| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2001-1105 | 0.00 | — | 0.03 | Sep 12, 2001 | RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure. | |||
| CVE-2001-1109 | 0.04 | — | 0.08 | Sep 12, 2001 | Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands. | |||
| CVE-2001-1110 | 0.00 | — | 0.01 | Sep 12, 2001 | EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection. | |||
| CVE-2001-1111 | 0.00 | — | 0.00 | Sep 12, 2001 | EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file. | |||
| CVE-2001-1112 | 0.04 | — | 0.11 | Sep 12, 2001 | Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters. | |||
| CVE-2001-0956 | 0.03 | — | 0.02 | Sep 11, 2001 | speechd 0.54 and earlier, with the Festival or rsynth speech synthesis package, allows attackers to execute arbitrary commands via shell metacharacters. | |||
| CVE-2001-0997 | 0.00 | — | 0.02 | Sep 11, 2001 | Textor Webmasters Ltd listrec.pl CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the TEMPLATE parameter. | |||
| CVE-2001-1094 | 0.00 | — | 0.00 | Sep 11, 2001 | NetOp School 1.5 allows local users to bypass access restrictions on the administration version by logging into the student version, closing the student version, then starting the administration version. | |||
| CVE-2001-1446 | 0.00 | — | 0.03 | Sep 11, 2001 | Find-By-Content in Mac OS X 10.0 through 10.0.4 creates world-readable index files named .FBCIndex in every directory, which allows remote attackers to learn the contents of files in web accessible directories. | |||
| CVE-2001-1089 | 0.00 | — | 0.02 | Sep 10, 2001 | libnss-pgsql in nss-pgsql 0.9.0 and earlier allows remote attackers to execute arbitrary SQL queries by inserting SQL code into an HTTP request. | |||
| CVE-2001-1090 | 0.00 | — | 0.02 | Sep 10, 2001 | nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request. | |||
| CVE-2001-1092 | 0.03 | — | 0.01 | Sep 10, 2001 | msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink attack on the .mh_profile file. | |||
| CVE-2001-1093 | 0.03 | — | 0.01 | Sep 10, 2001 | Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument. | |||
| CVE-2001-1369 | 0.00 | — | 0.02 | Sep 10, 2001 | Leon J Breedt pam-pgsql before 0.5.2 allows remote attackers to execute arbitrary SQL code and bypass authentication or modify user account records by injecting SQL statements into user or password fields. | |||
| CVE-2001-1401 | 0.00 | — | 0.02 | Sep 10, 2001 | Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) process_bug.cgi, (2) show_activity.cgi, (3) showvotes.cgi, (4) showdependencytree.cgi, (5)… | |||
| CVE-2001-1402 | 0.00 | — | 0.02 | Sep 10, 2001 | Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-site scripting (CSS) and possibly SQL injection attacks on (1) the product or output form variables for reports.cgi, (2) the… | |||
| CVE-2001-1403 | 0.00 | — | 0.01 | Sep 10, 2001 | Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser's location bar. | |||
| CVE-2001-1404 | 0.00 | — | 0.01 | Sep 10, 2001 | Bugzilla before 2.14 stores user passwords in plaintext and sends password requests in an email message, which could allow attackers to gain privileges. | |||
| CVE-2001-1405 | 0.00 | — | 0.00 | Sep 10, 2001 | Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi. | |||
| CVE-2001-1406 | 0.00 | — | 0.00 | Sep 10, 2001 | process_bug.cgi in Bugzilla before 2.14 does not set the "groupset" bit when a bug is moved between product groups, which will cause the bug to have the old group's restrictions, which might not be as stringent. | |||
| CVE-2001-1407 | 0.00 | — | 0.01 | Sep 10, 2001 | Bugzilla before 2.14 allows Bugzilla users to bypass group security checks by marking a bug as the duplicate of a restricted bug, which adds the user to the CC list of the restricted bug and allows the user to view the bug. | |||
| CVE-2001-0985 | 0.03 | — | 0.04 | Sep 8, 2001 | shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter. | |||
| CVE-2001-1019 | 0.00 | — | 0.02 | Sep 8, 2001 | Directory traversal vulnerability in view_item CGI program in sglMerchant 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTML_FILE parameter. | |||
| CVE-2001-1101 | 0.00 | — | 0.01 | Sep 8, 2001 | The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to… | |||
