Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 328

Количество 372 328

nvd логотип

CVE-2001-1100

почти 25 лет назад

sendmessage.cgi in W3Mail 1.0.2, and possibly other CGI programs, allows remote attackers to execute arbitrary commands via shell metacharacters in any field of the 'Compose Message' page.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1099

почти 25 лет назад

The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1098

почти 25 лет назад

Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1097

около 25 лет назад

Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1096

почти 25 лет назад

Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1095

почти 25 лет назад

Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1094

почти 25 лет назад

NetOp School 1.5 allows local users to bypass access restrictions on the administration version by logging into the student version, closing the student version, then starting the administration version.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1093

почти 25 лет назад

Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-1092

почти 25 лет назад

msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink attack on the .mh_profile file.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1091

почти 25 лет назад

The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-1090

почти 25 лет назад

nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1089

почти 25 лет назад

libnss-pgsql in nss-pgsql 0.9.0 and earlier allows remote attackers to execute arbitrary SQL queries by inserting SQL code into an HTTP request.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1088

около 25 лет назад

Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2001-1087

около 25 лет назад

The default configuration of the config.http.tunnel.allow_ports option on NetCache devices is set to +all, which allows remote attackers to connect to arbitrary ports on remote systems behind the device.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1086

около 25 лет назад

XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1085

около 25 лет назад

Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS2: 3.7
EPSS: Низкий
nvd логотип

CVE-2001-1084

около 25 лет назад

Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1083

около 25 лет назад

Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or \ (backward slash).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1082

около 25 лет назад

Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1081

около 25 лет назад

Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via format specifiers that are injected into log messages.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1100

sendmessage.cgi in W3Mail 1.0.2, and possibly other CGI programs, allows remote attackers to execute arbitrary commands via shell metacharacters in any field of the 'Compose Message' page.

CVSS2: 7.5
4%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1099

The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.

CVSS2: 5
3%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1098

Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file.

CVSS2: 2.1
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1097

Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.

CVSS2: 5
4%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1096

Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code.

CVSS2: 4.6
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1095

Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter.

CVSS2: 4.6
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1094

NetOp School 1.5 allows local users to bypass access restrictions on the administration version by logging into the student version, closing the student version, then starting the administration version.

CVSS2: 4.6
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1093

Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument.

CVSS2: 7.2
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1092

msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink attack on the .mh_profile file.

CVSS2: 2.1
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1091

The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.

CVSS2: 7.2
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1090

nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request.

CVSS2: 7.5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1089

libnss-pgsql in nss-pgsql 0.9.0 and earlier allows remote attackers to execute arbitrary SQL queries by inserting SQL code into an HTTP request.

CVSS2: 7.5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1088

Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.

CVSS2: 7.5
20%
Средний
около 25 лет назад
nvd логотип
CVE-2001-1087

The default configuration of the config.http.tunnel.allow_ports option on NetCache devices is set to +all, which allows remote attackers to connect to arbitrary ports on remote systems behind the device.

CVSS2: 7.5
2%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1086

XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.

CVSS2: 7.5
3%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1085

Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS2: 3.7
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1084

Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.

CVSS2: 7.5
3%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1083

Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or \ (backward slash).

CVSS2: 5
10%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1082

Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack.

CVSS2: 5
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1081

Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via format specifiers that are injected into log messages.

CVSS2: 7.5
3%
Низкий
около 25 лет назад

Уязвимостей на страницу