|
Name: CVE-2001-0001
Description:
cookiedecode function in PHP-Nuke 4.4 allows users to
bypass authentication and gain access to other user
accounts by extracting the authentication information
from a cookie. Status: Entry
Reference: BUGTRAQ:20010213 RFP2101: RFPlutonium
to fuel your PHP-Nuke
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0257.html
Reference: XF:php-nuke-elevate-privileges(6183)
Reference:
URL:http://xforce.iss.net/static/6183.php
Name: CVE-2001-0002
Description:
Internet Explorer 5.5 and earlier allows remote
attackers to obtain the physical location of cached
content and open the content in the Local Computer Zone,
then use compiled HTML help (.chm) files to execute
arbitrary programs. Status: Entry
Reference: MS:MS01-015
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-015.asp
Reference: BUGTRAQ:20001120 IE 5.x/Outlook allows
executing arbitrary programs using .chm files and
temporary internet files folder
Reference:
MISC:http://www.guninski.com/chmtempmain.html
Reference: BID:2456
Reference:
URL:http://www.securityfocus.com/bid/2456
Reference: OSVDB:7823
Reference: URL:http://www.osvdb.org/7823
Reference: OVAL:oval:org.mitre.oval:def:920
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:920
Reference: XF:ie-chm-execute-files(5567)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/5567
Name: CVE-2001-0003
Description:
Web Extender Client (WEC) in Microsoft Office 2000,
Windows 2000, and Windows Me does not properly process
Internet Explorer security settings for NTLM
authentication, which allows attackers to obtain NTLM
credentials and possibly obtain the password, aka the
"Web Client NTLM Authentication" vulnerability.
Status: Entry
Reference: MS:MS01-001
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-001.asp
Reference: XF:wec-ntlm-authentication
Reference:
URL:http://xforce.iss.net/static/5920.php
Reference: BID:2199
Reference:
URL:http://www.securityfocus.com/bid/2199
Name: CVE-2001-0004
Description:
IIS 5.0 and 4.0 allows remote attackers to read the
source code for executable web server programs by
appending "%3F+.htr" to the requested URL, which causes
the files to be parsed by the .HTR ISAPI extension, aka
a variant of the "File Fragment Reading via .HTR"
vulnerability. Status: Entry
Reference: BUGTRAQ:20010108 IIS 5.0 allows
viewing files using %3F+.htr
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97897954625305&w=2
Reference: MS:MS01-004
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-004.asp
Reference: BID:2313
Reference:
URL:http://www.securityfocus.com/bid/2313
Reference: XF:iis-read-files(5903)
Reference:
URL:http://xforce.iss.net/static/5903.php
Name: CVE-2001-0005
Description:
Buffer overflow in the parsing mechanism of the file
loader in Microsoft PowerPoint 2000 allows attackers to
execute arbitrary commands. Status: Entry
Reference: ATSTAKE:A012301-1
Reference:
URL:http://www.atstake.com/research/advisories/2001/a012301-1.txt
Reference: MS:MS01-002
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-002.asp
Reference: XF:powerpoint-execute-code(5996)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/5996
Name: CVE-2001-0006
Description:
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0
has inappropriate Everyone/Full Control permissions,
which allows local users to modify the permissions to
"No Access" and disable Winsock network connectivity to
cause a denial of service, aka the "Winsock Mutex"
vulnerability. Status: Entry
Reference: BUGTRAQ:20010126 ntsecurity.nu
advisory: Winsock Mutex Vulnerability in Windows NT 4.0
SP6 and below
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98075221915234&w=2
Reference: MS:MS01-003
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-003.asp
Reference: XF:winnt-mutex-dos(6006)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6006
Name: CVE-2001-0007
Description:
Buffer overflow in NetScreen Firewall WebUI allows
remote attackers to cause a denial of service via a long
URL request to the web administration interface.
