Unknown · CVSS Not scored
Buffer overflow in Lotus Domino Mail Server 5.0.5 and earlier allows a remote attacker to crash the server or execute arbitrary code via a long "RCPT TO" command.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
webmin 0.84 and earlier allows local users to overwrite and create arbitrary files via a symlink attack.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in Support Tools Manager (xstm,cstm,stm) in HP-UX 11.11 and earlier allows local users to cause a denial of service.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker can use to decrypt that user's private key file.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in mars_nwe 0.99.pl19 allows remote attackers to execute arbitrary commands.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and possibly other operating systems, allows local users to gain privileges.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in httpGets function in CUPS 1.1.5 allows remote attackers to execute arbitrary commands via a long input line.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed in MS:MS00-090.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
inetd ident server in FreeBSD 4.x and earlier does not properly set group permissions, which allows remote attackers to read the first 16 bytes of files that are accessible by the wheel group.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes the packet appear to be part of an established connection.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router's telnet program to connect to the router's IP address, which causes a crash.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed URL that contains a "."
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file named skin.wmz, then referencing that skin in the codebase parameter to an applet tag, aka the Windows Media Player Skins File Download" vulnerability.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Macromedia Shockwave Flash plugin version 8 and earlier allows remote attackers to cause a denial of service via malformed tag length specifiers in a SWF file.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password information to a file, which allows local users to recover the passwords and read the compressed folders.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Debugging utility in the backdoor mode of Palm OS 3.5.2 and earlier allows attackers with physical access to a Palm device to bypass access restrictions and obtain passwords, even if the system lockout mechanism is enabled.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in eXtropia bbs_forum.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the file parameter.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.
Published May 7, 2001 · Updated Aug 8, 2024