CSV
173,053 results for "vulnerability" Page 17
CVE-2001-0218

Format string vulnerability in mars_nwe 0.99.pl19 allows remote attackers to execute arbitrary commands.

May 3, 2001 1 affected product(s) NVD
10.0
CVSS
2.3%
EPSS
⚡ 40.7
CVE-2001-0148

The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.

Jun 2, 2001 1 affected product(s) NVD
7.5
CVSS
13.7%
EPSS
⚡ 34.1
CVE-2001-0212

Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.

Jun 2, 2001 1 affected product(s) NVD
7.5
CVSS
13.1%
EPSS
⚡ 33.9
CVE-2001-1325

Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).

Apr 20, 2001 4 affected product(s) NVD
7.5
CVSS
12.4%
EPSS
⚡ 33.7
CVE-2001-0311

Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client.

Jun 2, 2001 2 affected product(s) NVD
4.6
CVSS
48.9%
EPSS
⚡ 33.1
CVE-2001-1398

Masquerading code for Linux kernel before 2.2.19 does not fully check packet lengths in certain cases, which may lead to a vulnerability.

Apr 17, 2001 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2001-0155

Format string vulnerability in VShell SSH gateway 1.0.1 and earlier allows remote attackers to execute arbitrary commands via a user name that contains format string specifiers.

Jun 2, 2001 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2001-0318

Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd).

Jun 2, 2001 1 affected product(s) NVD
7.5
CVSS
0.9%
EPSS
⚡ 30.3
CVE-2001-0193

Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.

May 3, 2001 9 affected product(s) NVD
7.2
CVSS
0.2%
EPSS
⚡ 28.9
CVE-2001-0281

Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.

May 3, 2001 1 affected product(s) NVD
7.2
CVSS
0.5%
EPSS
⚡ 28.9
CVE-2001-0266

Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges.

May 3, 2001 1 affected product(s) NVD
7.2
CVSS
0.1%
EPSS
⚡ 28.8
CVE-2001-0283

Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.

May 3, 2001 1 affected product(s) NVD
6.4
CVSS
2.7%
EPSS
⚡ 26.4
CVE-2001-0199

Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the HTTP GET request.

May 3, 2001 1 affected product(s) NVD
5.0
CVSS
8.4%
EPSS
⚡ 22.5
CVE-2001-0253

Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.

Jun 2, 2001 1 affected product(s) NVD
5.0
CVSS
7.8%
EPSS
⚡ 22.3
CVE-2001-1391 MEDIUM

Off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory.

Apr 17, 2001 1 affected product(s) NVD
5.5
CVSS
0.2%
EPSS
⚡ 22
CVE-2001-0304

Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request.

May 3, 2001 1 affected product(s) NVD
5.0
CVSS
6.7%
EPSS
⚡ 22
CVE-2001-0228

Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request.

May 3, 2001 2 affected product(s) NVD
5.0
CVSS
5.2%
EPSS
⚡ 21.6
CVE-2001-0217

Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.

Jun 2, 2001 1 affected product(s) NVD
5.0
CVSS
5.3%
EPSS
⚡ 21.6
CVE-2001-0272

Directory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the templ parameter.

May 3, 2001 1 affected product(s) NVD
5.0
CVSS
5.0%
EPSS
⚡ 21.5
CVE-2001-0295

Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." command.

May 3, 2001 1 affected product(s) NVD
5.0
CVSS
4.3%
EPSS
⚡ 21.3