CSV
180,320 results for "vulnerability" Page 14
CVE-2000-1089 Exploit

Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.

Jan 9, 2001 2 affected product(s) NVD
10.0
CVSS
74.6%
EPSS
⚡ 72.4
CVE-2001-0013

Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.

Feb 12, 2001 5 affected product(s) NVD
10.0
CVSS
10.8%
EPSS
⚡ 43.2
CVE-2000-1126

Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service.

Jan 9, 2001 6 affected product(s) NVD
10.0
CVSS
5.8%
EPSS
⚡ 41.7
CVE-2001-0032

Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain root privileges via malicious format string specifiers in a URL.

Feb 16, 2001 1 affected product(s) NVD
10.0
CVSS
4.3%
EPSS
⚡ 41.3
CVE-2001-0060

Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.

Feb 12, 2001 4 affected product(s) NVD
10.0
CVSS
2.8%
EPSS
⚡ 40.8
CVE-2001-0101

Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.

Feb 12, 2001 52 affected product(s) NVD
10.0
CVSS
1.8%
EPSS
⚡ 40.5
CVE-2000-1113

Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the ".ASX Buffer Overrun" vulnerability.

Jan 9, 2001 2 affected product(s) NVD
7.5
CVSS
19.4%
EPSS
⚡ 35.8
CVE-2000-1149

Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the "Terminal Server Login Buffer Overflow" vulnerability.

Jan 9, 2001 1 affected product(s) NVD
7.5
CVSS
16.1%
EPSS
⚡ 34.8
CVE-2000-1104

Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.

Jan 9, 2001 2 affected product(s) NVD
7.5
CVSS
5.6%
EPSS
⚡ 31.7
CVE-2000-1176

Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field.

Jan 9, 2001 1 affected product(s) NVD
7.5
CVSS
5.7%
EPSS
⚡ 31.7
CVE-2000-1139

The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.

Jan 9, 2001 1 affected product(s) NVD
7.5
CVSS
5.0%
EPSS
⚡ 31.5
CVE-2001-1468

PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code.

Feb 7, 2001 14 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2001-0048

The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.

Feb 12, 2001 1 affected product(s) NVD
7.2
CVSS
2.0%
EPSS
⚡ 29.4
CVE-2001-0006 HIGH

The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.

Feb 12, 2001 1 affected product(s) NVD
7.1
CVSS
3.0%
EPSS
⚡ 29.3
CVE-2001-0093

Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.

Feb 12, 2001 1 affected product(s) NVD
7.2
CVSS
0.7%
EPSS
⚡ 29
CVE-2001-0004

IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.

Feb 12, 2001 2 affected product(s) NVD
5.0
CVSS
26.7%
EPSS
⚡ 28
CVE-2001-0096

FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.

Feb 12, 2001 2 affected product(s) NVD
5.0
CVSS
19.1%
EPSS
⚡ 25.7
CVE-2001-0083

Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the "Severed Windows Media Server Connection" vulnerability.

Feb 12, 2001 2 affected product(s) NVD
5.0
CVSS
17.3%
EPSS
⚡ 25.2
CVE-2001-0014

Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.

Feb 12, 2001 1 affected product(s) NVD
5.0
CVSS
13.3%
EPSS
⚡ 24
CVE-2001-0054

Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.

Feb 16, 2001 1 affected product(s) NVD
5.0
CVSS
12.0%
EPSS
⚡ 23.6