OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1506

около 24 лет назад

Unknown vulnerability in the file system protection subsystem in HP Secure OS Software for Linux 1.0 allows additional user privileges on some files beyond what is specified in the file system protection rules, which allows local users to conduct unauthorized operations on restricted files.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1505

около 24 лет назад

tinc 1.0pre3 and 1.0pre4 allows remote attackers to inject data into user sessions by sniffing and replaying packets.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1504

около 24 лет назад

Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user processes the e-mail message.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1503

около 24 лет назад

The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1502

около 24 лет назад

webcart.cgi in Mountain Network Systems WebCart 8.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the NEXTPAGE parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1501

около 24 лет назад

The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/" sequences in the argument.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1500

около 24 лет назад

ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1499

около 24 лет назад

Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1498

около 24 лет назад

Buffer overflow in mod_bf 0.2 allows local users to execute arbitrary commands via a long script.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-1497

около 24 лет назад

Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1496

около 24 лет назад

Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1515

Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended.

CVSS3: 7.5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1514

ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.

CVSS2: 10
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1513

Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as demonstrated using ctx.

CVSS2: 7.5
8%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1512

Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Pages (JSP), a variant of CVE-2000-1050.

CVSS2: 6.4
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1511

JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source filename ending in (1) "jsp%00" or (2) "js%2570".

CVSS2: 5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1510

Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.

CVSS2: 5
4%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1509

geteuid in Itanium Architecture (IA) running on HP-UX 11.20 does not properly identify a user's effective user id, which could allow local users to gain privileges.

CVSS2: 4.6
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1508

Buffer overflow in lpstat in SCO OpenServer 5.0 through 5.0.6a allows local users to execute arbitrary code as group bin via a long command line argument.

CVSS2: 4.6
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1507

OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.

CVSS2: 7.5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1506

Unknown vulnerability in the file system protection subsystem in HP Secure OS Software for Linux 1.0 allows additional user privileges on some files beyond what is specified in the file system protection rules, which allows local users to conduct unauthorized operations on restricted files.

CVSS2: 4.6
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1505

tinc 1.0pre3 and 1.0pre4 allows remote attackers to inject data into user sessions by sniffing and replaying packets.

CVSS2: 5
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1504

Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user processes the e-mail message.

CVSS2: 7.5
3%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1503

The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.

CVSS2: 2.1
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1502

webcart.cgi in Mountain Network Systems WebCart 8.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the NEXTPAGE parameter.

CVSS2: 7.5
9%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1501

The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/" sequences in the argument.

CVSS2: 5
8%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1500

ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged.

CVSS2: 7.5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1499

Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks.

CVSS2: 5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1498

Buffer overflow in mod_bf 0.2 allows local users to execute arbitrary commands via a long script.

CVSS2: 7.2
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1497

Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.

CVSS2: 2.1
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1496

Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS3: 9.8
18%
Средний
около 24 лет назад

Уязвимостей на страницу