| CVE-2001-1102 | 0.00 | — | 0.00 | Sep 8, 2001 | Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable. | |||
| CVE-2001-1000 | 0.03 | — | 0.01 | Sep 7, 2001 | rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file. | |||
| CVE-2001-1099 | 0.00 | — | 0.03 | Sep 7, 2001 | The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice. | |||
| CVE-2001-1138 | 0.04 | — | 0.10 | Sep 7, 2001 | Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter. | |||
| CVE-2001-1137 | 0.03 | — | 0.03 | Sep 6, 2001 | D-Link DI-704 Internet Gateway firmware earlier than V2.56b6 allows remote attackers to cause a denial of service (reboot) via malformed IP datagram fragments. | |||
| CVE-2001-1378 | 0.00 | — | 0.00 | Sep 6, 2001 | fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files. | |||
| CVE-2001-0992 | 0.00 | — | 0.02 | Sep 5, 2001 | shopplus.cgi in ShopPlus shopping cart allows remote attackers to execute arbitrary commands via shell metacharacters in the "file" parameter. | |||
| CVE-2001-1012 | 0.00 | — | 0.00 | Sep 5, 2001 | Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/. | |||
| CVE-2001-1020 | 0.00 | — | 0.03 | Sep 5, 2001 | edit_image.php in Vibechild Directory Manager before 0.91 allows remote attackers to execute arbitrary commands via shell metacharacters in the userfile_name parameter, which is sent unfiltered to the PHP passthru function. | |||
| CVE-2001-1132 | 0.00 | — | 0.03 | Sep 5, 2001 | Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication. | |||
| CVE-2001-1152 | 0.00 | — | 0.02 | Sep 5, 2001 | Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file… | |||
| CVE-2001-0990 | 0.00 | — | 0.00 | Sep 4, 2001 | Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library. | |||
| CVE-2001-0994 | 0.00 | — | 0.02 | Sep 4, 2001 | Marconi ForeThought 7.1 allows remote attackers to cause a denial of service by causing both telnet sessions to be locked via unusual input (e.g., from a port scanner), which prevents others from logging into the device. | |||
| CVE-2001-1016 | 0.00 | — | 0.01 | Sep 4, 2001 | PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been… | |||
| CVE-2001-1017 | 0.00 | — | 0.00 | Sep 4, 2001 | rmuser utility in FreeBSD 4.2 and 4.3 creates a copy of the master.passwd file with world-readable permissions while updating the original file, which could allow local users to gain privileges by reading the copied file while rmuser is running, obtain the password hashes, and… | |||
| CVE-2001-1456 | 0.00 | — | 0.06 | Sep 4, 2001 | Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message. | |||
| CVE-2001-0978 | 0.00 | — | 0.02 | Sep 3, 2001 | login in HP-UX 10.26 does not record failed login attempts in /var/adm/btmp, which could allow attackers to conduct brute force password guessing attacks without being detected or observed using the lastb program. | |||
| CVE-2001-0979 | 0.03 | — | 0.02 | Sep 3, 2001 | Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long command line argument. | |||
| CVE-2001-0996 | — | 0.00 | — | 0.02 | Sep 2, 2001 | POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interpreted by various mail clients as valid POP server responses or other input that… | ||
| CVE-2001-1169 | 0.00 | — | 0.01 | Sep 2, 2001 | keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo. | |||
| CVE-2000-1190 | 0.00 | — | 0.00 | Aug 31, 2001 | imwheel-solo in imwheel package allows local users to modify arbitrary files via a symlink attack from the .imwheelrc file. | |||
| CVE-2000-1191 | 0.00 | — | 0.03 | Aug 31, 2001 | htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path. | |||
| CVE-2000-1192 | 0.00 | — | 0.03 | Aug 31, 2001 | Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap. | |||
| CVE-2000-1193 | 0.03 | — | 0.03 | Aug 31, 2001 | Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port. | |||
| CVE-2000-1194 | 0.00 | — | 0.03 | Aug 31, 2001 | Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands. | |||
| CVE-2000-1195 | 0.00 | — | 0.02 | Aug 31, 2001 | telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option. |
- CVE-2001-1105Sep 12, 2001risk 0.00cvss —epss 0.03
RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure.
