| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2001-0460 | 0.03 | — | 0.03 | Jun 27, 2001 | Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header. | |||
| CVE-2001-0461 | 0.03 | — | 0.05 | Jun 27, 2001 | template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell metacharacters in the argument to template.cgi. | |||
| CVE-2001-0462 | 0.03 | — | 0.06 | Jun 27, 2001 | Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |||
| CVE-2001-0463 | 0.04 | — | 0.10 | Jun 27, 2001 | Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter. | |||
| CVE-2001-0467 | 0.03 | — | 0.06 | Jun 27, 2001 | Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a \... (modified dot dot) in an HTTP URL request. | |||
| CVE-2001-0468 | 0.03 | — | 0.00 | Jun 27, 2001 | Buffer overflow in FTPFS allows local users to gain root privileges via a long user name. | |||
| CVE-2001-0469 | 0.00 | — | 0.01 | Jun 27, 2001 | rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length. | |||
| CVE-2001-0470 | 0.00 | — | 0.00 | Jun 27, 2001 | Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name. | |||
| CVE-2001-0471 | 0.03 | — | 0.03 | Jun 27, 2001 | SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack. | |||
| CVE-2001-0472 | 0.00 | — | 0.01 | Jun 27, 2001 | Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request. | |||
| CVE-2001-0473 | 0.00 | — | 0.01 | Jun 27, 2001 | Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands. | |||
| CVE-2001-0474 | 0.00 | — | 0.00 | Jun 27, 2001 | Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file. | |||
| CVE-2001-0475 | 0.00 | — | 0.01 | Jun 27, 2001 | index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter. | |||
| CVE-2001-0476 | 0.03 | — | 0.05 | Jun 27, 2001 | Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter. | |||
| CVE-2001-0477 | 0.00 | — | 0.02 | Jun 27, 2001 | Vulnerability in WebCalendar 0.9.26 allows remote command execution. | |||
| CVE-2001-0478 | 0.00 | — | 0.01 | Jun 27, 2001 | Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script. | |||
| CVE-2001-0479 | 0.00 | — | 0.02 | Jun 27, 2001 | Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script. | |||
| CVE-2001-0480 | 0.00 | — | 0.00 | Jun 27, 2001 | Directory traversal vulnerability in Alex's FTP Server 0.7 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the (1) GET or (2) CD commands. | |||
| CVE-2001-0481 | 0.00 | — | 0.00 | Jun 27, 2001 | Vulnerability in rpmdrake in Mandrake Linux 8.0 related to insecure temporary file handling. | |||
| CVE-2001-0484 | 0.03 | — | 0.03 | Jun 27, 2001 | Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages. | |||
| CVE-2001-0485 | 0.03 | — | 0.00 | Jun 27, 2001 | Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option. | |||
| CVE-2001-0487 | 0.00 | — | 0.01 | Jun 27, 2001 | AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection. | |||
| CVE-2001-0488 | 0.00 | — | 0.00 | Jun 27, 2001 | pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service. | |||
| CVE-2001-0489 | 0.00 | — | 0.01 | Jun 27, 2001 | Format string vulnerability in gftp prior to 2.0.8 allows remote malicious FTP servers to execute arbitrary commands. | |||
| CVE-2001-0490 | 0.03 | — | 0.04 | Jun 27, 2001 | Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file. | |||
| CVE-2001-0491 | 0.03 | — | 0.03 | Jun 27, 2001 | Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks, such as (1) .... in CWD, (2) .. in NLST, or (3) ... in NLST. | |||
| CVE-2001-0492 | 0.00 | — | 0.01 | Jun 27, 2001 | Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3. | |||
| CVE-2001-0493 | 0.00 | — | 0.01 | Jun 27, 2001 | Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux. | |||
| CVE-2001-0494 | 0.00 | — | 0.01 | Jun 27, 2001 | Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header. | |||
| CVE-2001-0495 | 0.04 | — | 0.06 | Jun 27, 2001 | Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack. | |||
| CVE-2001-0496 | 0.00 | — | 0.00 | Jun 27, 2001 | kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges. | |||
