CSV
180,401 results for "vulnerability" Page 27
CVE-2001-1196

Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument.

Dec 17, 2001 1 affected product(s) NVD
10.0
CVSS
9.8%
EPSS
⚡ 42.9
CVE-2001-1440

Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.

Dec 21, 2001 1 affected product(s) NVD
10.0
CVSS
5.0%
EPSS
⚡ 41.5
CVE-2001-0727

Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability."

Dec 14, 2001 2 affected product(s) NVD
7.5
CVSS
31.0%
EPSS
⚡ 39.3
CVE-2001-1217

Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.

Dec 21, 2001 1 affected product(s) NVD
5.0
CVSS
54.4%
EPSS
⚡ 36.3
CVE-2001-0542

Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.

Dec 20, 2001 2 affected product(s) NVD
7.5
CVSS
13.6%
EPSS
⚡ 34.1
CVE-2001-1199

Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter.

Dec 17, 2001 32 affected product(s) NVD
7.5
CVSS
8.7%
EPSS
⚡ 32.6
CVE-2001-0857

Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter.

Dec 6, 2001 1 affected product(s) NVD
7.5
CVSS
7.9%
EPSS
⚡ 32.4
CVE-2001-1432

Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Dec 29, 2001 7 affected product(s) NVD
7.8
CVSS
4.1%
EPSS
⚡ 32.4
CVE-2001-0838

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

Dec 6, 2001 1 affected product(s) NVD
7.5
CVSS
7.0%
EPSS
⚡ 32.1
CVE-2001-1202

Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error.

Dec 28, 2001 4 affected product(s) NVD
7.5
CVSS
6.7%
EPSS
⚡ 32
CVE-2001-0844

Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter.

Dec 6, 2001 2 affected product(s) NVD
7.5
CVSS
3.6%
EPSS
⚡ 31.1
CVE-2001-0835

Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.

Dec 6, 2001 1 affected product(s) NVD
7.5
CVSS
3.4%
EPSS
⚡ 31
CVE-2001-0869

Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow remote attackers to execute arbitrary commands.

Dec 21, 2001 9 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2001-0871

Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor allows remote attackers to execute arbitrary commands via an HTTP request containing (1) a .. in versions 2.0 through 2.6.18, or (2) a DOS device name followed by a .. in versions 2.6.19 through 3.0.10.

Dec 21, 2001 12 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2001-0841

Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.

Dec 6, 2001 1 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2001-0842

Directory traversal vulnerability in Search.cgi in Leoboard LB5000 LB5000II 1029 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.

Dec 6, 2001 1 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2001-1215

Format string vulnerability in PFinger 0.7.5 through 0.7.7 allows remote attackers to execute arbitrary code via format string specifiers in a .plan file.

Dec 20, 2001 3 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2001-1208

Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code.

Dec 31, 2001 4 affected product(s) NVD
7.5
CVSS
2.2%
EPSS
⚡ 30.7
CVE-2001-1351

Cross-site scripting vulnerability in Namazu 2.0.8 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the index file name that is displayed when displaying hit numbers.

Dec 25, 2001 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2001-1352

Cross-site scripting vulnerability in Namazu 2.0.9 and earlier allows remote attackers to execute arbitrary Javascript as other web users via an error message that is returned when an invalid index file is specified in the idxname parameter.

Dec 27, 2001 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5