Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2001-1247

больше 24 лет назад

PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2001-1246

около 25 лет назад

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1245

около 25 лет назад

Opera 5.0 for Linux does not properly handle malformed HTTP headers, which allows remote attackers to cause a denial of service, possibly with a header whose value is the same as a MIME header name.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1244

около 25 лет назад

Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2001-1243

около 25 лет назад

Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2001-1242

около 25 лет назад

Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1241

около 25 лет назад

Un-CGI 1.9 and earlier does not verify that a CGI script has the execution bits set before executing it, which allows remote attackers to execute arbitrary commands by directing Un-CGI to a document that begins with "#!" and the desired program name.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1240

около 25 лет назад

The default configuration of sudo in Engarde Secure Linux 1.0.1 allows any user in the admin group to run certain commands that could be leveraged to gain full root access.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-1239

около 25 лет назад

PowerNet IX allows remote attackers to cause a denial of service via a port scan.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1238

около 25 лет назад

Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2001-1237

почти 25 лет назад

Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1236

почти 25 лет назад

myphpPagetool PHP script 0.4.3-1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1235

почти 25 лет назад

pSlash PHP script 0.7 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1234

почти 25 лет назад

Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the includedir variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1233

почти 25 лет назад

Netware Enterprise Web Server 5.1 running GroupWise WebAccess 5.5 with Novell Directory Services (NDS) enabled allows remote attackers to enumerate user names, group names and other system information by accessing ndsobj.nlm.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1232

почти 25 лет назад

GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1231

почти 25 лет назад

GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1230

больше 25 лет назад

Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1229

больше 25 лет назад

Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1228

больше 24 лет назад

Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1247

PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files.

CVSS2: 6.4
9%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1246

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

CVSS2: 7.5
8%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1245

Opera 5.0 for Linux does not properly handle malformed HTTP headers, which allows remote attackers to cause a denial of service, possibly with a header whose value is the same as a MIME header name.

CVSS2: 5
2%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1244

Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.

CVSS2: 5
21%
Средний
около 25 лет назад
nvd логотип
CVE-2001-1243

Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.

CVSS2: 5
63%
Средний
около 25 лет назад
nvd логотип
CVE-2001-1242

Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form.

CVSS2: 7.5
3%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1241

Un-CGI 1.9 and earlier does not verify that a CGI script has the execution bits set before executing it, which allows remote attackers to execute arbitrary commands by directing Un-CGI to a document that begins with "#!" and the desired program name.

CVSS2: 7.5
4%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1240

The default configuration of sudo in Engarde Secure Linux 1.0.1 allows any user in the admin group to run certain commands that could be leveraged to gain full root access.

CVSS2: 10
2%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1239

PowerNet IX allows remote attackers to cause a denial of service via a port scan.

CVSS2: 5
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1238

Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.

CVSS3: 7.8
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1237

Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable.

CVSS2: 7.5
5%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1236

myphpPagetool PHP script 0.4.3-1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.

CVSS2: 7.5
4%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1235

pSlash PHP script 0.7 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.

CVSS2: 7.5
5%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1234

Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the includedir variable.

CVSS2: 7.5
4%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1233

Netware Enterprise Web Server 5.1 running GroupWise WebAccess 5.5 with Novell Directory Services (NDS) enabled allows remote attackers to enumerate user names, group names and other system information by accessing ndsobj.nlm.

CVSS2: 5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1232

GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".

CVSS2: 5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1231

GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.

CVSS2: 5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1230

Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.

CVSS2: 7.5
3%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1229

Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.

CVSS2: 7.5
3%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1228

Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.

CVSS2: 7.5
3%
Низкий
больше 24 лет назад

Уязвимостей на страницу