CVE-2001-1002
- EPSS 4.72%
- Veröffentlicht 31.08.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains mal...
CVE-2001-0635
- EPSS 0.05%
- Veröffentlicht 14.08.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can allow a local attacker to gain additional privileges by reading sensitive information from the swap file, such as passwords.
CVE-2001-1374
- EPSS 0.05%
- Veröffentlicht 19.07.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.
CVE-2001-1375
- EPSS 0.14%
- Veröffentlicht 19.07.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before other directories, which could allow local users to execute arbitrary code via a Trojan horse library that is under a user-controlled directory.
CVE-2001-1030
- EPSS 0.18%
- Veröffentlicht 18.07.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such...
- EPSS 2.67%
- Veröffentlicht 16.07.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field.
CVE-2001-0439
- EPSS 1.34%
- Veröffentlicht 02.07.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
CVE-2001-0441
- EPSS 1.78%
- Veröffentlicht 27.06.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.
CVE-2001-0473
- EPSS 1.01%
- Veröffentlicht 27.06.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.
CVE-2001-0496
- EPSS 0.07%
- Veröffentlicht 27.06.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.