-
CVE-2001-0233
•
published on May 7, 2001
Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.
-
CVE-2001-0195
•
published on May 7, 2001
sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.
-
CVE-2001-0218
•
published on May 7, 2001
Format string vulnerability in mars_nwe 0.99.pl19 allows remote attackers to execute arbitrary commands.
-
CVE-2001-0219
•
published on May 7, 2001
Vulnerability in Support Tools Manager (xstm,cstm,stm) in HP-UX 11.11 and earlier allows local users to cause a denial of service.
-
CVE-2001-0197
•
published on May 7, 2001
Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.
-
CVE-2001-0221
•
published on May 7, 2001
Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.
-
CVE-2001-0230
•
published on May 7, 2001
Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and possibly other operating systems, allows local users to gain privileges.
-
CVE-2001-0234
•
published on May 7, 2001
NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.
-
CVE-2001-0260
•
published on May 7, 2001
Buffer overflow in Lotus Domino Mail Server 5.0.5 and earlier allows a remote attacker to crash the server or execute arbitrary code via a long "RCPT TO" command.
-
CVE-2001-0266
•
published on May 7, 2001
Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges.
-
CVE-2001-0278
•
published on May 7, 2001
Vulnerability in linkeditor in HP MPE/iX 6.5 and earlier allows local users to gain privileges.
-
CVE-2001-0279
•
published on May 7, 2001
Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.
-
CVE-2001-0326
•
published on May 7, 2001
Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the FilePermission.
-
CVE-2001-0267
•
published on May 7, 2001
NM debug in HP MPE/iX 6.5 and earlier does not properly handle breakpoints, which allows local users to gain privileges.
-
CVE-2001-0289
•
published on May 7, 2001
Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory.
-
CVE-2001-0295
•
published on May 7, 2001
Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." command.
-
CVE-2001-0299
•
published on May 7, 2001
Buffer overflow in Voyager web administration server for Nokia IP440 allows local users to cause a denial of service, and possibly execute arbitrary commands, via a long URL.
-
CVE-2001-0301
•
published on May 7, 2001
Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings.
-
CVE-2001-0309
•
published on May 7, 2001
inetd in Red Hat 6.2 does not properly close sockets for internal services such as chargen, daytime, echo, etc., which allows remote attackers to cause a denial of service via a series of connections to the internal services.
-
CVE-2001-0316
•
published on May 7, 2001
Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.