CSV
180,320 results for "vulnerability" Page 20
CVE-2001-1264

Vulnerability in mkacct in HP-UX 11.04 running Virtualvault Operating System (VVOS) 4.0 and 4.5 allows attackers to elevate privileges.

Jul 19, 2001 3 affected product(s) NVD
10.0
CVSS
3.9%
EPSS
⚡ 41.2
CVE-2001-0431

Vulnerability in iPlanet Web Server Enterprise Edition 4.x.

Jul 2, 2001 1 affected product(s) NVD
10.0
CVSS
1.5%
EPSS
⚡ 40.5
CVE-2001-1363

Vulnerability in phpWebSite before 0.7.9 related to running multiple instances in the same domain, which may allow attackers to gain administrative privileges.

Jul 19, 2001 1 affected product(s) NVD
10.0
CVSS
1.5%
EPSS
⚡ 40.4
CVE-2001-0479

Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.

Jun 27, 2001 2 affected product(s) NVD
7.5
CVSS
5.9%
EPSS
⚡ 31.8
CVE-2001-0478

Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.

Jun 27, 2001 1 affected product(s) NVD
7.5
CVSS
4.8%
EPSS
⚡ 31.4
CVE-2001-1279

Buffer overflow in print-rx.c of tcpdump 3.x (probably 3.6x) allows remote attackers to cause a denial of service and possibly execute arbitrary code via AFS RPC packets with invalid lengths that trigger an integer signedness error, a different vulnerability than CVE-2000-1026.

Jul 17, 2001 1 affected product(s) NVD
7.5
CVSS
4.8%
EPSS
⚡ 31.4
CVE-2001-1265

Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary files via a .. (dot dot) attack.

Jul 20, 2001 1 affected product(s) NVD
7.5
CVSS
4.2%
EPSS
⚡ 31.3
CVE-2001-0477

Vulnerability in WebCalendar 0.9.26 allows remote command execution.

Jun 27, 2001 12 affected product(s) NVD
7.5
CVSS
4.0%
EPSS
⚡ 31.2
CVE-2001-1161

Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.

Jul 2, 2001 1 affected product(s) NVD
7.5
CVSS
3.6%
EPSS
⚡ 31.1
CVE-2001-1084

Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.

Jul 2, 2001 2 affected product(s) NVD
7.5
CVSS
3.1%
EPSS
⚡ 30.9
CVE-2001-1242

Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form.

Jul 17, 2001 12 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2001-1176

Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via format strings in the control connection.

Jul 12, 2001 11 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2001-0473

Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.

Jun 27, 2001 15 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2001-0489

Format string vulnerability in gftp prior to 2.0.8 allows remote malicious FTP servers to execute arbitrary commands.

Jun 27, 2001 1 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2001-1427

Unknown vulnerability in ColdFusion Server 2.0 through 4.5.1 SP2 allows remote attackers to overwrite templates with zero byte files via unknown attack vectors.

Jul 11, 2001 12 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2001-1361

Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links.

Jul 19, 2001 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2001-1362

Vulnerability in the server for nPULSE before 0.53p4.

Jul 19, 2001 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.3
CVE-2001-1364

Vulnerability in autodns.pl for AutoDNS before 0.0.4 related to domain names that are not fully qualified.

Jul 19, 2001 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2001-1365

Vulnerability in IntraGnat before 1.4.

Jul 19, 2001 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2001-0423

Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.

Jul 2, 2001 1 affected product(s) NVD
7.2
CVSS
1.3%
EPSS
⚡ 29.2