- EPSS 51.99%
- Veröffentlicht 31.12.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability ...
- EPSS 88.68%
- Veröffentlicht 12.12.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
CVE-2001-0652
- EPSS 0.11%
- Veröffentlicht 30.10.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.
- EPSS 74.29%
- Veröffentlicht 18.10.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.
CVE-2001-1414
- EPSS 0.72%
- Veröffentlicht 09.10.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, which allows remote attackers to hide their activities, possibly when certain BSM audit files are not present under the FTP root.
CVE-2001-0699
- EPSS 0.06%
- Veröffentlicht 20.09.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in cb_reset in the System Service Processor (SSP) package of SunOS 5.8 allows a local user to execute arbitrary code via a long argument.
CVE-2001-0548
- EPSS 0.12%
- Veröffentlicht 14.08.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.
- EPSS 16.67%
- Veröffentlicht 14.08.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
CVE-2001-0565
- EPSS 0.18%
- Veröffentlicht 14.08.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.
CVE-2001-0594
- EPSS 0.14%
- Veröffentlicht 02.08.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.