Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 149

Количество 371 149

nvd логотип

CVE-2001-0873

больше 24 лет назад

uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privileges by calling uux and specifying an alternate configuration file with the --config option.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0872

больше 24 лет назад

OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0871

больше 24 лет назад

Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor allows remote attackers to execute arbitrary commands via an HTTP request containing (1) a .. in versions 2.0 through 2.6.18, or (2) a DOS device name followed by a .. in versions 2.6.19 through 3.0.10.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0870

больше 24 лет назад

HTTP server in Alchemy Eye and Alchemy Network Monitor 1.9x through 2.6.18 is enabled without authentication by default, which allows remote attackers to obtain network monitoring logs with potentially sensitive information by directly requesting the eye.ini file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0869

больше 24 лет назад

Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow remote attackers to execute arbitrary commands.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0868

больше 24 лет назад

Red Hat Stronghold 2.3 to 3.0 allows remote attackers to retrieve system information via an HTTP GET request to (1) stronghold-info or (2) stronghold-status.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0867

больше 24 лет назад

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly filter does not properly filter packet fragments even when the "fragment" keyword is used in an ACL, which allows remote attackers to bypass the intended access controls.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0866

больше 24 лет назад

Cisco 12000 with IOS 12.0 and lines card based on Engine 2 does not properly handle an outbound ACL when an input ACL is not configured on all the interfaces of a multi port line card, which could allow remote attackers to bypass the intended access controls.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0865

больше 24 лет назад

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not support the "fragment" keyword in an outgoing ACL, which could allow fragmented packets in violation of the intended access.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0864

больше 24 лет назад

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0863

больше 24 лет назад

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not handle the "fragment" keyword in a compiled ACL (Turbo ACL) for packets that are sent to the router, which allows remote attackers to cause a denial of service via a flood of fragments.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0862

больше 24 лет назад

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0861

больше 24 лет назад

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic that generates a large number of ICMP Unreachable replies.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0860

больше 24 лет назад

Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Address Translation (NAT).

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0859

больше 24 лет назад

2.4.3-12 kernel in Red Hat Linux 7.1 Korean installation program sets the setting default umask for init to 000, which installs files with world-writeable permissions.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0858

больше 24 лет назад

Buffer overflow in pppattach and other linked PPP utilities in Caldera Open Unix 8.0 and UnixWare 7.1.0 and 7.1.1 allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-0857

больше 24 лет назад

Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0856

больше 24 лет назад

Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a brute force attack to create a 3DES exporter key.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-0855

больше 24 лет назад

Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM environment variable.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0854

больше 24 лет назад

PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of the user.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-0873

uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privileges by calling uux and specifying an alternate configuration file with the --config option.

CVSS2: 7.2
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0872

OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.

CVSS2: 7.2
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0871

Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor allows remote attackers to execute arbitrary commands via an HTTP request containing (1) a .. in versions 2.0 through 2.6.18, or (2) a DOS device name followed by a .. in versions 2.6.19 through 3.0.10.

CVSS2: 7.5
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0870

HTTP server in Alchemy Eye and Alchemy Network Monitor 1.9x through 2.6.18 is enabled without authentication by default, which allows remote attackers to obtain network monitoring logs with potentially sensitive information by directly requesting the eye.ini file.

CVSS2: 5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0869

Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow remote attackers to execute arbitrary commands.

CVSS2: 7.5
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0868

Red Hat Stronghold 2.3 to 3.0 allows remote attackers to retrieve system information via an HTTP GET request to (1) stronghold-info or (2) stronghold-status.

CVSS2: 5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0867

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly filter does not properly filter packet fragments even when the "fragment" keyword is used in an ACL, which allows remote attackers to bypass the intended access controls.

CVSS2: 7.5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0866

Cisco 12000 with IOS 12.0 and lines card based on Engine 2 does not properly handle an outbound ACL when an input ACL is not configured on all the interfaces of a multi port line card, which could allow remote attackers to bypass the intended access controls.

CVSS2: 7.5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0865

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not support the "fragment" keyword in an outgoing ACL, which could allow fragmented packets in violation of the intended access.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0864

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0863

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not handle the "fragment" keyword in a compiled ACL (Turbo ACL) for packets that are sent to the router, which allows remote attackers to cause a denial of service via a flood of fragments.

CVSS2: 5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0862

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL.

CVSS2: 7.5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0861

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic that generates a large number of ICMP Unreachable replies.

CVSS2: 5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0860

Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Address Translation (NAT).

CVSS2: 7.5
5%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0859

2.4.3-12 kernel in Red Hat Linux 7.1 Korean installation program sets the setting default umask for init to 000, which installs files with world-writeable permissions.

CVSS2: 5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0858

Buffer overflow in pppattach and other linked PPP utilities in Caldera Open Unix 8.0 and UnixWare 7.1.0 and 7.1.1 allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0857

Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter.

CVSS2: 7.5
8%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0856

Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a brute force attack to create a 3DES exporter key.

CVSS2: 4.6
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0855

Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM environment variable.

CVSS2: 7.2
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-0854

PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of the user.

CVSS2: 5
1%
Низкий
больше 24 лет назад

Уязвимостей на страницу