|
353151
|
5.0 |
MEDIUM
|
ibm
|
lotus_domino lotus_domino_server
|
Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request wit…
|
NVD-CWE-Other
|
CVE-2001-1567
|
2016-10-18 11:15 |
2001-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353152
|
7.5 |
HIGH
|
mutt
|
mutt
|
Vulnerability in RFC822 address parser in mutt before 1.2.5.1 and mutt 1.3.x before 1.3.25 allows remote attackers to execute arbitrary commands via an improperly terminated comment or phrase in the …
|
NVD-CWE-Other
|
CVE-2002-0001
|
2016-10-18 11:15 |
2002-02-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353153
|
7.5 |
HIGH
|
university_of_washington
|
pine
|
URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&).
|
NVD-CWE-Other
|
CVE-2002-0014
|
2016-10-18 11:15 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353154
|
10.0 |
HIGH
|
andrew_tridgell
|
rsync
|
Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other versions allow remote attackers to cause a denial of service and execute arbitrary…
|
NVD-CWE-Other
|
CVE-2002-0048
|
2016-10-18 11:15 |
2002-02-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353155
|
7.5 |
HIGH
|
squid redhat
|
squid linux
|
Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote attackers to bypass intended access restrictions.
|
NVD-CWE-Other
|
CVE-2002-0067
|
2016-10-18 11:15 |
2002-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353156
|
7.5 |
HIGH
|
squid redhat
|
squid linux
|
Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an ftp:// URL with a larger number of special characters, which…
|
NVD-CWE-Other
|
CVE-2002-0068
|
2016-10-18 11:15 |
2002-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353157
|
2.6 |
LOW
|
squid redhat
|
squid linux
|
Memory leak in SNMP in Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service.
|
NVD-CWE-Other
|
CVE-2002-0069
|
2016-10-18 11:15 |
2002-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353158
|
7.5 |
HIGH
|
php
|
php
|
Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTT…
|
NVD-CWE-Other
|
CVE-2002-0081
|
2016-10-18 11:15 |
2002-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353159
|
4.6 |
MEDIUM
|
ultraedit
|
ultraedit-32
|
UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read the file to decrypt the passwords and gain privileges.
|
NVD-CWE-Other
|
CVE-2001-0983
|
2016-10-18 11:14 |
2001-08-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353160
|
4.6 |
MEDIUM
|
webct
|
respondus
|
Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can read the WEBCT.SVR file to decrypt the passwords and gain additional privileges.
|
NVD-CWE-Other
|
CVE-2001-1003
|
2016-10-18 11:14 |
2001-08-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353161
|
2.1 |
LOW
|
oracle
|
database_server
|
oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory …
|
NVD-CWE-Other
|
CVE-2001-1041
|
2016-10-18 11:14 |
2001-08-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353162
|
10.0 |
HIGH
|
webmin
|
webmin
|
Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument.
|
NVD-CWE-Other
|
CVE-2001-1196
|
2016-10-18 11:14 |
2001-12-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353163
|
7.2 |
HIGH
|
timecop
|
wmcube_gdk
|
Buffer overflow in wmcube-gdk for WMCube/GDK 0.98 allows local users to execute arbitrary code via long lines in the object description file.
|
NVD-CWE-Other
|
CVE-2001-1201
|
2016-10-18 11:14 |
2001-12-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353164
|
7.5 |
HIGH
|
delegate
|
delegate
|
Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on …
|
NVD-CWE-Other
|
CVE-2001-1202
|
2016-10-18 11:14 |
2001-12-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353165
|
5.0 |
MEDIUM
|
matrixs_cgi_vault
|
last_lines
|
Directory traversal vulnerability in lastlines.cgi for Last Lines 2.0 allows remote attackers to read arbitrary files via '..' sequences in the $error_log variable.
|
CWE-22
パス・トラバーサル
|
CVE-2001-1205
|
2016-10-18 11:14 |
2001-12-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353166
|
7.5 |
HIGH
|
matrixs_cgi_vault
|
last_lines
|
Matrix CGI vault Last Lines 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the $error_log variable.
|
NVD-CWE-Other
|
CVE-2001-1206
|
2016-10-18 11:14 |
2001-12-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353167
|
7.5 |
HIGH
|
daydream
|
daydream_bbs
|
Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code.