Status: Entry
Reference: BUGTRAQ:20010109 NSFOCUS SA2001-01:
NetScreen Firewall WebUI Buffer Overflow vulnerability
Reference:
URL:http://www.securityfocus.com/archive/1/155149
Reference: BID:2176
Reference:
URL:http://www.securityfocus.com/bid/2176
Reference: XF:netscreen-webui-bo(5908)
Reference:
URL:http://xforce.iss.net/static/5908.php
Reference: OSVDB:1707
Reference: URL:http://www.osvdb.org/1707
Name: CVE-2001-0008
Description:
Backdoor account in Interbase database server allows
remote attackers to overwrite arbitrary files using
stored procedures. Status: Entry
Reference: CERT:CA-2001-01
Reference:
URL:http://www.cert.org/advisories/CA-2001-01.html
Reference: BID:2192
Reference:
URL:http://www.securityfocus.com/bid/2192
Reference: XF:interbase-backdoor-account(5911)
Reference:
URL:http://xforce.iss.net/static/5911.php
Name: CVE-2001-0009
Description:
Directory traversal vulnerability in Lotus Domino 5.0.5
web server allows remote attackers to read arbitrary
files via a .. attack. Status: Entry
Reference: BUGTRAQ:20010105 Lotus Domino 5.0.5
Web Server vulnerability - reading files outside the web
root
Reference:
URL:http://www.securityfocus.com/archive/1/154537
Reference: BUGTRAQ:20010109 bugtraq id 2173 Lotus
Domino Server
Reference:
URL:http://www.securityfocus.com/archive/1/155124
Reference: BID:2173
Reference:
URL:http://www.securityfocus.com/bid/2173
Reference:
XF:lotus-domino-directory-traversal(5899)
Reference:
URL:http://xforce.iss.net/static/5899.php
Reference: OSVDB:1703
Reference: URL:http://www.osvdb.org/1703
Name: CVE-2001-0010
Description:
Buffer overflow in transaction signature (TSIG) handling
code in BIND 8 allows remote attackers to gain root
privileges. Status: Entry
Reference: NAI:20010129 Vulnerabilities in BIND 4
and 8
Reference:
URL:http://www.nai.com/research/covert/advisories/047.asp
Reference: CERT:CA-2001-02
Reference:
URL:http://www.cert.org/advisories/CA-2001-02.html
Reference: IBM:ERS-SVA-E01-2001:002.1
Reference: DEBIAN:DSA-026
Reference:
URL:http://www.debian.org/security/2001/dsa-026
Reference: MANDRAKE:MDKSA-2001-017
Reference: REDHAT:RHSA-2001:007
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-007.html
Reference: CONECTIVA:000377
Reference: FREEBSD:FreeBSD-SA-01:18
Reference: XF:bind-tsig-bo
Reference: BID:2302
Reference:
URL:http://www.securityfocus.com/bid/2302
Name: CVE-2001-0011
Description:
Buffer overflow in nslookupComplain function in BIND 4
allows remote attackers to gain root privileges.
Status: Entry
Reference: NAI:20010129 Vulnerabilities in BIND 4
and 8
Reference:
URL:http://www.nai.com/research/covert/advisories/047.asp
Reference: CERT:CA-2001-02
Reference:
URL:http://www.cert.org/advisories/CA-2001-02.html
Reference: IBM:ERS-SVA-E01-2001:002.1
Reference: MANDRAKE:MDKSA-2001-017
Reference: REDHAT:RHSA-2001:007
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-007.html
Reference: CONECTIVA:000377
Reference: FREEBSD:FreeBSD-SA-01:18
Reference: XF:bind-complain-bo
Reference: BID:2307
Reference:
URL:http://www.securityfocus.com/bid/2307
Name: CVE-2001-0012
Description:
BIND 4 and BIND 8 allow remote attackers to access
sensitive information such as environment variables.
Status: Entry
Reference: NAI:20010129 Vulnerabilities in BIND 4
and 8
Reference:
URL:http://www.nai.com/research/covert/advisories/047.asp
Reference: CERT:CA-2001-02
Reference:
URL:http://www.cert.org/advisories/CA-2001-02.html
Reference: DEBIAN:DSA-026
Reference:
URL:http://www.debian.org/security/2001/dsa-026
Reference: IBM:ERS-SVA-E01-2001:002.1
Reference: MANDRAKE:MDKSA-2001-017
Reference: REDHAT:RHSA-2001:007
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-007.html
Reference: CONECTIVA:000377
Reference: FREEBSD:FreeBSD-SA-01:18
Reference: XF:bind-inverse-query-disclosure
Reference: BID:2321
Reference:
URL:http://www.securityfocus.com/bid/2321
Name: CVE-2001-0013
Description:
Format string vulnerability in nslookupComplain function
in BIND 4 allows remote attackers to gain root
privileges. Status: Entry
Reference: NAI:20010129 Vulnerabilities in BIND 4
and 8
Reference:
URL:http://www.nai.com/research/covert/advisories/047.asp
Reference: CERT:CA-2001-02
Reference:
URL:http://www.cert.org/advisories/CA-2001-02.html
Reference: IBM:ERS-SVA-E01-2001:002.1
Reference: MANDRAKE:MDKSA-2001-017
Reference: REDHAT:RHSA-2001:007
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-007.html
Reference: CONECTIVA:000377
Reference: FREEBSD:FreeBSD-SA-01:18
Reference: XF:bind-complain-format-string
Reference: BID:2309
Reference:
URL:http://www.securityfocus.com/bid/2309
Name: CVE-2001-0014
Description:
Remote Data Protocol (RDP) in Windows 2000 Terminal
Service does not properly handle certain malformed
packets, which allows remote attackers to cause a denial
of service, aka the "Invalid RDP Data" vulnerability.
