Unknown · CVSS Not scored
Buffer overflow in dbadmin CGI program 1.0.1 on Linux allows remote attackers to execute arbitrary commands.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for files by unmounting the file system and using a file system editor such as fsdb to directly modify the file through a device.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Solaris Solstice AdminSuite (AdminSuite) 2.1 incorrectly sets write permissions on source files for NIS maps, which could allow local users to gain privileges by modifying /etc/passwd.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found").
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
NFS daemon (nfsd.exe) for Omni-NFS/X 6.1 allows remote attackers to cause a denial of service (resource exhaustion) via certain packets, possibly with the Urgent (URG) flag set, to port 111.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
IBM/Tivoli OPC Tracker Agent version 2 release 1 creates files, directories, and IPC message queues with insecure permissions (world-readable and world-writable), which could allow local users to disrupt operations and possibly gain privileges by modifying or deleting files.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Bug in AMD K6 processor on Linux 2.0.x and 2.1.x kernels allows local users to cause a denial of service (crash) via a particular sequence of instructions, possibly related to accessing addresses outside of segments.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local users to gain privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in libsocks5 library of Socks 5 (socks5) 1.0r5 allows local users to gain privileges via long environmental variables.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
HTTP server for Xerox DocuColor 4 LP allows remote attackers to cause a denial of service (hang) via a long URL that contains a large number of . characters.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
gcc 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary .i, .s, or .o files.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Micah Software Full Armor Network Configurator and Zero Administration allow local users with physical access to bypass the desktop protection by (1) using <CTRL><ALT><DEL> and kill the process using the task manager, (2) booting the system from a separate disk, or (3) interrupting certain processes that execute while the system is booting.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "<" sign, and the 0x9b character to a ">" sign, which could allow remote attackers to attack other clients via cross-site scripting (CSS) in CGI programs that do not filter these characters.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
BMC Patrol component, when installed with Compaq Insight Management Agent 4.23 and earlier, or Management Agents for Servers 4.40 and earlier, creates a PFCUser account with a default password and potentially dangerous privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
passwd in SunOS 4.1.x allows local users to overwrite arbitrary files via a symlink attack and the -F command line argument.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Auto_FTP.pl script in Auto_FTP 0.2 uses the /tmp/ftp_tmp as a shared directory with insecure permissions, which allows local users to (1) send arbitrary files to the remote server by placing them in the directory, and (2) view files that are being transferred.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule before a more restrictive one, which allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the "set host prompt" setting is made for a port, which allows attackers to bypass restrictions by providing the hostname twice at the "host: " prompt.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands.
Published Sep 12, 2001 · Updated Aug 1, 2024