CSV
180,399 results for "vulnerability" Page 24
CVE-2001-0789

Format string vulnerability in avpkeeper in Kaspersky KAV 3.5.135.2 for Sendmail allows remote attackers to cause a denial of service or possibly execute arbitrary code via a malformed mail message.

Oct 18, 2001 1 affected product(s) NVD
10.0
CVSS
7.2%
EPSS
⚡ 42.2
CVE-2001-0717

Format string vulnerability in ToolTalk database server rpc.ttdbserverd allows remote attackers to execute arbitrary commands via format string specifiers that are passed to the syslog function.

Oct 30, 2001 1 affected product(s) NVD
10.0
CVSS
5.7%
EPSS
⚡ 41.7
CVE-2001-0506

Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.

Sep 20, 2001 2 affected product(s) NVD
7.2
CVSS
30.0%
EPSS
⚡ 37.8
CVE-2001-0664

Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing vulnerability."

Oct 30, 2001 2 affected product(s) NVD
7.5
CVSS
18.2%
EPSS
⚡ 35.5
CVE-2001-0658

Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message.

Sep 20, 2001 1 affected product(s) NVD
7.5
CVSS
14.2%
EPSS
⚡ 34.3
CVE-2001-0690

Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers.

Sep 20, 2001 4 affected product(s) NVD
7.5
CVSS
11.9%
EPSS
⚡ 33.6
CVE-2001-0665

Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP Request Encoding vulnerability."

Oct 30, 2001 1 affected product(s) NVD
7.5
CVSS
12.1%
EPSS
⚡ 33.6
CVE-2001-0667 HIGH

Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150.

Oct 30, 2001 1 affected product(s) NVD
7.3
CVSS
14.7%
EPSS
⚡ 33.6
CVE-2001-0718

Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.

Oct 30, 2001 2 affected product(s) NVD
7.5
CVSS
11.1%
EPSS
⚡ 33.3
CVE-2001-1109

Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.

Sep 12, 2001 1 affected product(s) NVD
7.5
CVSS
8.0%
EPSS
⚡ 32.4
CVE-2001-0758

Directory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via "CWD ..." command.

Oct 18, 2001 1 affected product(s) NVD
7.5
CVSS
4.2%
EPSS
⚡ 31.3
CVE-2001-1460

SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter.

Oct 13, 2001 3 affected product(s) NVD
7.5
CVSS
3.3%
EPSS
⚡ 31
CVE-2001-0792

Format string vulnerability in XChat 1.2.x allows remote attackers to execute arbitrary code via a malformed nickname.

Oct 18, 2001 1 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2001-0963

Directory traversal vulnerability in SpoonFTP 1.1 allows local and sometimes remote attackers to access files outside of the FTP root via a ... (modified dot dot) in the CD (CWD) command.

Sep 20, 2001 1 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2001-1297

PHP remote file inclusion vulnerability in Actionpoll PHP script before 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter.

Oct 2, 2001 1 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2001-0694

Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.

Sep 20, 2001 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2001-1461

Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to access restricted resources via URL-encoded (1) /.. or (2) \.. sequences.

Oct 22, 2001 1 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2001-0689

Vulnerability in TrendMicro Virus Control System 1.8 allows a remote attacker to view configuration files and change the configuration via a certain CGI program.

Sep 20, 2001 1 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2001-0507

IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.

Sep 20, 2001 1 affected product(s) NVD
7.2
CVSS
4.4%
EPSS
⚡ 30.1
CVE-2001-1123

Vulnerability in Network Node Manager (NNM) 6.2 and earlier in HP OpenView allows a local user to execute arbitrary code, possibly via a buffer overflow in a long hostname or object ID.

Oct 1, 2001 3 affected product(s) NVD
7.2
CVSS
0.8%
EPSS
⚡ 29