CSV
180,320 results for "vulnerability" Page 19
CVE-2001-0333 Exploit

Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.

Jun 27, 2001 2 affected product(s) NVD
7.5
CVSS
90.8%
EPSS
⚡ 67.2
CVE-2001-1162

Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.

Jun 23, 2001 8 affected product(s) NVD
10.0
CVSS
12.0%
EPSS
⚡ 43.6
CVE-2001-1078

Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.

Jun 21, 2001 14 affected product(s) NVD
10.0
CVSS
5.4%
EPSS
⚡ 41.6
CVE-2001-0431

Vulnerability in iPlanet Web Server Enterprise Edition 4.x.

Jul 2, 2001 1 affected product(s) NVD
10.0
CVSS
1.5%
EPSS
⚡ 40.5
CVE-2001-0242

Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed in MS:MS00-090.

Jun 27, 2001 3 affected product(s) NVD
7.5
CVSS
30.0%
EPSS
⚡ 39
CVE-2001-0339

Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."

Jun 27, 2001 1 affected product(s) NVD
7.5
CVSS
15.0%
EPSS
⚡ 34.5
CVE-2001-0479

Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.

Jun 27, 2001 2 affected product(s) NVD
7.5
CVSS
5.9%
EPSS
⚡ 31.8
CVE-2001-0478

Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.

Jun 27, 2001 1 affected product(s) NVD
7.5
CVSS
4.8%
EPSS
⚡ 31.4
CVE-2001-0477

Vulnerability in WebCalendar 0.9.26 allows remote command execution.

Jun 27, 2001 12 affected product(s) NVD
7.5
CVSS
4.0%
EPSS
⚡ 31.2
CVE-2001-1161

Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.

Jul 2, 2001 1 affected product(s) NVD
7.5
CVSS
3.6%
EPSS
⚡ 31.1
CVE-2001-1084

Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.

Jul 2, 2001 2 affected product(s) NVD
7.5
CVSS
3.1%
EPSS
⚡ 30.9
CVE-2001-0359

Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.

Jun 27, 2001 2 affected product(s) NVD
7.5
CVSS
2.3%
EPSS
⚡ 30.7
CVE-2001-0473

Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.

Jun 27, 2001 15 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2001-0489

Format string vulnerability in gftp prior to 2.0.8 allows remote malicious FTP servers to execute arbitrary commands.

Jun 27, 2001 1 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2001-0423

Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.

Jul 2, 2001 1 affected product(s) NVD
7.2
CVSS
1.3%
EPSS
⚡ 29.2
CVE-2001-0485

Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option.

Jun 27, 2001 1 affected product(s) NVD
7.2
CVSS
1.2%
EPSS
⚡ 29.1
CVE-2001-0481

Vulnerability in rpmdrake in Mandrake Linux 8.0 related to insecure temporary file handling.

Jun 27, 2001 1 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2001-0387

Format string vulnerability in hfaxd in HylaFAX before 4.1.b2_2 allows local users to gain privileges via the -q command line argument.

Jul 2, 2001 6 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2001-1441

Cross-site scripting (XSS) vulnerability in VisualAge for Java 3.5 Professional allows remote attackers to execute JavaScript on other clients via the URL, which injects the script in the resulting error message.

Jul 2, 2001 1 affected product(s) NVD
6.8
CVSS
2.7%
EPSS
⚡ 28
CVE-2001-0450

Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name.

Jun 27, 2001 1 affected product(s) NVD
6.4
CVSS
1.7%
EPSS
⚡ 26.1