CVE-2001-0635
- EPSS 0.05%
- Veröffentlicht 14.08.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can allow a local attacker to gain additional privileges by reading sensitive information from the swap file, such as passwords.
CVE-2001-1374
- EPSS 0.05%
- Veröffentlicht 19.07.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.
CVE-2001-1375
- EPSS 0.14%
- Veröffentlicht 19.07.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before other directories, which could allow local users to execute arbitrary code via a Trojan horse library that is under a user-controlled directory.
CVE-2001-1030
- EPSS 0.18%
- Veröffentlicht 18.07.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such...
- EPSS 2.96%
- Veröffentlicht 16.07.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field.
CVE-2001-0439
- EPSS 1.08%
- Veröffentlicht 02.07.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
CVE-2001-0441
- EPSS 1.78%
- Veröffentlicht 27.06.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.
CVE-2001-0473
- EPSS 0.81%
- Veröffentlicht 27.06.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.
CVE-2001-0496
- EPSS 0.07%
- Veröffentlicht 27.06.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.
- EPSS 0.79%
- Veröffentlicht 02.06.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
inetd in Red Hat 6.2 does not properly close sockets for internal services such as chargen, daytime, echo, etc., which allows remote attackers to cause a denial of service via a series of connections to the internal services.