Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2002-1199
Disclosure Date: October 28, 2002 (last updated February 22, 2025)
The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.
0
Attacker Value
Unknown
CVE-2001-0851
Disclosure Date: December 06, 2001 (last updated February 22, 2025)
Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie.
0
Attacker Value
Unknown
CVE-2000-1195
Disclosure Date: August 31, 2001 (last updated February 22, 2025)
telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option.
0
Attacker Value
Unknown
CVE-2001-1030
Disclosure Date: July 18, 2001 (last updated February 22, 2025)
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
0
Attacker Value
Unknown
CVE-2001-0181
Disclosure Date: March 26, 2001 (last updated February 22, 2025)
Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2001-0139
Disclosure Date: March 12, 2001 (last updated February 22, 2025)
inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
0
Attacker Value
Unknown
CVE-2000-1134
Disclosure Date: January 09, 2001 (last updated February 22, 2025)
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.
0
Attacker Value
Unknown
CVE-2000-0917
Disclosure Date: December 19, 2000 (last updated February 22, 2025)
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2000-0844
Disclosure Date: November 14, 2000 (last updated February 22, 2025)
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
0
Attacker Value
Unknown
CVE-2000-0594
Disclosure Date: July 04, 2000 (last updated February 22, 2025)
BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.
0