Unknown · CVSS Not scored
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts.
Published May 7, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.
Published May 7, 2001 · Updated Aug 8, 2024