| CVE-2001-1164 | 0.00 | — | 0.00 | Jun 27, 2001 | Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt. | |||
| CVE-2001-1083 | 0.04 | — | 0.13 | Jun 26, 2001 | Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or \ (backward slash). | |||
| CVE-2001-1324 | 0.00 | — | 0.00 | Jun 26, 2001 | cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges. | |||
| CVE-2001-1162 | 0.06 | — | 0.32 | Jun 23, 2001 | Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file. | |||
| CVE-2001-0906 | 0.03 | — | 0.00 | Jun 22, 2001 | teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produced when printing .dvi files using lpr. | |||
| CVE-2001-1328 | 0.00 | — | 0.05 | Jun 22, 2001 | Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code. | |||
| CVE-2001-1078 | 0.04 | — | 0.14 | Jun 21, 2001 | Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that… | |||
| CVE-2001-1276 | 0.00 | — | 0.00 | Jun 21, 2001 | ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file. | |||
| CVE-2001-1080 | 0.03 | — | 0.03 | Jun 19, 2001 | diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program. | |||
| CVE-2001-1459 | 0.00 | — | 0.00 | Jun 19, 2001 | OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d. | |||
| CVE-2001-0247 | 0.06 | — | 0.35 | Jun 18, 2001 | Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3. | |||
| CVE-2001-0248 | Cri | 0.64 | 9.8 | 0.05 | Jun 18, 2001 | Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings. | ||
| CVE-2001-0249 | Cri | 0.64 | 9.8 | 0.05 | Jun 18, 2001 | Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings. | ||
| CVE-2001-0263 | 0.03 | — | 0.04 | Jun 18, 2001 | Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled. | |||
| CVE-2001-0264 | 0.04 | — | 0.07 | Jun 18, 2001 | Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff… | |||
| CVE-2001-0265 | 0.03 | — | 0.01 | Jun 18, 2001 | ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file. | |||
| CVE-2001-0371 | 0.00 | — | 0.00 | Jun 18, 2001 | Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted information. | |||
| CVE-2001-0372 | 0.00 | — | 0.02 | Jun 18, 2001 | Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct. | |||
| CVE-2001-0373 | 0.00 | — | 0.01 | Jun 18, 2001 | The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information. |
- CVE-2001-0460Jun 27, 2001risk 0.03cvss —epss 0.03
Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header.
- CVE-2001-0461Jun 27, 2001risk 0.03cvss —epss 0.05
template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell metacharacters in the argument to template.cgi.
- CVE-2001-0462Jun 27, 2001risk 0.03cvss —epss 0.06
Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
- CVE-2001-0463Jun 27, 2001risk 0.04cvss —epss 0.10
Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.
- CVE-2001-0467Jun 27, 2001risk 0.03cvss —epss 0.06
Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a \... (modified dot dot) in an HTTP URL request.
- CVE-2001-0468Jun 27, 2001risk 0.03cvss —epss 0.00
Buffer overflow in FTPFS allows local users to gain root privileges via a long user name.
- CVE-2001-0469Jun 27, 2001risk 0.00cvss —epss 0.01
rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length.
- CVE-2001-0470Jun 27, 2001risk 0.00cvss —epss 0.00
Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.
- CVE-2001-0471Jun 27, 2001risk 0.03cvss —epss 0.03
SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.
- CVE-2001-0472Jun 27, 2001risk 0.00cvss —epss 0.01
Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.
- CVE-2001-0473Jun 27, 2001risk 0.00cvss —epss 0.01
Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.
- CVE-2001-0474Jun 27, 2001risk 0.00cvss —epss 0.00
Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file.
- CVE-2001-0475Jun 27, 2001risk 0.00cvss —epss 0.01
index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.
- CVE-2001-0476Jun 27, 2001risk 0.03cvss —epss 0.05
Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter.
