Unknown · CVSS Not scored
Nosque MsgCore 2.14 stores passwords in cleartext: (1) the administrator password in the AdmPasswd registry key, and (2) user passwords in the Userbase.dbf data file, which could allow local users to gain privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Control Panel "Password Security" option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup disk and using a disk editor to modify the on/off toggle or password in the aaaaaaaAPWD file, which is normally inaccessible.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default.
Published Sep 1, 2004 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in DEC OpenVMS VAX 5.5-2 through 5.0, and OpenVMS AXP 1.0, allows local users to gain system privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Matt Wright's download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
ICQ ActiveList Server allows remote attackers to cause a denial of service (crash) via malformed packets to the server's UDP port.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Screen savers in KDE beta 3 allows local users to overwrite arbitrary files via a symlink attack on the .kss.pid file.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
ARCAD Systemhaus 0.078-5 installs critical programs and files with world-writeable permissions, which could allow local users to gain privileges by replacing a program with a Trojan horse.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerabilities in DECnet/OSI for OpenVMS before 5.8 on DEC Alpha AXP and VAX/VMS systems allow local users to gain privileges or cause a denial of service.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE) 1.5 and earlier, store the administrator password in cleartext in (1) the navieg.ini file for NAVIEG, and (2) the ModifyPassword registry key in NAVMSE.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in prwarn in SCO UNIX 4.2 and earlier allows local users to gain root access.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in accton in Cray UNICOS 6.1 and 6.0 allows local users to read arbitrary files and modify system accounting configuration.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in pt_chmod in SCO UNIX 4.2 and earlier allows local users to gain root access.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in web administration feature of Kolban Webcam32 4.8.3 and earlier allows remote attackers to execute arbitrary commands via a long URL.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in "at" program in SCO UNIX 4.2 and earlier allows local users to gain root access.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in login in SCO UNIX 4.2 and earlier allows local users to gain root access.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the spoolmain.log file when a new database is created, which allows local users to obtain the password from that file.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
SMTP server in SLmail 3.1 and earlier allows remote attackers to cause a denial of service via malformed commands whose arguments begin with a "(" (parenthesis) character, such as (1) SEND, (2) VRFY, (3) EXPN, (4) MAIL FROM, (5) RCPT TO.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been explicitly disabled.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
iPass RoamServer 3.1 creates temporary files with world-writable permissions.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy command to the server.
Published Sep 12, 2001 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface.
Published Sep 12, 2001 · Updated Aug 1, 2024