Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 614

Количество 367 614

nvd логотип

CVE-2001-1286

почти 25 лет назад

Ipswitch IMail 7.04 and earlier stores a user's session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. via an HTML email that causes the Referrer to be sent to a URL under the attacker's control.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1285

почти 25 лет назад

Directory traversal vulnerability in readmail.cgi for Ipswitch IMail 7.04 and earlier allows remote attackers to access the mailboxes of other users via a .. (dot dot) in the mbx parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1284

почти 25 лет назад

Ipswitch IMail 7.04 and earlier uses predictable session IDs for authentication, which allows remote attackers to hijack sessions of other users.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1283

почти 25 лет назад

The webmail interface for Ipswitch IMail 7.04 and earlier allows remote authenticated users to cause a denial of service (crash) via a mailbox name that contains a large number of . (dot) or other characters to programs such as (1) readmail.cgi or (2) printmail.cgi, possibly due to a buffer overflow that may allow execution of arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1282

почти 25 лет назад

Ipswitch IMail 7.04 and earlier records the physical path of attachments in an e-mail message header, which could allow remote attackers to obtain potentially sensitive configuration information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1281

почти 25 лет назад

Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser parameter in the "Change User Information" web form.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1280

почти 25 лет назад

POP3 Server for Ipswitch IMail 7.04 and earlier generates different responses to valid and invalid user names, which allows remote attackers to determine users on the system.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1279

около 25 лет назад

Buffer overflow in print-rx.c of tcpdump 3.x (probably 3.6x) allows remote attackers to cause a denial of service and possibly execute arbitrary code via AFS RPC packets with invalid lengths that trigger an integer signedness error, a different vulnerability than CVE-2000-1026.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1278

почти 25 лет назад

Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1277

около 25 лет назад

makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1276

около 25 лет назад

ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file.

CVSS2: 1.2
EPSS: Низкий
nvd логотип

CVE-2001-1275

больше 25 лет назад

MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-1274

больше 25 лет назад

Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1273

больше 25 лет назад

The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1272

больше 24 лет назад

wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1271

около 25 лет назад

Directory traversal vulnerability in rar 2.02 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) attack on archived filenames.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1270

около 25 лет назад

Directory traversal vulnerability in the console version of PKZip (pkzipc) 4.00 and earlier allows attackers to overwrite arbitrary files during archive extraction with the -rec (recursive) option via a .. (dot dot) attack on the archived files.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1269

около 25 лет назад

Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that begin with the '/' (slash) character.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1268

около 25 лет назад

Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1267

около 25 лет назад

Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1286

Ipswitch IMail 7.04 and earlier stores a user's session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. via an HTML email that causes the Referrer to be sent to a URL under the attacker's control.

CVSS2: 7.5
3%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1285

Directory traversal vulnerability in readmail.cgi for Ipswitch IMail 7.04 and earlier allows remote attackers to access the mailboxes of other users via a .. (dot dot) in the mbx parameter.

CVSS2: 5
3%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1284

Ipswitch IMail 7.04 and earlier uses predictable session IDs for authentication, which allows remote attackers to hijack sessions of other users.

CVSS2: 7.5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1283

The webmail interface for Ipswitch IMail 7.04 and earlier allows remote authenticated users to cause a denial of service (crash) via a mailbox name that contains a large number of . (dot) or other characters to programs such as (1) readmail.cgi or (2) printmail.cgi, possibly due to a buffer overflow that may allow execution of arbitrary code.

CVSS2: 7.5
4%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1282

Ipswitch IMail 7.04 and earlier records the physical path of attachments in an e-mail message header, which could allow remote attackers to obtain potentially sensitive configuration information.

CVSS2: 5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1281

Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser parameter in the "Change User Information" web form.

CVSS2: 5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1280

POP3 Server for Ipswitch IMail 7.04 and earlier generates different responses to valid and invalid user names, which allows remote attackers to determine users on the system.

CVSS2: 5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1279

Buffer overflow in print-rx.c of tcpdump 3.x (probably 3.6x) allows remote attackers to cause a denial of service and possibly execute arbitrary code via AFS RPC packets with invalid lengths that trigger an integer signedness error, a different vulnerability than CVE-2000-1026.

CVSS2: 7.5
5%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1278

Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.

CVSS2: 7.5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1277

makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.

CVSS2: 2.1
0%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1276

ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file.

CVSS2: 1.2
0%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1275

MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.

CVSS2: 7.2
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1274

Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.

CVSS2: 7.5
5%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1273

The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).

CVSS2: 2.1
0%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1272

wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option.

CVSS2: 4.6
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1271

Directory traversal vulnerability in rar 2.02 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) attack on archived filenames.

CVSS2: 2.1
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1270

Directory traversal vulnerability in the console version of PKZip (pkzipc) 4.00 and earlier allows attackers to overwrite arbitrary files during archive extraction with the -rec (recursive) option via a .. (dot dot) attack on the archived files.

CVSS2: 2.1
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1269

Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that begin with the '/' (slash) character.

CVSS2: 2.1
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1268

Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename.

CVSS2: 2.1
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1267

Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).

CVSS2: 2.1
1%
Низкий
около 25 лет назад

Уязвимостей на страницу