|
NVD-CWE-Other
|
CVE-2001-1208
|
2016-10-18 11:14 |
2001-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353168
|
7.5 |
HIGH
|
icecast libshout
|
icecast libshout
|
Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2001-1229
|
2016-10-18 11:14 |
2001-03-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353169
|
7.5 |
HIGH
|
icecast
|
icecast
|
Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2001-1230
|
2016-10-18 11:14 |
2001-03-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353170
|
1.2 |
LOW
|
itcorp
|
ispell
|
ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file.
|
NVD-CWE-Other
|
CVE-2001-1276
|
2016-10-18 11:14 |
2001-06-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353171
|
2.1 |
LOW
|
wolfram_schneider
|
makewhatis
|
makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.
|
NVD-CWE-Other
|
CVE-2001-1277
|
2016-10-18 11:14 |
2001-06-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353172
|
5.0 |
MEDIUM
|
mirabilis
|
icq
|
ICQ 2001a Alpha and earlier allows remote attackers to automatically add arbitrary UINs to an ICQ user's contact list via a URL to a web page with a Content-Type of application/x-icq, which is proces…
|
NVD-CWE-Other
|
CVE-2001-1305
|
2016-10-18 11:14 |
2001-08-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353173
|
5.0 |
MEDIUM
|
phpslash
|
phpslash
|
Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.
|
NVD-CWE-Other
|
CVE-2001-1334
|
2016-10-18 11:14 |
2002-05-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353174
|
7.5 |
HIGH
|
namazu
|
namazu
|
Cross-site scripting vulnerability in namazu.cgi for Namazu 2.0.7 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the lang parameter.
|
NVD-CWE-Other
|
CVE-2001-1350
|
2016-10-18 11:14 |
2001-11-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353175
|
2.6 |
LOW
|
aladdin_enterprises
|
ghostscript
|
ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.
|
NVD-CWE-Other
|
CVE-2001-1353
|
2016-10-18 11:14 |
2001-09-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353176
|
10.0 |
HIGH
|
phplib_team
|
phplib
|
prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malic…
|
NVD-CWE-Other
|
CVE-2001-1370
|
2016-10-18 11:14 |
2001-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353177
|
7.5 |
HIGH
|
oracle
|
application_server
|
The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manage…
|
NVD-CWE-noinfo CWE-264
認可・権限・アクセス制御
|
CVE-2001-1371
|
2016-10-18 11:14 |
2002-02-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353178
|
7.2 |
HIGH
|
linux
|
linux_kernel
|
ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or setgid program that itself calls an unprivileged program, su…
|
NVD-CWE-Other
|
CVE-2001-1384
|
2016-10-18 11:14 |
2001-10-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353179
|
5.0 |
MEDIUM
|
php mandrakesoft
|
php mandrake_linux
|
The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the sour…
|
NVD-CWE-Other
|
CVE-2001-1385
|
2016-10-18 11:14 |
2001-01-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353180
|
7.5 |
HIGH
|
xinetd
|
xinetd
|
Multiple vulnerabilities in xinetd 2.3.0 and earlier, and additional variants until 2.3.3, may allow remote attackers to cause a denial of service or execute arbitrary code, primarily via buffer over…
|
NVD-CWE-Other
|
CVE-2001-1389
|
2016-10-18 11:14 |
2001-08-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353181
|
7.5 |
HIGH
|
intel
|
high-bandwidth_digital_content_protection
|
Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new devi…
|
NVD-CWE-Other
|
CVE-2001-0903
|
2016-10-18 11:13 |
2001-11-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353182
|
7.5 |
HIGH
|
network_solutions
|
rwhoisd
|
Format string vulnerability in Network Solutions Rwhoisd 1.5.7.2 and earlier, when using syslog, allows remote attackers to corrupt memory and possibly execute arbitrary code via a rwhois request tha…
|
NVD-CWE-Other
|
CVE-2001-0913
|
2016-10-18 11:13 |
2001-11-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353183
|
7.2 |
HIGH
|
berkeley
|
pmake
|
Format string vulnerability in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via format specifiers in the check argument of a shell definition.
|
NVD-CWE-Other
|
CVE-2001-0915
|
2016-10-18 11:13 |
2001-11-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353184
|
7.2 |
HIGH
|
berkeley
|
pmake
|
Buffer overflow in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via a long check argument of a shell definition.
