Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 395 605

Количество 395 605

nvd логотип

CVE-2001-1438

почти 25 лет назад

Handspring Visor 1.0 and 1.0.1 with the VisorPhone Springboard module installed allows remote attackers to cause a denial of service (PalmOS crash and VisorPhone database corruption) by sending a large or crafted SMS image.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1437

почти 25 лет назад

easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1436

больше 25 лет назад

Dallas Semiconductor iButton DS1991 returns predictable values when given an incorrect password, which makes it easier for users with physical access to conduct dictionary attacks against the device password.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1435

больше 25 лет назад

inetd in Compaq Tru64 UNIX 5.1 allows attackers to cause a denial of service (network connection loss) by causing one of the services handled by inetd to core dump during startup, which causes inetd to stop accepting connections to all of its services.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1434

больше 25 лет назад

Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topology information via an "snmp-server host" command, which creates a readable "community" community string if one has not been previously created.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1433

больше 24 лет назад

Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1432

больше 24 лет назад

Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2001-1431

почти 25 лет назад

Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWall-1 4.1 Service Pack 3, IPSO 3.4 and VPN-1/FireWall-1 4.1 Service Pack 4, and IPSO 3.4 or IPSO 3.4.1 and VPN-1/FireWall-1 4.1 Service Pack 5, when SYN Defender is configured in Active Gateway mode, does not properly rewrite the third packet of a TCP three-way handshake to use the NAT IP address, which allows remote attackers to gain sensitive information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1430

больше 25 лет назад

Cayman 3220-H DSL Router 1.0 ship without a password set, which allows remote attackers to gain unauthorized access.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1429

почти 25 лет назад

Buffer overflow in mcedit in Midnight Commander 4.5.1 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted text file.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1428

больше 25 лет назад

The (1) FTP and (2) Telnet services in Beck GmbH IPC@Chip are shipped with a default password, which allows remote attackers to gain unauthorized access.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1427

около 25 лет назад

Unknown vulnerability in ColdFusion Server 2.0 through 4.5.1 SP2 allows remote attackers to overwrite templates with zero byte files via unknown attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1426

больше 25 лет назад

Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 has a TFTP server running without a password, which allows remote attackers to change firmware versions or the device's configurations.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1425

больше 25 лет назад

The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1424

больше 25 лет назад

Alcatel Speed Touch ADSL modem running firmware KHDSAA.108, KHDSAA.132, KHDSBA.133, and KHDSAA.134 has a blank default password, which allows remote attackers to gain unauthorized access.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1423

почти 25 лет назад

Advanced Poll before 1.61, when using a flat file database, allows remote attackers to gain privileges by setting the logged_in parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1422

больше 25 лет назад

WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1421

почти 25 лет назад

AOL Instant Messenger (AIM) 4.7 and earlier allows remote attackers to cause a denial of service (application crash) via a large number of different fonts followed by an HTML HR tag.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1420

больше 21 года назад

AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a long filename, possibly caused by a buffer overflow.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1419

почти 25 лет назад

AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<!--" HTML comments.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1438

Handspring Visor 1.0 and 1.0.1 with the VisorPhone Springboard module installed allows remote attackers to cause a denial of service (PalmOS crash and VisorPhone database corruption) by sending a large or crafted SMS image.

CVSS2: 5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1437

easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out.

CVSS2: 7.5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1436

Dallas Semiconductor iButton DS1991 returns predictable values when given an incorrect password, which makes it easier for users with physical access to conduct dictionary attacks against the device password.

CVSS2: 4.6
0%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1435

inetd in Compaq Tru64 UNIX 5.1 allows attackers to cause a denial of service (network connection loss) by causing one of the services handled by inetd to core dump during startup, which causes inetd to stop accepting connections to all of its services.

CVSS2: 5
2%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1434

Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topology information via an "snmp-server host" command, which creates a readable "community" community string if one has not been previously created.

CVSS2: 5
3%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1433

Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities.

CVSS2: 7.5
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1432

Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

CVSS2: 7.8
4%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1431

Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWall-1 4.1 Service Pack 3, IPSO 3.4 and VPN-1/FireWall-1 4.1 Service Pack 4, and IPSO 3.4 or IPSO 3.4.1 and VPN-1/FireWall-1 4.1 Service Pack 5, when SYN Defender is configured in Active Gateway mode, does not properly rewrite the third packet of a TCP three-way handshake to use the NAT IP address, which allows remote attackers to gain sensitive information.

CVSS2: 5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1430

Cayman 3220-H DSL Router 1.0 ship without a password set, which allows remote attackers to gain unauthorized access.

CVSS2: 7.5
4%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1429

Buffer overflow in mcedit in Midnight Commander 4.5.1 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted text file.

CVSS2: 4.6
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1428

The (1) FTP and (2) Telnet services in Beck GmbH IPC@Chip are shipped with a default password, which allows remote attackers to gain unauthorized access.

CVSS2: 7.5
3%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1427

Unknown vulnerability in ColdFusion Server 2.0 through 4.5.1 SP2 allows remote attackers to overwrite templates with zero byte files via unknown attack vectors.

CVSS2: 7.5
2%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-1426

Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 has a TFTP server running without a password, which allows remote attackers to change firmware versions or the device's configurations.

CVSS2: 7.5
2%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1425

The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login.

CVSS2: 7.5
4%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1424

Alcatel Speed Touch ADSL modem running firmware KHDSAA.108, KHDSAA.132, KHDSBA.133, and KHDSAA.134 has a blank default password, which allows remote attackers to gain unauthorized access.

CVSS2: 7.5
4%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1423

Advanced Poll before 1.61, when using a flat file database, allows remote attackers to gain privileges by setting the logged_in parameter.

CVSS2: 7.5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1422

WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.

CVSS2: 7.5
2%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1421

AOL Instant Messenger (AIM) 4.7 and earlier allows remote attackers to cause a denial of service (application crash) via a large number of different fonts followed by an HTML HR tag.

CVSS2: 5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1420

AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a long filename, possibly caused by a buffer overflow.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2001-1419

AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<!--" HTML comments.

CVSS2: 5
2%
Низкий
почти 25 лет назад

Уязвимостей на страницу