CSV
180,403 results for "vulnerability" Page 28
CVE-2001-1583 Exploit

lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability as CVE-2000-1220.

Dec 31, 2001 1 affected product(s) NVD
10.0
CVSS
83.4%
EPSS
⚡ 75
CVE-2001-1440

Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.

Dec 21, 2001 1 affected product(s) NVD
10.0
CVSS
5.0%
EPSS
⚡ 41.5
CVE-2001-1217

Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.

Dec 21, 2001 1 affected product(s) NVD
5.0
CVSS
54.4%
EPSS
⚡ 36.3
CVE-2002-0077

Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the popup object, aka the "Local Executable Invocation via Object tag" vulnerability.

Jan 13, 2002 6 affected product(s) NVD
7.5
CVSS
11.5%
EPSS
⚡ 33.4
CVE-2001-1432

Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Dec 29, 2001 7 affected product(s) NVD
7.8
CVSS
4.1%
EPSS
⚡ 32.4
CVE-2001-1202

Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error.

Dec 28, 2001 4 affected product(s) NVD
7.5
CVSS
6.7%
EPSS
⚡ 32
CVE-2001-1563

Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.

Dec 31, 2001 2 affected product(s) NVD
7.5
CVSS
4.9%
EPSS
⚡ 31.5
CVE-2001-0869

Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow remote attackers to execute arbitrary commands.

Dec 21, 2001 9 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2001-0871

Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor allows remote attackers to execute arbitrary commands via an HTTP request containing (1) a .. in versions 2.0 through 2.6.18, or (2) a DOS device name followed by a .. in versions 2.6.19 through 3.0.10.

Dec 21, 2001 12 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2001-1215

Format string vulnerability in PFinger 0.7.5 through 0.7.7 allows remote attackers to execute arbitrary code via format string specifiers in a .plan file.

Dec 20, 2001 3 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2001-1566

Format string vulnerability in libvanessa_logger 0.0.1 in Perdition 0.1.8 allows remote attackers to execute arbitrary code via format string specifiers in the __vanessa_logger_log function.

Dec 31, 2001 2 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2001-1208

Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code.

Dec 31, 2001 4 affected product(s) NVD
7.5
CVSS
2.2%
EPSS
⚡ 30.7
CVE-2001-1351

Cross-site scripting vulnerability in Namazu 2.0.8 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the index file name that is displayed when displaying hit numbers.

Dec 25, 2001 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2001-1352

Cross-site scripting vulnerability in Namazu 2.0.9 and earlier allows remote attackers to execute arbitrary Javascript as other web users via an error message that is returned when an invalid index file is specified in the idxname parameter.

Dec 27, 2001 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2001-1482

SQL injection vulnerability in bb_memberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL queries via the $sortby variable.

Dec 31, 2001 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2001-1577

Unknown vulnerability in CDE in Caldera OpenUnix 7.1.0, 7.1.1, and 8.0 allows an xterm session to gain privileges when the session is reused.

Dec 31, 2001 3 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2001-1203

Format string vulnerability in gpm-root in gpm 1.17.8 through 1.17.18 allows local users to gain root privileges.

Dec 27, 2001 2 affected product(s) NVD
7.2
CVSS
0.3%
EPSS
⚡ 28.9
CVE-2001-1562

Format string vulnerability in nvi before 1.79 allows local users to gain privileges via format string specifiers in a filename.

Dec 31, 2001 1 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2001-0891

Format string vulnerability in NQS daemon (nqsdaemon) in NQE 3.3.0.16 for CRAY UNICOS and SGI IRIX allows a local user to gain root privileges by using qsub to submit a batch job whose name contains formatting characters.

Jan 31, 2002 2 affected product(s) NVD
7.2
CVSS
0.3%
EPSS
⚡ 28.9
CVE-2001-1512

Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Pages (JSP), a variant of CVE-2000-1050.

Dec 31, 2001 1 affected product(s) NVD
6.4
CVSS
2.1%
EPSS
⚡ 26.2