CVE-2001-0279
- EPSS 0.22%
- Veröffentlicht 03.05.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.
CVE-2001-1331
- EPSS 0.07%
- Veröffentlicht 03.05.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.
CVE-2001-0170
- EPSS 0.64%
- Veröffentlicht 26.03.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.
CVE-2001-0195
- EPSS 0.08%
- Veröffentlicht 26.03.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.
- EPSS 14.82%
- Veröffentlicht 26.03.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.
CVE-2001-0235
- EPSS 0.1%
- Veröffentlicht 26.03.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Vulnerability in crontab allows local users to read crontab files of other users by replacing the temporary file that is being edited while crontab is running.
- EPSS 0.32%
- Veröffentlicht 12.03.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.
- EPSS 0.44%
- Veröffentlicht 12.03.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.
CVE-2001-0111
- EPSS 0.21%
- Veröffentlicht 12.03.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument.
CVE-2001-0112
- EPSS 0.37%
- Veröffentlicht 12.03.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.