Show filters
90 Total Results
Displaying 81-90 of 90
Sort by:
Attacker Value
Unknown
CVE-2001-0834
Disclosure Date: December 06, 2001 (last updated February 22, 2025)
htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file.
0
Attacker Value
Unknown
CVE-2001-0918
Disclosure Date: November 22, 2001 (last updated February 22, 2025)
Vulnerabilities in CGI scripts in susehelp in SuSE 7.2 and 7.3 allow remote attackers to execute arbitrary commands by not opening files securely.
0
Attacker Value
Unknown
CVE-2001-0763
Disclosure Date: October 18, 2001 (last updated February 22, 2025)
Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response, which is not properly handled by the svc_logprint function.
0
Attacker Value
Unknown
CVE-2001-1012
Disclosure Date: September 05, 2001 (last updated February 22, 2025)
Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/.
0
Attacker Value
Unknown
CVE-2001-1130
Disclosure Date: August 02, 2001 (last updated February 22, 2025)
Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using a .. in the HTTP referer (from the HTTP_REFERER variable) to point to the directory that contains the keylist.txt file.
0
Attacker Value
Unknown
CVE-2001-0388
Disclosure Date: June 27, 2001 (last updated February 22, 2025)
time server daemon timed allows remote attackers to cause a denial of service via malformed packets.
0
Attacker Value
Unknown
CVE-2001-0458
Disclosure Date: June 27, 2001 (last updated February 22, 2025)
Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2001-0178
Disclosure Date: March 26, 2001 (last updated February 22, 2025)
kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
0
Attacker Value
Unknown
CVE-2000-1095
Disclosure Date: January 09, 2001 (last updated February 22, 2025)
modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.
0
Attacker Value
Unknown
CVE-2000-1134
Disclosure Date: January 09, 2001 (last updated February 22, 2025)
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.
0