CSV
180,320 results for "vulnerability" Page 17
CVE-2001-0218

Format string vulnerability in mars_nwe 0.99.pl19 allows remote attackers to execute arbitrary commands.

May 3, 2001 1 affected product(s) NVD
10.0
CVSS
3.5%
EPSS
⚡ 41.1
CVE-2001-1325

Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).

Apr 20, 2001 4 affected product(s) NVD
7.5
CVSS
27.3%
EPSS
⚡ 38.2
CVE-2001-0148

The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.

Jun 2, 2001 1 affected product(s) NVD
7.5
CVSS
26.8%
EPSS
⚡ 38
CVE-2001-0212

Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.

Jun 2, 2001 1 affected product(s) NVD
7.5
CVSS
17.0%
EPSS
⚡ 35.1
CVE-2001-0318

Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd).

Jun 2, 2001 1 affected product(s) NVD
7.5
CVSS
11.4%
EPSS
⚡ 33.4
CVE-2001-1398

Masquerading code for Linux kernel before 2.2.19 does not fully check packet lengths in certain cases, which may lead to a vulnerability.

Apr 17, 2001 1 affected product(s) NVD
7.5
CVSS
2.9%
EPSS
⚡ 30.9
CVE-2001-0155

Format string vulnerability in VShell SSH gateway 1.0.1 and earlier allows remote attackers to execute arbitrary commands via a user name that contains format string specifiers.

Jun 2, 2001 1 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2001-0281

Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.

May 3, 2001 1 affected product(s) NVD
7.2
CVSS
4.8%
EPSS
⚡ 30.2
CVE-2001-0193

Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.

May 3, 2001 9 affected product(s) NVD
7.2
CVSS
1.1%
EPSS
⚡ 29.1
CVE-2001-0266

Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges.

May 3, 2001 1 affected product(s) NVD
7.2
CVSS
0.5%
EPSS
⚡ 29
CVE-2001-0283

Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.

May 3, 2001 1 affected product(s) NVD
6.4
CVSS
6.0%
EPSS
⚡ 27.4
CVE-2001-0205

Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested pathname, a modified .. (dot dot) attack.

May 3, 2001 1 affected product(s) NVD
5.0
CVSS
23.6%
EPSS
⚡ 27.1
CVE-2001-0199

Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the HTTP GET request.

May 3, 2001 1 affected product(s) NVD
5.0
CVSS
10.8%
EPSS
⚡ 23.2
CVE-2001-0253

Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.

Jun 2, 2001 1 affected product(s) NVD
5.0
CVSS
10.6%
EPSS
⚡ 23.2
CVE-2001-1335

Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contains a ...%5c (modified dot dot).

May 27, 2001 1 affected product(s) NVD
5.0
CVSS
8.2%
EPSS
⚡ 22.5
CVE-2001-0295

Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." command.

May 3, 2001 1 affected product(s) NVD
5.0
CVSS
8.1%
EPSS
⚡ 22.4
CVE-2001-1391 MEDIUM

Off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory.

Apr 17, 2001 1 affected product(s) NVD
5.5
CVSS
0.4%
EPSS
⚡ 22.1
CVE-2001-0206

Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into the requested pathname of an HTTP GET request.

Jun 2, 2001 1 affected product(s) NVD
5.0
CVSS
6.7%
EPSS
⚡ 22
CVE-2001-0210

Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page parameter.

Jun 2, 2001 1 affected product(s) NVD
5.0
CVSS
6.5%
EPSS
⚡ 22
CVE-2001-0211

Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.

Jun 2, 2001 1 affected product(s) NVD
5.0
CVSS
6.5%
EPSS
⚡ 22