Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 395 079

Количество 395 079

nvd логотип

CVE-2001-0843

почти 25 лет назад

Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0842

почти 25 лет назад

Directory traversal vulnerability in Search.cgi in Leoboard LB5000 LB5000II 1029 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0841

почти 25 лет назад

Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0840

почти 25 лет назад

Buffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-0839

почти 25 лет назад

ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0838

почти 25 лет назад

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0837

почти 25 лет назад

DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-readable locations in the installation directory, which allows local users to read the information in (1) temp.html, (2) the log folder, and (3) the PhoneBook folder.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-0836

почти 25 лет назад

Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2001-0835

почти 25 лет назад

Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0834

почти 25 лет назад

htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2001-0833

почти 25 лет назад

Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0832

почти 25 лет назад

Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability."

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-0831

почти 25 лет назад

Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-0830

почти 25 лет назад

6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to and disconnecting from the server.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0829

почти 25 лет назад

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2001-0828

почти 25 лет назад

A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which causes an error message that does not properly quote the Javascript.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2001-0827

почти 25 лет назад

Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0826

почти 25 лет назад

Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0825

почти 25 лет назад

Buffer overflow in internal string handling routines of xinetd before 2.1.8.8 allows remote attackers to execute arbitrary commands via a length argument of zero or less, which disables the length check.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-0824

почти 25 лет назад

Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-0843

Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request.

CVSS2: 5
3%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0842

Directory traversal vulnerability in Search.cgi in Leoboard LB5000 LB5000II 1029 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.

CVSS2: 7.5
3%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0841

Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.

CVSS2: 7.5
3%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0840

Buffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI.

CVSS2: 10
9%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0839

ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing.

CVSS2: 7.5
7%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0838

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

CVSS2: 7.5
7%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0837

DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-readable locations in the installation directory, which allows local users to read the information in (1) temp.html, (2) the log folder, and (3) the PhoneBook folder.

CVSS2: 2.1
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0836

Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.

CVSS2: 7.5
15%
Средний
почти 25 лет назад
nvd логотип
CVE-2001-0835

Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.

CVSS2: 7.5
3%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0834

htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file.

CVSS2: 6.4
3%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0833

Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."

CVSS2: 7.2
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0832

Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability."

CVSS2: 2.1
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0831

Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.

CVSS2: 4.6
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0830

6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to and disconnecting from the server.

CVSS3: 7.5
6%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0829

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

CVSS2: 5.1
12%
Средний
почти 25 лет назад
nvd логотип
CVE-2001-0828

A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which causes an error message that does not properly quote the Javascript.

CVSS2: 5.1
3%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0827

Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.

CVSS3: 7.5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0826

Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD.

CVSS2: 7.5
4%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0825

Buffer overflow in internal string handling routines of xinetd before 2.1.8.8 allows remote attackers to execute arbitrary commands via a length argument of zero or less, which disables the length check.

CVSS2: 10
4%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-0824

Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.

CVSS2: 7.5
2%
Низкий
почти 25 лет назад

Уязвимостей на страницу