Unknown · CVSS Not scored
Configuration error in Axent Raptor Firewall 6.5 allows remote attackers to use the firewall as a proxy to access internal web resources when the http.noproxy Rule is not set.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Savant 3.0 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Host HTTP header.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to verify login information.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted port.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The LogDataListToFile ActiveX function used in (1) Knowledge Center and (2) Back web components of Compaq Presario computers allows remote attackers to modify arbitrary files and cause a denial of service.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option.
Published Sep 1, 2004 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Configuration error in Argus PitBull LX allows root users to bypass specified access control restrictions and cause a denial of service or execute arbitrary commands by modifying kernel variables such as MaxFiles, MaxInodes, and ModProbePath in /proc/sys via calls to sysctl.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in gftp prior to 2.0.8 allows remote malicious FTP servers to execute arbitrary commands.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Reliant Unix 5.44 and earlier allows remote attackers to cause a denial of service via an ICMP port unreachable packet, which causes Reliant to drop all connections to the source address of the packet.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell metacharacters in the argument to template.cgi.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflows in ascdc Afterstep while running setuid allows local users to gain root privileges via a long (1) -d option, (2) -m option, or (3) -f option.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail command line option.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users to read files that are being processed by sgml-tools.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Trend Micro Virus Buster 2001 8.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long "From" header.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
man2html before 1.5-22 allows remote attackers to cause a denial of service (memory exhaustion).
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
BinTec X4000 Access router, and possibly other versions, allows remote attackers to cause a denial of service via a SYN port scan, which causes the router to hang.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.
Published May 24, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.
Published Sep 1, 2004 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when another user opens a file containing malicious VIM control codes.
Published Sep 18, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts.
Published May 24, 2001 · Updated Aug 8, 2024