- CVE-2001-1109Sep 12, 2001risk 0.04cvss —epss 0.08
Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.
- CVE-2001-1110Sep 12, 2001risk 0.00cvss —epss 0.01
EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.
- CVE-2001-1111Sep 12, 2001risk 0.00cvss —epss 0.00
EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file.
- CVE-2001-1112Sep 12, 2001risk 0.04cvss —epss 0.11
Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters.
- CVE-2001-0956Sep 11, 2001risk 0.03cvss —epss 0.02
speechd 0.54 and earlier, with the Festival or rsynth speech synthesis package, allows attackers to execute arbitrary commands via shell metacharacters.
- CVE-2001-0997Sep 11, 2001risk 0.00cvss —epss 0.02
Textor Webmasters Ltd listrec.pl CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the TEMPLATE parameter.
- CVE-2001-1094Sep 11, 2001risk 0.00cvss —epss 0.00
NetOp School 1.5 allows local users to bypass access restrictions on the administration version by logging into the student version, closing the student version, then starting the administration version.
- CVE-2001-1446Sep 11, 2001risk 0.00cvss —epss 0.03
Find-By-Content in Mac OS X 10.0 through 10.0.4 creates world-readable index files named .FBCIndex in every directory, which allows remote attackers to learn the contents of files in web accessible directories.
- CVE-2001-1089Sep 10, 2001risk 0.00cvss —epss 0.02
libnss-pgsql in nss-pgsql 0.9.0 and earlier allows remote attackers to execute arbitrary SQL queries by inserting SQL code into an HTTP request.
- CVE-2001-1090Sep 10, 2001risk 0.00cvss —epss 0.02
nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request.
- CVE-2001-1092Sep 10, 2001risk 0.03cvss —epss 0.01
msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink attack on the .mh_profile file.
- CVE-2001-1093Sep 10, 2001risk 0.03cvss —epss 0.01
Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument.
- CVE-2001-1369Sep 10, 2001risk 0.00cvss —epss 0.02
Leon J Breedt pam-pgsql before 0.5.2 allows remote attackers to execute arbitrary SQL code and bypass authentication or modify user account records by injecting SQL statements into user or password fields.
- CVE-2001-1401Sep 10, 2001risk 0.00cvss —epss 0.02
Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) process_bug.cgi, (2) show_activity.cgi, (3) showvotes.cgi, (4) showdependencytree.cgi, (5)…
- CVE-2001-1402Sep 10, 2001risk 0.00cvss —epss 0.02
Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-site scripting (CSS) and possibly SQL injection attacks on (1) the product or output form variables for reports.cgi, (2) the…
- CVE-2001-1403Sep 10, 2001risk 0.00cvss —epss 0.01
Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser's location bar.
- CVE-2001-1404Sep 10, 2001risk 0.00cvss —epss 0.01
Bugzilla before 2.14 stores user passwords in plaintext and sends password requests in an email message, which could allow attackers to gain privileges.
- CVE-2001-1405Sep 10, 2001risk 0.00cvss —epss 0.00
Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi.
- CVE-2001-1406Sep 10, 2001risk 0.00cvss —epss 0.00
process_bug.cgi in Bugzilla before 2.14 does not set the "groupset" bit when a bug is moved between product groups, which will cause the bug to have the old group's restrictions, which might not be as stringent.
- CVE-2001-1407Sep 10, 2001risk 0.00cvss —epss 0.01
Bugzilla before 2.14 allows Bugzilla users to bypass group security checks by marking a bug as the duplicate of a restricted bug, which adds the user to the CC list of the restricted bug and allows the user to view the bug.
- CVE-2001-0985Sep 8, 2001risk 0.03cvss —epss 0.04
shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter.