- CVE-2001-0477Jun 27, 2001risk 0.00cvss —epss 0.02
Vulnerability in WebCalendar 0.9.26 allows remote command execution.
- CVE-2001-0478Jun 27, 2001risk 0.00cvss —epss 0.01
Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.
- CVE-2001-0479Jun 27, 2001risk 0.00cvss —epss 0.02
Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.
- CVE-2001-0480Jun 27, 2001risk 0.00cvss —epss 0.00
Directory traversal vulnerability in Alex's FTP Server 0.7 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the (1) GET or (2) CD commands.
- CVE-2001-0481Jun 27, 2001risk 0.00cvss —epss 0.00
Vulnerability in rpmdrake in Mandrake Linux 8.0 related to insecure temporary file handling.
- CVE-2001-0484Jun 27, 2001risk 0.03cvss —epss 0.03
Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages.
- CVE-2001-0485Jun 27, 2001risk 0.03cvss —epss 0.00
Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option.
- CVE-2001-0487Jun 27, 2001risk 0.00cvss —epss 0.01
AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.
- CVE-2001-0488Jun 27, 2001risk 0.00cvss —epss 0.00
pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.
- CVE-2001-0489Jun 27, 2001risk 0.00cvss —epss 0.01
Format string vulnerability in gftp prior to 2.0.8 allows remote malicious FTP servers to execute arbitrary commands.
- CVE-2001-0490Jun 27, 2001risk 0.03cvss —epss 0.04
Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file.
- CVE-2001-0491Jun 27, 2001risk 0.03cvss —epss 0.03
Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks, such as (1) .... in CWD, (2) .. in NLST, or (3) ... in NLST.
- CVE-2001-0492Jun 27, 2001risk 0.00cvss —epss 0.01
Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3.
- CVE-2001-0493Jun 27, 2001risk 0.00cvss —epss 0.01
Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.
- CVE-2001-0494Jun 27, 2001risk 0.00cvss —epss 0.01
Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header.
- CVE-2001-0495Jun 27, 2001risk 0.04cvss —epss 0.06
Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack.
- CVE-2001-0496Jun 27, 2001risk 0.00cvss —epss 0.00
kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.
- CVE-2001-1164Jun 27, 2001risk 0.00cvss —epss 0.00
Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.
- CVE-2001-1083Jun 26, 2001risk 0.04cvss —epss 0.13
Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or \ (backward slash).
- CVE-2001-1324Jun 26, 2001risk 0.00cvss —epss 0.00
cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.
- CVE-2001-1162Jun 23, 2001risk 0.06cvss —epss 0.32
Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.
- CVE-2001-0906Jun 22, 2001risk 0.03cvss —epss 0.00
teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produced when printing .dvi files using lpr.
- CVE-2001-1328Jun 22, 2001risk 0.00cvss —epss 0.05
Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.
- CVE-2001-1078Jun 21, 2001risk 0.04cvss —epss 0.14
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that…
- CVE-2001-1276Jun 21, 2001risk 0.00cvss —epss 0.00
ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file.
- CVE-2001-1080Jun 19, 2001risk 0.03cvss —epss 0.03
diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.
- CVE-2001-1459Jun 19, 2001risk 0.00cvss —epss 0.00
OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.
- CVE-2001-0247Jun 18, 2001risk 0.06cvss —epss 0.35
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.
- risk 0.64cvss 9.8epss 0.05
Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.
- risk 0.64cvss 9.8epss 0.05
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
- CVE-2001-0263Jun 18, 2001risk 0.03cvss —epss 0.04
Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.
- CVE-2001-0264Jun 18, 2001risk 0.04cvss —epss 0.07
Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff…
- CVE-2001-0265Jun 18, 2001risk 0.03cvss —epss 0.01
ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file.
- CVE-2001-0371Jun 18, 2001risk 0.00cvss —epss 0.00
Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted information.
- CVE-2001-0372Jun 18, 2001risk 0.00cvss —epss 0.02
Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.
- CVE-2001-0373Jun 18, 2001risk 0.00cvss —epss 0.01
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.