Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 395 079

Количество 395 079

nvd логотип

CVE-2001-0572

около 25 лет назад

The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker to obtain the following information via sniffing: (1) password lengths or ranges of lengths, which simplifies brute force password guessing, (2) whether RSA or DSA authentication is being used, (3) the number of authorized_keys in RSA authentication, or (4) the lengths of shell commands.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0571

около 25 лет назад

Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the requested URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0570

около 25 лет назад

minicom 1.83.1 and earlier allows a local attacker to gain additional privileges via numerous format string attacks.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0569

около 25 лет назад

Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) ObjectManager, (2) PropertyManager, and (3) PropertySheet.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-0568

около 25 лет назад

Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-0567

около 25 лет назад

Digital Creations Zope 2.3.2 and earlier allows a local attacker to gain additional privileges via the changing of ZClass permission mappings for objects and methods in the ZClass.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-0566

около 25 лет назад

Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disabled.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0565

около 25 лет назад

Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-0564

около 25 лет назад

APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of service via repeated failed logon attempts which temporarily locks the card.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0563

около 25 лет назад

ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via large (> 160000 character) strings sent to port 23.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0562

около 25 лет назад

a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-0561

около 25 лет назад

Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2001-0560

около 25 лет назад

Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters).

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-0559

около 25 лет назад

crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0558

около 25 лет назад

T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-0557

около 25 лет назад

T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2001-0556

около 25 лет назад

The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users' files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2001-0555

около 25 лет назад

ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITEWare Editor's Desktop or (2) the template parameter in SWEditServlet.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2001-0554

около 25 лет назад

Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2001-0553

около 25 лет назад

SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field.

CVSS2: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-0572

The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker to obtain the following information via sniffing: (1) password lengths or ranges of lengths, which simplifies brute force password guessing, (2) whether RSA or DSA authentication is being used, (3) the number of authorized_keys in RSA authentication, or (4) the lengths of shell commands.

CVSS2: 7.5
7%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0571

Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the requested URL.

CVSS2: 5
8%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0570

minicom 1.83.1 and earlier allows a local attacker to gain additional privileges via numerous format string attacks.

CVSS2: 7.2
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0569

Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) ObjectManager, (2) PropertyManager, and (3) PropertySheet.

CVSS2: 2.1
0%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0568

Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes.

CVSS2: 2.1
0%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0567

Digital Creations Zope 2.3.2 and earlier allows a local attacker to gain additional privileges via the changing of ZClass permission mappings for objects and methods in the ZClass.

CVSS2: 4.6
0%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0566

Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disabled.

CVSS2: 5
6%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0565

Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.

CVSS2: 4.6
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0564

APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of service via repeated failed logon attempts which temporarily locks the card.

CVSS2: 5
3%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0563

ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via large (> 160000 character) strings sent to port 23.

CVSS2: 5
7%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0562

a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters.

CVSS2: 7.5
4%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0561

Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.

CVSS2: 7.5
13%
Средний
около 25 лет назад
nvd логотип
CVE-2001-0560

Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters).

CVSS2: 4.6
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0559

crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.

CVSS2: 7.2
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0558

T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0).

CVSS2: 5
7%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0557

T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).

CVSS2: 5
11%
Средний
около 25 лет назад
nvd логотип
CVE-2001-0556

The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users' files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file.

CVSS2: 7.2
1%
Низкий
около 25 лет назад
nvd логотип
CVE-2001-0555

ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITEWare Editor's Desktop or (2) the template parameter in SWEditServlet.

CVSS2: 10
15%
Средний
около 25 лет назад
nvd логотип
CVE-2001-0554

Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.

CVSS2: 10
39%
Средний
около 25 лет назад
nvd логотип
CVE-2001-0553

SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field.

CVSS2: 7.2
1%
Низкий
около 25 лет назад

Уязвимостей на страницу