Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 328

Количество 372 328

nvd логотип

CVE-2001-0541

почти 25 лет назад

Buffer overflow in Microsoft Windows Media Player 7.1 and earlier allows remote attackers to execute arbitrary commands via a malformed Windows Media Station (.NSC) file.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2001-0540

почти 25 лет назад

Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389.

CVSS2: 5
EPSS: Высокий
nvd логотип

CVE-2001-0538

почти 25 лет назад

Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2001-0537

около 25 лет назад

HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2001-0535

почти 25 лет назад

Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variable in (1) the "Web Publish" example script, and (2) the "Email" example script.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0534

около 25 лет назад

Multiple buffer overflows in RADIUS daemon radiusd in (1) Merit 3.6b and (2) Lucent 2.1-2 RADIUS allow remote attackers to cause a denial of service or execute arbitrary commands.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-0533

почти 25 лет назад

Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0530

почти 25 лет назад

Spearhead NetGAP 200 and 300 before build 78 allow a remote attacker to bypass file blocking and content inspection via specially encoded URLs which include '%' characters.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0529

почти 25 лет назад

OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0528

почти 25 лет назад

Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0527

почти 25 лет назад

DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-0526

почти 25 лет назад

Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-0525

почти 25 лет назад

Buffer overflow in dsh in dqs 3.2.7 in SuSE Linux 7.0 and earlier, and possibly other operating systems, allows local users to gain privileges via a long first command line argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0524

почти 25 лет назад

eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0523

почти 25 лет назад

eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on vulnerable programs that would otherwise be protected.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0522

почти 25 лет назад

Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2001-0521

почти 25 лет назад

Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0520

почти 25 лет назад

Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT tag, or (5) any other tag in which scripts can be defined.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0519

почти 25 лет назад

Aladdin eSafe Gateway versions 2.x allows a remote attacker to circumvent HTML SCRIPT filtering via a special arrangement of HTML tags which includes SCRIPT tags embedded within other SCRIPT tags.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0518

около 25 лет назад

Oracle listener before Oracle 9i allows attackers to cause a denial of service by repeatedly sending the first portion of a fragmented Oracle command without sending the remainder of the command, which causes the listener to hang.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-0541

Buffer overflow in Microsoft Windows Media Player 7.1 and earlier allows remote attackers to execute arbitrary commands via a malformed Windows Media Station (.NSC) file.

CVSS2: 7.5
16%
Средний
почти 25 лет назад
nvd логотип
CVE-2001-0540

Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389.

CVSS2: 5
71%
Высокий
почти 25 лет назад
nvd логотип
CVE-2001-0538

Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.

CVSS2: 10
53%
Средний
почти 25 лет назад
nvd логотип
CVE-2001-0537

HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.

CVSS2: 9.3
68%
Средний
около 25 лет назад
nvd логотип
CVE-2001-0535

Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variable in (1) the "Web Publish" example script, and (2) the "Email" example script.

CVSS2: 7.5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0534

Multiple buffer overflows in RADIUS daemon radiusd in (1) Merit 3.6b and (2) Lucent 2.1-2 RADIUS allow remote attackers to cause a denial of service or execute arbitrary commands.

CVSS2: 10
7%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0533

Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.

CVSS2: 7.2
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0530

Spearhead NetGAP 200 and 300 before build 78 allow a remote attacker to bypass file blocking and content inspection via specially encoded URLs which include '%' characters.

CVSS2: 5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0529

OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.

CVSS2: 7.2
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0528

Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain privileges.

CVSS2: 7.2
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0527

DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.

CVSS2: 10
5%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0526

Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable.

CVSS2: 4.6
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0525

Buffer overflow in dsh in dqs 3.2.7 in SuSE Linux 7.0 and earlier, and possibly other operating systems, allows local users to gain privileges via a long first command line argument.

CVSS2: 7.2
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0524

eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier.

CVSS2: 7.5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0523

eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on vulnerable programs that would otherwise be protected.

CVSS2: 7.5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0522

Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.

CVSS2: 7.5
14%
Средний
почти 25 лет назад
nvd логотип
CVE-2001-0521

Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.

CVSS2: 7.5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0520

Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT tag, or (5) any other tag in which scripts can be defined.

CVSS2: 7.5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0519

Aladdin eSafe Gateway versions 2.x allows a remote attacker to circumvent HTML SCRIPT filtering via a special arrangement of HTML tags which includes SCRIPT tags embedded within other SCRIPT tags.

CVSS2: 7.5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0518

Oracle listener before Oracle 9i allows attackers to cause a denial of service by repeatedly sending the first portion of a fragmented Oracle command without sending the remainder of the command, which causes the listener to hang.

CVSS2: 5
2%
Низкий
около 25 лет назад

Уязвимостей на страницу