Show filters
31 Total Results
Displaying 21-30 of 31
Sort by:
Attacker Value
Unknown

CVE-2002-0083

Disclosure Date: March 15, 2002 (last updated February 22, 2025)
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
Attacker Value
Unknown

CVE-2001-1030

Disclosure Date: July 18, 2001 (last updated February 22, 2025)
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
0
Attacker Value
Unknown

CVE-2001-0169

Disclosure Date: March 26, 2001 (last updated February 22, 2025)
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
0
Attacker Value
Unknown

CVE-2001-0117

Disclosure Date: March 12, 2001 (last updated February 22, 2025)
sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.
0
Attacker Value
Unknown

CVE-2001-0142

Disclosure Date: March 12, 2001 (last updated February 22, 2025)
squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.
0
Attacker Value
Unknown

CVE-2000-0917

Disclosure Date: December 19, 2000 (last updated February 22, 2025)
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
0
Attacker Value
Unknown

CVE-2000-1009

Disclosure Date: December 11, 2000 (last updated February 22, 2025)
dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.
0
Attacker Value
Unknown

CVE-2000-0844

Disclosure Date: November 14, 2000 (last updated February 22, 2025)
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
0
Attacker Value
Unknown

CVE-2000-0867

Disclosure Date: November 14, 2000 (last updated February 22, 2025)
Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.
0
Attacker Value
Unknown

CVE-2000-0791

Disclosure Date: October 20, 2000 (last updated February 22, 2025)
Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.
0