CSV
180,401 results for "vulnerability" Page 26
CVE-2001-0817

Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to modify arbitrary files and gain root privileges via a certain print request.

Dec 6, 2001 5 affected product(s) NVD
10.0
CVSS
10.2%
EPSS
⚡ 43.1
CVE-2001-1196

Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument.

Dec 17, 2001 1 affected product(s) NVD
10.0
CVSS
9.8%
EPSS
⚡ 42.9
CVE-2001-0727

Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability."

Dec 14, 2001 2 affected product(s) NVD
7.5
CVSS
31.0%
EPSS
⚡ 39.3
CVE-2001-0542

Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.

Dec 20, 2001 2 affected product(s) NVD
7.5
CVSS
13.6%
EPSS
⚡ 34.1
CVE-2001-0722

Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."

Dec 6, 2001 2 affected product(s) NVD
6.4
CVSS
27.6%
EPSS
⚡ 33.9
CVE-2001-0724

Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing Vulnerability variant" of CVE-2001-0664.

Nov 14, 2001 1 affected product(s) NVD
7.5
CVSS
12.3%
EPSS
⚡ 33.7
CVE-2001-1199

Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter.

Dec 17, 2001 32 affected product(s) NVD
7.5
CVSS
8.7%
EPSS
⚡ 32.6
CVE-2001-0857

Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter.

Dec 6, 2001 1 affected product(s) NVD
7.5
CVSS
7.9%
EPSS
⚡ 32.4
CVE-2001-0838

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

Dec 6, 2001 1 affected product(s) NVD
7.5
CVSS
7.0%
EPSS
⚡ 32.1
CVE-2001-0931

Directory traversal vulnerability in Cooolsoft PowerFTP Server 2.03 allows attackers to list or read arbitrary files and directories via a .. (dot dot) in (1) LS or (2) GET.

Nov 28, 2001 1 affected product(s) NVD
7.5
CVSS
4.3%
EPSS
⚡ 31.3
CVE-2001-0844

Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter.

Dec 6, 2001 2 affected product(s) NVD
7.5
CVSS
3.6%
EPSS
⚡ 31.1
CVE-2001-0835

Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.

Dec 6, 2001 1 affected product(s) NVD
7.5
CVSS
3.4%
EPSS
⚡ 31
CVE-2001-0913

Format string vulnerability in Network Solutions Rwhoisd 1.5.7.2 and earlier, when using syslog, allows remote attackers to corrupt memory and possibly execute arbitrary code via a rwhois request that contains format specifiers.

Nov 22, 2001 9 affected product(s) NVD
7.5
CVSS
2.9%
EPSS
⚡ 30.9
CVE-2001-0927

Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitrary code via an argument that contains format specifiers that are passed into the (1) syslog_message and (2) syslog_io_message functions.

Nov 27, 2001 4 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2001-0841

Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.

Dec 6, 2001 1 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2001-0842

Directory traversal vulnerability in Search.cgi in Leoboard LB5000 LB5000II 1029 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.

Dec 6, 2001 1 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2001-0948

Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the certificate is viewed.

Dec 4, 2001 11 affected product(s) NVD
7.5
CVSS
2.3%
EPSS
⚡ 30.7
CVE-2001-0824

Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.

Dec 6, 2001 2 affected product(s) NVD
7.5
CVSS
2.3%
EPSS
⚡ 30.7
CVE-2001-1350

Cross-site scripting vulnerability in namazu.cgi for Namazu 2.0.7 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the lang parameter.

Nov 25, 2001 1 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2001-0935

Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CVE-2001-0550.

Nov 28, 2001 3 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.4