Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 878

Количество 331 878

nvd логотип

CVE-2001-1472

больше 24 лет назад

SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1471

больше 24 лет назад

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2001-1470

около 25 лет назад

The IDEA cipher as implemented by SSH1 does not protect the final block of a message against modification, which allows remote attackers to modify the block without detection by changing its cyclic redundancy check (CRC) to match the modifications to the message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1469

около 25 лет назад

The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message's cyclic redundancy check (CRC) with the CRC of a mask consisting of all the bits of the original message that were modified.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1468

около 25 лет назад

PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1467

почти 25 лет назад

mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1466

около 24 лет назад

Buffer overflow in VanDyke SecureCRT before 3.4.2, when using the SSH-1 protocol, allows remote attackers to execute arbitrary code via a long (1) username or (2) password.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2001-1465

почти 24 года назад

SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1464

около 25 лет назад

Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1463

около 24 лет назад

The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1462

больше 24 лет назад

WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1461

больше 24 лет назад

Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to access restricted resources via URL-encoded (1) /.. or (2) \.. sequences.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1460

больше 24 лет назад

SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1459

больше 24 лет назад

OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1458

больше 24 лет назад

Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1457

около 24 лет назад

Buffer overflow in CrazyWWWBoard 2000p4 and 2000LEp5 allows remote attackers to execute arbitrary code via a long HTTP_USER_AGENT CGI environment variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1456

больше 24 лет назад

Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1455

больше 24 лет назад

Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1454

около 25 лет назад

Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2001-1453

около 25 лет назад

Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1472

SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.

CVSS2: 4.6
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1471

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

CVSS3: 8.8
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1470

The IDEA cipher as implemented by SSH1 does not protect the final block of a message against modification, which allows remote attackers to modify the block without detection by changing its cyclic redundancy check (CRC) to match the modifications to the message.

CVSS2: 5
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1469

The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message's cyclic redundancy check (CRC) with the CRC of a mask consisting of all the bits of the original message that were modified.

CVSS2: 5
0%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1468

PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
2%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1467

mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.

CVSS2: 7.5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1466

Buffer overflow in VanDyke SecureCRT before 3.4.2, when using the SSH-1 protocol, allows remote attackers to execute arbitrary code via a long (1) username or (2) password.

CVSS2: 7.5
14%
Средний
около 24 лет назад
nvd логотип
CVE-2001-1465

SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements.

CVSS2: 4.6
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1464

Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.

CVSS2: 7.5
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1463

The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.

CVSS2: 7.5
7%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1462

WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information.

CVSS2: 7.5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1461

Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to access restricted resources via URL-encoded (1) /.. or (2) \.. sequences.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1460

SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter.

CVSS2: 7.5
4%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1459

OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.

CVSS2: 7.5
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1458

Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1457

Buffer overflow in CrazyWWWBoard 2000p4 and 2000LEp5 allows remote attackers to execute arbitrary code via a long HTTP_USER_AGENT CGI environment variable.

CVSS2: 7.5
6%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1456

Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message.

CVSS2: 7.5
9%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1455

Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1454

Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.

CVSS2: 7.5
12%
Средний
около 25 лет назад
nvd логотип
CVE-2001-1453

Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.

CVSS2: 7.5
12%
Средний
около 25 лет назад

Уязвимостей на страницу