- CVE-2001-1019Sep 8, 2001risk 0.00cvss —epss 0.02
Directory traversal vulnerability in view_item CGI program in sglMerchant 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTML_FILE parameter.
- CVE-2001-1101Sep 8, 2001risk 0.00cvss —epss 0.01
The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to…
- CVE-2001-1102Sep 8, 2001risk 0.00cvss —epss 0.00
Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable.
- CVE-2001-1000Sep 7, 2001risk 0.03cvss —epss 0.01
rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file.
- CVE-2001-1099Sep 7, 2001risk 0.00cvss —epss 0.03
The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
- CVE-2001-1138Sep 7, 2001risk 0.04cvss —epss 0.10
Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter.
- CVE-2001-1137Sep 6, 2001risk 0.03cvss —epss 0.03
D-Link DI-704 Internet Gateway firmware earlier than V2.56b6 allows remote attackers to cause a denial of service (reboot) via malformed IP datagram fragments.
- CVE-2001-1378Sep 6, 2001risk 0.00cvss —epss 0.00
fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.
- CVE-2001-0992Sep 5, 2001risk 0.00cvss —epss 0.02
shopplus.cgi in ShopPlus shopping cart allows remote attackers to execute arbitrary commands via shell metacharacters in the "file" parameter.
- CVE-2001-1012Sep 5, 2001risk 0.00cvss —epss 0.00
Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/.
- CVE-2001-1020Sep 5, 2001risk 0.00cvss —epss 0.03
edit_image.php in Vibechild Directory Manager before 0.91 allows remote attackers to execute arbitrary commands via shell metacharacters in the userfile_name parameter, which is sent unfiltered to the PHP passthru function.
- CVE-2001-1132Sep 5, 2001risk 0.00cvss —epss 0.03
Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication.
- CVE-2001-1152Sep 5, 2001risk 0.00cvss —epss 0.02
Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file…
- CVE-2001-0990Sep 4, 2001risk 0.00cvss —epss 0.00
Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library.
- CVE-2001-0994Sep 4, 2001risk 0.00cvss —epss 0.02
Marconi ForeThought 7.1 allows remote attackers to cause a denial of service by causing both telnet sessions to be locked via unusual input (e.g., from a port scanner), which prevents others from logging into the device.
- CVE-2001-1016Sep 4, 2001risk 0.00cvss —epss 0.01
PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been…
- CVE-2001-1017Sep 4, 2001risk 0.00cvss —epss 0.00
rmuser utility in FreeBSD 4.2 and 4.3 creates a copy of the master.passwd file with world-readable permissions while updating the original file, which could allow local users to gain privileges by reading the copied file while rmuser is running, obtain the password hashes, and…
- CVE-2001-1456Sep 4, 2001risk 0.00cvss —epss 0.06
Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message.
- CVE-2001-0978Sep 3, 2001risk 0.00cvss —epss 0.02
login in HP-UX 10.26 does not record failed login attempts in /var/adm/btmp, which could allow attackers to conduct brute force password guessing attacks without being detected or observed using the lastb program.
- CVE-2001-0979Sep 3, 2001risk 0.03cvss —epss 0.02
Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long command line argument.
- CVE-2001-0996Sep 2, 2001risk 0.00cvss —epss 0.02
POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interpreted by various mail clients as valid POP server responses or other input that…
- CVE-2001-1169Sep 2, 2001risk 0.00cvss —epss 0.01
keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo.
- CVE-2000-1190Aug 31, 2001risk 0.00cvss —epss 0.00
imwheel-solo in imwheel package allows local users to modify arbitrary files via a symlink attack from the .imwheelrc file.
- CVE-2000-1191Aug 31, 2001risk 0.00cvss —epss 0.03
htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.
- CVE-2000-1192Aug 31, 2001risk 0.00cvss —epss 0.03
Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap.
- CVE-2000-1193Aug 31, 2001risk 0.03cvss —epss 0.03
Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port.
- CVE-2000-1194Aug 31, 2001risk 0.00cvss —epss 0.03
Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.
- CVE-2000-1195Aug 31, 2001risk 0.00cvss —epss 0.02
telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option.