Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 328

Количество 372 328

nvd логотип

CVE-2001-0454

около 25 лет назад

Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in the HTTP request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0453

около 25 лет назад

Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) scripts directories.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0452

около 25 лет назад

BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0451

около 25 лет назад

INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0450

около 25 лет назад

Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2001-0449

около 25 лет назад

Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail command line option.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-0448

около 25 лет назад

Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0447

около 25 лет назад

Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0446

около 25 лет назад

IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0444

около 25 лет назад

Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-0443

около 25 лет назад

Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0442

около 25 лет назад

Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP command.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0441

около 25 лет назад

Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0440

около 25 лет назад

Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0439

около 25 лет назад

licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0438

около 25 лет назад

Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-0437

около 25 лет назад

upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0436

около 25 лет назад

dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0435

около 25 лет назад

The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on" option and capturing the passphrases of other share holders as they authenticate.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-0434

около 25 лет назад

The LogDataListToFile ActiveX function used in (1) Knowledge Center and (2) Back web components of Compaq Presario computers allows remote attackers to modify arbitrary files and cause a denial of service.

CVSS2: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-0454

Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in the HTTP request.

CVSS2: 5
3%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0453

Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) scripts directories.

CVSS2: 5
2%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0452

BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.

CVSS2: 5
3%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0451

INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1.

CVSS2: 7.5
2%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0450

Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name.

CVSS2: 6.4
2%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0449

Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail command line option.

CVSS2: 4.6
0%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0448

Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.

CVSS2: 5
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0447

Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters.

CVSS2: 7.5
2%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0446

IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.

CVSS2: 5
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0444

Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information.

CVSS2: 2.1
0%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0443

Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password.

CVSS2: 7.5
2%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0442

Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP command.

CVSS2: 7.5
5%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0441

Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.

CVSS2: 7.5
3%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0440

Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.

CVSS2: 7.5
5%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0439

licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

CVSS2: 7.5
2%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0438

Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu.

CVSS2: 2.1
0%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0437

upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.

CVSS2: 5
2%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0436

dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.

CVSS2: 7.5
2%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0435

The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on" option and capturing the passphrases of other share holders as they authenticate.

CVSS2: 4.6
0%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0434

The LogDataListToFile ActiveX function used in (1) Knowledge Center and (2) Back web components of Compaq Presario computers allows remote attackers to modify arbitrary files and cause a denial of service.

CVSS2: 6.4
1%
Низкий
около 25 лет назад

Уязвимостей на страницу