Unknown · CVSS Not scored
The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters the encrypted private key file and captures a single message signed with the signature key.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
SonicWALL Tele2 and SOHO firewalls with 6.0.0.0 firmware using IPSEC with IKE pre-shared keys do not allow for the use of full 128 byte IKE pre-shared keys, which is the intended design of the IKE pre-shared key, and only support 48 byte keys. This allows a remote attacker to brute force attack the pre-shared keys with significantly less resources than if the full 128 byte IKE pre-shared keys were used.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented community string 'ILMI'.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ppd in Reliant Sinix allows local users to corrupt arbitrary files via a symlink attack in the /tmp/ppd.trace file.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) attack in the helpon parameter.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The HTTP server in Compaq web-enabled management software for (1) Foundation Agents, (2) Survey, (3) Power Manager, (4) Availability Agents, (5) Intelligent Cluster Administrator, and (6) Insight Manager can be used as a generic proxy server, which allows remote attackers to bypass access restrictions via the management port, 2301.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Mirabilis ICQ WebFront Plug-in ICQ2000b Build 3278 allows a remote attacker to create a denial of service via HTTP URL requests containing a large number of % characters.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line argument (non-existent printer name).
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
fcheck prior to 2.57.59 calls the file signature checking program insecurely, which can allow a local user to run arbitrary commands via a file name that contains shell metacharacters.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Novell Groupwise 5.5 (sp1 and sp2) allows a remote user to access arbitrary files via an implementation error in Groupwise system policies.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." command.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
sort in FreeBSD 4.1.1 and earlier, and possibly other operating systems, uses predictable temporary file names and does not properly handle when the temporary file already exists, which causes sort to crash and possibly impacts security-sensitive scripts.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd).
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
inetd in Red Hat 6.2 does not properly close sockets for internal services such as chargen, daytime, echo, etc., which allows remote attackers to cause a denial of service via a series of connections to the internal services.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the <<ALL FILES>> FilePermission.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
VERITAS Cluster Server (VCS) 1.3.0 on Solaris allows local users to cause a denial of service (system panic) via the -L option to the lltstat command.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Voyager web administration server for Nokia IP440 allows local users to cause a denial of service, and possibly execute arbitrary commands, via a long URL.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in linkeditor in HP MPE/iX 6.5 and earlier allows local users to gain privileges.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
kicq IRC client 1.0.0, and possibly later versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
NM debug in HP MPE/iX 6.5 and earlier does not properly handle breakpoints, which allows local users to gain privileges.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.
Published May 24, 2001 · Updated Aug 8, 2024