CSV
180,323 results for "vulnerability" Page 23
CVE-2001-0966

Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the CD (CWD) command.

Aug 31, 2001 1 affected product(s) NVD
10.0
CVSS
3.0%
EPSS
⚡ 40.9
CVE-2001-1061

Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.

Aug 31, 2001 1 affected product(s) NVD
10.0
CVSS
1.8%
EPSS
⚡ 40.6
CVE-2001-0506

Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.

Sep 20, 2001 2 affected product(s) NVD
7.2
CVSS
30.0%
EPSS
⚡ 37.8
CVE-2001-0658

Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message.

Sep 20, 2001 1 affected product(s) NVD
7.5
CVSS
14.2%
EPSS
⚡ 34.3
CVE-2001-0690

Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers.

Sep 20, 2001 4 affected product(s) NVD
7.5
CVSS
11.9%
EPSS
⚡ 33.6
CVE-2001-1138

Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter.

Sep 7, 2001 1 affected product(s) NVD
7.5
CVSS
10.3%
EPSS
⚡ 33.1
CVE-2001-1109

Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.

Sep 12, 2001 1 affected product(s) NVD
7.5
CVSS
8.0%
EPSS
⚡ 32.4
CVE-2001-0591

Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack.

Aug 22, 2001 2 affected product(s) NVD
7.5
CVSS
4.0%
EPSS
⚡ 31.2
CVE-2001-0970

Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script.

Aug 31, 2001 1 affected product(s) NVD
7.5
CVSS
3.4%
EPSS
⚡ 31
CVE-2001-0963

Directory traversal vulnerability in SpoonFTP 1.1 allows local and sometimes remote attackers to access files outside of the FTP root via a ... (modified dot dot) in the CD (CWD) command.

Sep 20, 2001 1 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2001-0694

Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.

Sep 20, 2001 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2001-1016

PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which has already been signed by the third party, aka the "PGPsdk Key Validity Vulnerability."

Sep 4, 2001 8 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2001-0689

Vulnerability in TrendMicro Virus Control System 1.8 allows a remote attacker to view configuration files and change the configuration via a certain CGI program.

Sep 20, 2001 1 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2001-0507

IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.

Sep 20, 2001 1 affected product(s) NVD
7.2
CVSS
4.4%
EPSS
⚡ 30.1
CVE-2001-0976

Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables.

Aug 31, 2001 1 affected product(s) NVD
7.2
CVSS
0.5%
EPSS
⚡ 29
CVE-2001-1123

Vulnerability in Network Node Manager (NNM) 6.2 and earlier in HP OpenView allows a local user to execute arbitrary code, possibly via a buffer overflow in a long hostname or object ID.

Oct 1, 2001 3 affected product(s) NVD
7.2
CVSS
0.8%
EPSS
⚡ 29
CVE-2001-1012

Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/.

Sep 5, 2001 5 affected product(s) NVD
7.2
CVSS
0.3%
EPSS
⚡ 28.9
CVE-2001-1034

Format string vulnerability in Hylafax on FreeBSD allows local users to execute arbitrary code via format specifiers in the -h hostname argument for (1) faxrm or (2) faxalter.

Sep 23, 2001 1 affected product(s) NVD
7.2
CVSS
0.5%
EPSS
⚡ 28.9
CVE-2001-0508

Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.

Sep 20, 2001 1 affected product(s) NVD
5.0
CVSS
25.2%
EPSS
⚡ 27.6
CVE-2001-0571

Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the requested URL.

Aug 22, 2001 2 affected product(s) NVD
5.0
CVSS
8.3%
EPSS
⚡ 22.5