Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 395 605

Количество 395 605

nvd логотип

CVE-2001-1501

больше 24 лет назад

The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/" sequences in the argument.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2001-1500

больше 24 лет назад

ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2001-1499

больше 24 лет назад

Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1498

больше 24 лет назад

Buffer overflow in mod_bf 0.2 allows local users to execute arbitrary commands via a long script.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-1497

больше 24 лет назад

Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1496

больше 24 лет назад

Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2001-1495

больше 24 лет назад

network_query.php in Network Query Tool 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the target parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1494

больше 24 лет назад

script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2001-1492

больше 24 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2001-1460. Reason: This candidate is a refinement duplicate of CVE-2001-1460. Notes: All CVE users should reference CVE-2001-1460 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2001-1491

больше 24 лет назад

Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1490

больше 24 лет назад

Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1489

больше 24 лет назад

Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2001-1488

больше 24 лет назад

Open Projects Network Internet Relay Chat (IRC) daemon u2.10.05.18 does not perform a double-reverse DNS lookup, which allows remote attackers to spoof any valid hostname on the Internet. NOTE: a followup post suggests that this is not an issue in the daemon.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1487

больше 24 лет назад

popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1484

больше 24 лет назад

Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1483

больше 24 лет назад

One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1482

больше 24 лет назад

SQL injection vulnerability in bb_memberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL queries via the $sortby variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1481

больше 24 лет назад

Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2001-1480

больше 24 лет назад

Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1479

больше 24 лет назад

smcboot in Sun SMC (Sun Management Center) 2.0 in Solaris 8 allows local users to delete arbitrary files via a symlink attack on /tmp/smc$SMC_PORT.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1501

The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/" sequences in the argument.

CVSS2: 5
38%
Средний
больше 24 лет назад
nvd логотип
CVE-2001-1500

ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged.

CVSS2: 7.5
12%
Средний
больше 24 лет назад
nvd логотип
CVE-2001-1499

Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks.

CVSS2: 5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1498

Buffer overflow in mod_bf 0.2 allows local users to execute arbitrary commands via a long script.

CVSS2: 7.2
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1497

Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.

CVSS2: 2.1
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1496

Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS3: 9.8
5%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1495

network_query.php in Network Query Tool 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the target parameter.

CVSS2: 7.5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1494

script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.

CVSS3: 5.5
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1492

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2001-1460. Reason: This candidate is a refinement duplicate of CVE-2001-1460. Notes: All CVE users should reference CVE-2001-1460 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

больше 24 лет назад
nvd логотип
CVE-2001-1491

Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS2: 5
7%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1490

Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS2: 5
6%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1489

Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS2: 5
18%
Средний
больше 24 лет назад
nvd логотип
CVE-2001-1488

Open Projects Network Internet Relay Chat (IRC) daemon u2.10.05.18 does not perform a double-reverse DNS lookup, which allows remote attackers to spoof any valid hostname on the Internet. NOTE: a followup post suggests that this is not an issue in the daemon.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1487

popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option.

CVSS2: 4.6
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1484

Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication.

CVSS2: 7.5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1483

One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.

CVSS2: 5
4%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1482

SQL injection vulnerability in bb_memberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL queries via the $sortby variable.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1481

Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.

CVSS3: 9.8
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1480

Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.

CVSS2: 7.5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1479

smcboot in Sun SMC (Sun Management Center) 2.0 in Solaris 8 allows local users to delete arbitrary files via a symlink attack on /tmp/smc$SMC_PORT.

CVSS2: 2.1
0%
Низкий
больше 24 лет назад

Уязвимостей на страницу