CSV
180,320 results for "vulnerability" Page 22
CVE-2001-0609 CRITICAL

Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.

Aug 2, 2001 1 affected product(s) NVD
9.8
CVSS
18.2%
EPSS
⚡ 44.7
CVE-2001-0966

Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the CD (CWD) command.

Aug 31, 2001 1 affected product(s) NVD
10.0
CVSS
3.0%
EPSS
⚡ 40.9
CVE-2001-1061

Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.

Aug 31, 2001 1 affected product(s) NVD
10.0
CVSS
1.8%
EPSS
⚡ 40.6
CVE-2001-0504

Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activities such as mail relaying.

Aug 14, 2001 1 affected product(s) NVD
7.5
CVSS
21.1%
EPSS
⚡ 36.3
CVE-2001-0347

Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.

Jul 21, 2001 1 affected product(s) NVD
7.5
CVSS
13.8%
EPSS
⚡ 34.1
CVE-2001-0522

Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.

Aug 14, 2001 3 affected product(s) NVD
7.5
CVSS
13.7%
EPSS
⚡ 34.1
CVE-2001-0561

Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.

Aug 14, 2001 2 affected product(s) NVD
7.5
CVSS
12.5%
EPSS
⚡ 33.8
CVE-2001-1022

Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.

Jul 26, 2001 7 affected product(s) NVD
7.5
CVSS
11.4%
EPSS
⚡ 33.4
CVE-2001-1138

Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter.

Sep 7, 2001 1 affected product(s) NVD
7.5
CVSS
10.3%
EPSS
⚡ 33.1
CVE-2001-0987

Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by causing the Javascript to be inserted into error messages that are generated by CGIWrap.

Jul 22, 2001 1 affected product(s) NVD
7.5
CVSS
7.2%
EPSS
⚡ 32.2
CVE-2001-0991

Cross-site scripting vulnerability in Proxomitron Naoko-4 BetaFour and earlier allows remote attackers to execute arbitrary script on other clients via an incorrect URL containing the malicious script, which is printed back in an error message.

Jul 24, 2001 4 affected product(s) NVD
7.5
CVSS
7.1%
EPSS
⚡ 32.1
CVE-2001-0591

Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack.

Aug 22, 2001 2 affected product(s) NVD
7.5
CVSS
4.0%
EPSS
⚡ 31.2
CVE-2001-0970

Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script.

Aug 31, 2001 1 affected product(s) NVD
7.5
CVSS
3.4%
EPSS
⚡ 31
CVE-2001-1108

Directory traversal vulnerability in SnapStream PVS 1.2a allows remote attackers to read arbitrary files via a .. (dot dot) attack in the requested URL.

Jul 26, 2001 1 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2001-1257

Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email.

Jul 21, 2001 7 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2001-1016

PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which has already been signed by the third party, aka the "PGPsdk Key Validity Vulnerability."

Sep 4, 2001 8 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2001-0349

Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.

Jul 21, 2001 1 affected product(s) NVD
7.2
CVSS
1.9%
EPSS
⚡ 29.4
CVE-2001-0976

Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables.

Aug 31, 2001 1 affected product(s) NVD
7.2
CVSS
0.5%
EPSS
⚡ 29
CVE-2001-1173

Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases.

Jul 26, 2001 30 affected product(s) NVD
7.2
CVSS
0.3%
EPSS
⚡ 28.9
CVE-2001-1012

Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/.

Sep 5, 2001 5 affected product(s) NVD
7.2
CVSS
0.3%
EPSS
⚡ 28.9