CSV
173,080 results for "vulnerability" Page 18
CVE-2001-0333 Exploit

Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.

Jun 27, 2001 2 affected product(s) NVD
7.5
CVSS
84.6%
EPSS
⚡ 65.4
CVE-2001-1162

Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.

Jun 23, 2001 8 affected product(s) NVD
10.0
CVSS
32.2%
EPSS
⚡ 49.7
CVE-2001-1078

Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.

Jun 21, 2001 14 affected product(s) NVD
10.0
CVSS
11.2%
EPSS
⚡ 43.4
CVE-2001-0339

Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."

Jun 27, 2001 1 affected product(s) NVD
7.5
CVSS
18.4%
EPSS
⚡ 35.5
CVE-2001-0148

The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.

Jun 2, 2001 1 affected product(s) NVD
7.5
CVSS
13.7%
EPSS
⚡ 34.1
CVE-2001-0212

Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.

Jun 2, 2001 1 affected product(s) NVD
7.5
CVSS
13.1%
EPSS
⚡ 33.9
CVE-2001-0242

Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed in MS:MS00-090.

Jun 27, 2001 3 affected product(s) NVD
7.5
CVSS
12.7%
EPSS
⚡ 33.8
CVE-2001-0311

Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client.

Jun 2, 2001 2 affected product(s) NVD
4.6
CVSS
48.9%
EPSS
⚡ 33.1
CVE-2001-0245

Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.

Jun 27, 2001 2 affected product(s) NVD
5.0
CVSS
37.4%
EPSS
⚡ 31.2
CVE-2001-0359

Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.

Jun 27, 2001 2 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.6
CVE-2001-0155

Format string vulnerability in VShell SSH gateway 1.0.1 and earlier allows remote attackers to execute arbitrary commands via a user name that contains format string specifiers.

Jun 2, 2001 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2001-0318

Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd).

Jun 2, 2001 1 affected product(s) NVD
7.5
CVSS
0.9%
EPSS
⚡ 30.3
CVE-2001-0450

Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name.

Jun 27, 2001 1 affected product(s) NVD
6.4
CVSS
1.5%
EPSS
⚡ 26.1
CVE-2001-0246

Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability.

Jun 27, 2001 2 affected product(s) NVD
5.0
CVSS
18.8%
EPSS
⚡ 25.6
CVE-2001-0332

Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.

Jun 27, 2001 2 affected product(s) NVD
5.0
CVSS
18.1%
EPSS
⚡ 25.4
CVE-2001-0253

Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.

Jun 2, 2001 1 affected product(s) NVD
5.0
CVSS
7.8%
EPSS
⚡ 22.3
CVE-2001-0304

Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request.

May 3, 2001 1 affected product(s) NVD
5.0
CVSS
6.7%
EPSS
⚡ 22
CVE-2001-0462

Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Jun 27, 2001 8 affected product(s) NVD
5.0
CVSS
6.2%
EPSS
⚡ 21.9
CVE-2001-0217

Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.

Jun 2, 2001 1 affected product(s) NVD
5.0
CVSS
5.3%
EPSS
⚡ 21.6
CVE-2001-0295

Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." command.

May 3, 2001 1 affected product(s) NVD
5.0
CVSS
4.3%
EPSS
⚡ 21.3