CVE-2001-0118: rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack.
rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack.
Published May 7, 2001 · Updated Aug 8, 2024
Browse CVE records published in May 2001, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 315 matching CVEs · Page 6 of 7.
rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack.
Published May 7, 2001 · Updated Aug 8, 2024
Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long connect request.
Published May 7, 2001 · Updated Aug 8, 2024
Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.
Published May 7, 2001 · Updated Aug 8, 2024
Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.
Published May 7, 2001 · Updated Aug 8, 2024
Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.
Published May 7, 2001 · Updated Aug 8, 2024
Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack.
Published May 7, 2001 · Updated Aug 8, 2024
HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.
Published May 7, 2001 · Updated Aug 8, 2024
dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack.
Published May 7, 2001 · Updated Aug 8, 2024
A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.
Published May 7, 2001 · Updated Aug 8, 2024
Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.
Published May 7, 2001 · Updated Aug 8, 2024
Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable.
Published May 7, 2001 · Updated Aug 8, 2024
procfs in FreeBSD and possibly other operating systems allows local users to cause a denial of service by calling mmap on the process' own mem file, which causes the kernel to hang.
Published May 7, 2001 · Updated Aug 8, 2024
Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the "sys" group.
Published May 7, 2001 · Updated Aug 8, 2024
Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the "Severed Windows Media Server Connection" vulnerability.
Published May 7, 2001 · Updated Aug 8, 2024
Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request.
Published May 7, 2001 · Updated Aug 8, 2024
Vulnerability in inetd server in HP-UX 11.04 and earlier allows attackers to cause a denial of service when the "swait" state is used by a server.
Published May 7, 2001 · Updated Aug 8, 2024
rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file.
Published May 7, 2001 · Updated Aug 8, 2024
The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.
Published May 7, 2001 · Updated Aug 8, 2024
Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.
Published May 7, 2001 · Updated Aug 8, 2024
Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address that resolves to a long DNS hostname or domain name.
Published May 7, 2001 · Updated Aug 8, 2024
bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.
Published May 7, 2001 · Updated Aug 8, 2024
Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet.
Published May 7, 2001 · Updated Aug 8, 2024
Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands.
Published May 7, 2001 · Updated Aug 8, 2024
FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.
Published May 7, 2001 · Updated Aug 8, 2024
Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client, which generates a protocol mismatch error.
Published May 7, 2001 · Updated Aug 8, 2024
IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.
Published May 7, 2001 · Updated Aug 8, 2024
Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.
Published May 7, 2001 · Updated Aug 8, 2024
exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file.
Published May 7, 2001 · Updated Aug 8, 2024
KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.
Published May 7, 2001 · Updated Aug 8, 2024
Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability.
Published May 7, 2001 · Updated Aug 8, 2024
Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.
Published May 7, 2001 · Updated Aug 8, 2024
The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.
Published May 7, 2001 · Updated Aug 8, 2024
useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack.
Published May 7, 2001 · Updated Aug 8, 2024
Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of " (quotation) characters.
Published May 7, 2001 · Updated Aug 8, 2024
KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.
Published May 7, 2001 · Updated Aug 8, 2024
Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer.
Published May 7, 2001 · Updated Aug 8, 2024
Buffer overflow in HTML parser of the Lotus R5 Domino Server before 5.06, and Domino Client before 5.05, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed font size specifier.
Published May 7, 2001 · Updated Aug 8, 2024
Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.
Published May 7, 2001 · Updated Aug 8, 2024
Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.
Published May 7, 2001 · Updated Aug 8, 2024
gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.
Published May 7, 2001 · Updated Aug 8, 2024
procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by forking a child process and executing a privileged process from the child, while the parent retains access to the child's address space.
Published May 7, 2001 · Updated Aug 8, 2024
The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.
Published May 7, 2001 · Updated Aug 8, 2024
The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the "Browser Print Template" vulnerability.
Published May 7, 2001 · Updated Aug 8, 2024
Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.
Published May 7, 2001 · Updated Aug 8, 2024
procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges.
Published May 7, 2001 · Updated Aug 8, 2024
gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.
Published May 7, 2001 · Updated Aug 8, 2024
APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file.
Published May 7, 2001 · Updated Aug 8, 2024
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
Published May 7, 2001 · Updated Aug 8, 2024
KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.
Published May 7, 2001 · Updated Aug 8, 2024
CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.
Published May 7, 2001 · Updated Aug 8, 2024