CSV
180,320 results for "vulnerability" Page 21
CVE-2001-0609 CRITICAL

Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.

Aug 2, 2001 1 affected product(s) NVD
9.8
CVSS
18.2%
EPSS
⚡ 44.7
CVE-2001-1264

Vulnerability in mkacct in HP-UX 11.04 running Virtualvault Operating System (VVOS) 4.0 and 4.5 allows attackers to elevate privileges.

Jul 19, 2001 3 affected product(s) NVD
10.0
CVSS
3.9%
EPSS
⚡ 41.2
CVE-2001-1363

Vulnerability in phpWebSite before 0.7.9 related to running multiple instances in the same domain, which may allow attackers to gain administrative privileges.

Jul 19, 2001 1 affected product(s) NVD
10.0
CVSS
1.5%
EPSS
⚡ 40.4
CVE-2001-0504

Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activities such as mail relaying.

Aug 14, 2001 1 affected product(s) NVD
7.5
CVSS
21.1%
EPSS
⚡ 36.3
CVE-2001-0347

Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.

Jul 21, 2001 1 affected product(s) NVD
7.5
CVSS
13.8%
EPSS
⚡ 34.1
CVE-2001-0522

Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.

Aug 14, 2001 3 affected product(s) NVD
7.5
CVSS
13.7%
EPSS
⚡ 34.1
CVE-2001-0561

Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.

Aug 14, 2001 2 affected product(s) NVD
7.5
CVSS
12.5%
EPSS
⚡ 33.8
CVE-2001-1022

Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.

Jul 26, 2001 7 affected product(s) NVD
7.5
CVSS
11.4%
EPSS
⚡ 33.4
CVE-2001-0987

Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by causing the Javascript to be inserted into error messages that are generated by CGIWrap.

Jul 22, 2001 1 affected product(s) NVD
7.5
CVSS
7.2%
EPSS
⚡ 32.2
CVE-2001-0991

Cross-site scripting vulnerability in Proxomitron Naoko-4 BetaFour and earlier allows remote attackers to execute arbitrary script on other clients via an incorrect URL containing the malicious script, which is printed back in an error message.

Jul 24, 2001 4 affected product(s) NVD
7.5
CVSS
7.1%
EPSS
⚡ 32.1
CVE-2001-1279

Buffer overflow in print-rx.c of tcpdump 3.x (probably 3.6x) allows remote attackers to cause a denial of service and possibly execute arbitrary code via AFS RPC packets with invalid lengths that trigger an integer signedness error, a different vulnerability than CVE-2000-1026.

Jul 17, 2001 1 affected product(s) NVD
7.5
CVSS
4.8%
EPSS
⚡ 31.4
CVE-2001-1265

Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary files via a .. (dot dot) attack.

Jul 20, 2001 1 affected product(s) NVD
7.5
CVSS
4.2%
EPSS
⚡ 31.3
CVE-2001-1242

Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form.

Jul 17, 2001 12 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2001-1176

Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via format strings in the control connection.

Jul 12, 2001 11 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2001-1108

Directory traversal vulnerability in SnapStream PVS 1.2a allows remote attackers to read arbitrary files via a .. (dot dot) attack in the requested URL.

Jul 26, 2001 1 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2001-1427

Unknown vulnerability in ColdFusion Server 2.0 through 4.5.1 SP2 allows remote attackers to overwrite templates with zero byte files via unknown attack vectors.

Jul 11, 2001 12 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2001-1257

Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email.

Jul 21, 2001 7 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2001-1361

Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links.

Jul 19, 2001 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2001-1362

Vulnerability in the server for nPULSE before 0.53p4.

Jul 19, 2001 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.3
CVE-2001-1364

Vulnerability in autodns.pl for AutoDNS before 0.0.4 related to domain names that are not fully qualified.

Jul 19, 2001 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3