Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 342 694

Количество 342 694

nvd логотип

CVE-2001-0839

больше 24 лет назад

ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0838

больше 24 лет назад

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0837

больше 24 лет назад

DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-readable locations in the installation directory, which allows local users to read the information in (1) temp.html, (2) the log folder, and (3) the PhoneBook folder.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-0836

больше 24 лет назад

Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2001-0835

больше 24 лет назад

Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0834

больше 24 лет назад

htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2001-0833

больше 24 лет назад

Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0832

больше 24 лет назад

Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability."

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-0831

больше 24 лет назад

Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-0830

больше 24 лет назад

6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to and disconnecting from the server.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0829

больше 24 лет назад

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2001-0828

больше 24 лет назад

A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which causes an error message that does not properly quote the Javascript.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2001-0827

больше 24 лет назад

Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0826

больше 24 лет назад

Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0825

больше 24 лет назад

Buffer overflow in internal string handling routines of xinetd before 2.1.8.8 allows remote attackers to execute arbitrary commands via a length argument of zero or less, which disables the length check.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-0824

больше 24 лет назад

Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0823

больше 24 лет назад

The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCP_LOG_DIR).

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0822

больше 24 лет назад

FPF kernel module 1.0 allows a remote attacker to cause a denial of service via fragmented packets.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0821

больше 24 лет назад

The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2001-0820

больше 24 лет назад

Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-0839

ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing.

CVSS2: 7.5
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0838

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

CVSS2: 7.5
4%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0837

DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-readable locations in the installation directory, which allows local users to read the information in (1) temp.html, (2) the log folder, and (3) the PhoneBook folder.

CVSS2: 2.1
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0836

Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.

CVSS2: 7.5
23%
Средний
больше 24 лет назад
nvd логотип
CVE-2001-0835

Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.

CVSS2: 7.5
5%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0834

htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file.

CVSS2: 6.4
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0833

Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."

CVSS2: 7.2
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0832

Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability."

CVSS2: 2.1
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0831

Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.

CVSS2: 4.6
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0830

6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to and disconnecting from the server.

CVSS3: 7.5
9%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0829

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

CVSS2: 5.1
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0828

A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which causes an error message that does not properly quote the Javascript.

CVSS2: 5.1
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0827

Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.

CVSS3: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0826

Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0825

Buffer overflow in internal string handling routines of xinetd before 2.1.8.8 allows remote attackers to execute arbitrary commands via a length argument of zero or less, which disables the length check.

CVSS2: 10
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0824

Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0823

The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCP_LOG_DIR).

CVSS2: 7.2
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0822

FPF kernel module 1.0 allows a remote attacker to cause a denial of service via fragmented packets.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0821

The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt.

CVSS2: 5
12%
Средний
больше 24 лет назад
nvd логотип
CVE-2001-0820

Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c.

CVSS2: 7.5
31%
Средний
больше 24 лет назад

Уязвимостей на страницу