Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 343 774

Количество 343 774

nvd логотип

CVE-2001-1227

больше 24 лет назад

Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1226

больше 24 лет назад

AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1225

больше 24 лет назад

Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1224

больше 24 лет назад

get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1223

больше 24 лет назад

The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-1222

около 24 лет назад

Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1221

больше 24 лет назад

D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of 'public' which allows remote attackers to gain sensitive information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1220

больше 24 лет назад

D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point stores the administrative password in plaintext in the default Management Information Base (MIB), which allows remote attackers to gain administrative privileges.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-1219

больше 24 лет назад

Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1218

больше 24 лет назад

Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1217

больше 24 лет назад

Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1216

больше 24 лет назад

Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1215

больше 24 лет назад

Format string vulnerability in PFinger 0.7.5 through 0.7.7 allows remote attackers to execute arbitrary code via format string specifiers in a .plan file.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1214

больше 24 лет назад

manual.php in Marcus S. Xenakis Unix Manual 1.0 allows remote attackers to execute arbitrary code via a URL that contains shell metacharacters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1213

больше 24 лет назад

The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote attackers to read and write arbitrary files in the root folder.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2001-1212

больше 24 лет назад

Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascript via the desc parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1211

больше 24 лет назад

Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1210

больше 24 лет назад

Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community strings.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2001-1209

больше 24 лет назад

Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1208

больше 24 лет назад

Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1227

Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1226

AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1225

Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried.

CVSS2: 2.1
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1224

get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1223

The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server.

CVSS2: 10
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1222

Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2001-1221

D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of 'public' which allows remote attackers to gain sensitive information.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1220

D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point stores the administrative password in plaintext in the default Management Information Base (MIB), which allows remote attackers to gain administrative privileges.

CVSS2: 10
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1219

Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location.

CVSS2: 5
5%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1218

Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.

CVSS2: 2.1
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1217

Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.

CVSS2: 5
7%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1216

Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.

CVSS2: 7.5
5%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1215

Format string vulnerability in PFinger 0.7.5 through 0.7.7 allows remote attackers to execute arbitrary code via format string specifiers in a .plan file.

CVSS2: 7.5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1214

manual.php in Marcus S. Xenakis Unix Manual 1.0 allows remote attackers to execute arbitrary code via a URL that contains shell metacharacters.

CVSS2: 7.5
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1213

The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote attackers to read and write arbitrary files in the root folder.

CVSS2: 6.4
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1212

Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascript via the desc parameter.

CVSS2: 5
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1211

Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain.

CVSS2: 7.5
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1210

Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community strings.

CVSS2: 6.4
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1209

Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVSS2: 5
5%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1208

Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code.

CVSS2: 7.5
2%
Низкий
больше 24 лет назад

Уязвимостей на страницу