|
NVD-CWE-Other
|
CVE-2001-0916
|
2016-10-18 11:13 |
2001-11-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353185
|
7.5 |
HIGH
|
gnome
|
libgtop_daemon
|
Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitrary code via an argument that contains format spec…
|
NVD-CWE-Other
|
CVE-2001-0927
|
2016-10-18 11:13 |
2001-11-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353186
|
7.5 |
HIGH
|
gnome
|
libgtop_daemon
|
Buffer overflow in the permitted function of GNOME gtop daemon (libgtop_daemon) in libgtop 1.0.13 and earlier may allow remote attackers to execute arbitrary code via long authentication data.
|
NVD-CWE-Other
|
CVE-2001-0928
|
2016-10-18 11:13 |
2001-11-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353187
|
7.5 |
HIGH
|
sendpage
|
sendpage.pl
|
Sendpage.pl allows remote attackers to execute arbitrary commands via a message containing shell metacharacters.
|
NVD-CWE-Other
|
CVE-2001-0930
|
2016-10-18 11:13 |
2001-11-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353188
|
7.5 |
HIGH
|
cooolsoft
|
powerftp
|
Cooolsoft PowerFTP Server 2.03 allows remote attackers to list the contents of arbitrary drives via a ls (LIST) command that includes the drive letter as an argument, e.g. "ls C:".
|
NVD-CWE-Other
|
CVE-2001-0933
|
2016-10-18 11:13 |
2001-11-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353189
|
7.5 |
HIGH
|
cooolsoft
|
powerftp
|
Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname.
|
NVD-CWE-Other
|
CVE-2001-0934
|
2016-10-18 11:13 |
2001-11-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353190
|
7.5 |
HIGH
|
matt_wright
|
pgpmail.pl
|
PGPMail.pl 1.31 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) recipient or (2) pgpuserid parameters.
|
NVD-CWE-Other
|
CVE-2001-0937
|
2016-10-18 11:13 |
2001-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353191
|
6.4 |
MEDIUM
|
persits
|
aspupload
|
Directory traversal vulnerability in AspUpload 2.1, in certain configurations, allows remote attackers to upload and read arbitrary files, and list arbitrary directories, via a .. (dot dot) in the Fi…
|
NVD-CWE-Other
|
CVE-2001-0938
|
2016-10-18 11:13 |
2001-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353192
|
7.2 |
HIGH
|
khaled_mardam-bey
|
mirc
|
DDE in mIRC allows local users to launch applications under another user's account via a DDE message that executes a command, which may be executed by the other user's process.
|
NVD-CWE-Other
|
CVE-2001-0944
|
2016-10-18 11:13 |
2001-12-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353193
|
5.0 |
MEDIUM
|
microsoft
|
outlook_express
|
Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line.
|
NVD-CWE-Other
|
CVE-2001-0945
|
2016-10-18 11:13 |
2001-12-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353194
|
4.6 |
MEDIUM
|
oracle
|
database_server
|
Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.
|
NVD-CWE-Other
|
CVE-2001-0831
|
2016-10-18 11:12 |
2001-12-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353195
|
2.1 |
LOW
|
oracle
|
database_server
|
Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log direc…
|
NVD-CWE-Other
|
CVE-2001-0832
|
2016-10-18 11:12 |
2001-12-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353196
|
7.5 |
HIGH
|
ikonboard.com
|
ikonboard
|
Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cooki…
|
NVD-CWE-Other
|
CVE-2001-0841
|
2016-10-18 11:12 |
2001-12-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353197
|
7.5 |
HIGH
|
leoboard
|
lb5000
|
Directory traversal vulnerability in Search.cgi in Leoboard LB5000 LB5000II 1029 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amemberna…
|
NVD-CWE-Other
|
CVE-2001-0842
|
2016-10-18 11:12 |
2001-12-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353198
|
7.5 |
HIGH
|
seth_leonard
|
book_of_guests post_it
|
Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter.
|
NVD-CWE-Other
|
CVE-2001-0844
|
2016-10-18 11:12 |
2001-12-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353199
|
4.6 |
MEDIUM
|
e-zone_media
|
fuse_talk
|
join.cfm in e-Zone Media Fuse Talk allows a local user to execute arbitrary SQL code via a semi-colon (;) in a form variable.
|
NVD-CWE-Other
|
CVE-2001-0848
|
2016-10-18 11:12 |
2001-12-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353200
|
5.0 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.…
|
NVD-CWE-Other
|
CVE-2001-0854
|
2016-10-18 11:12 |
2001-12-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|