Status: Entry
Reference: MS:MS01-006
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-006.asp
Reference: XF:win2k-rdp-dos
Reference: BID:2326
Reference:
URL:http://www.securityfocus.com/bid/2326
Name: CVE-2001-0015
Description:
Network Dynamic Data Exchange (DDE) in Windows 2000
allows local users to gain SYSTEM privileges via a
"WM_COPYDATA" message to an invisible window that is
running with the privileges of the WINLOGON process.
Status: Entry
Reference: ATSTAKE:A020501-1
Reference:
URL:http://www.atstake.com/research/advisories/2001/a020501-1.txt
Reference: MS:MS01-007
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-007.asp
Reference: BID:2341
Reference:
URL:http://www.securityfocus.com/bid/2341
Reference: XF:win-dde-elevate-privileges(6062)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6062
Name: CVE-2001-0016
Description:
NTLM Security Support Provider (NTLMSSP) service does
not properly check the function number in an LPC
request, which could allow local users to gain
administrator level access. Status: Entry
Reference: BINDVIEW:20010207 Local promotion
vulnerability in NT4's NTLM Security Support Provider
Reference:
URL:http://razor.bindview.com/publish/advisories/adv_NTLMSSP.html
Reference: MS:MS01-008
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-008.asp
Reference: BID:2348
Reference:
URL:http://www.securityfocus.com/bid/2348
Reference: XF:ntlm-ssp-elevate-privileges(6076)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6076
Name: CVE-2001-0017
Description:
Memory leak in PPTP server in Windows NT 4.0 allows
remote attackers to cause a denial of service via a
malformed data packet, aka the "Malformed PPTP Packet
Stream" vulnerability. Status: Entry
Reference: MS:MS01-009
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-009.asp
Reference: BID:2368
Reference:
URL:http://www.securityfocus.com/bid/2368
Reference: XF:winnt-pptp-dos(6103)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6103
Name: CVE-2001-0018
Description:
Windows 2000 domain controller in Windows 2000 Server,
Advanced Server, or Datacenter Server allows remote
attackers to cause a denial of service via a flood of
malformed service requests. Status: Entry
Reference: VULN-DEV:20001202 UDP Ping-pong in
Win2k
Reference:
URL:http://online.securityfocus.com/archive/82/148411
Reference: MS:MS01-011
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-011.asp
Reference: XF:win2k-domain-controller-dos(6136)
Reference:
URL:http://xforce.iss.net/static/6136.php
Reference: CIAC:L-049
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-049.shtml
Name: CVE-2001-0020
Description:
Directory traversal vulnerability in Arrowpoint (aka
Cisco Content Services, or CSS) allows local
unprivileged users to read arbitrary files via a .. (dot
dot) attack. Status: Entry
Reference: ATSTAKE:A013101-1
Reference:
URL:http://www.atstake.com/research/advisories/2001/a013101-1.txt
Reference: CISCO:20010131 Cisco Content Services
Switch Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/arrowpoint-cli-filesystem-pub.shtml
Reference: XF:cisco-ccs-file-access(6031)
Reference:
URL:http://xforce.iss.net/static/6031.php
Reference: BID:2331
Reference:
URL:http://www.securityfocus.com/bid/2331
Reference: OSVDB:1757
Reference: URL:http://www.osvdb.org/1757
Name: CVE-2001-0021
Description:
MailMan Webmail 3.0.25 and earlier allows remote
attackers to execute arbitrary commands via shell
metacharacters in the alternate_template parameter.
Status: Entry
Reference: BUGTRAQ:20001206 (SRADV00005) Remote
command execution vulnerabilities in MailMan Webmail
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0057.html
Reference:
CONFIRM:http://www.endymion.com/products/mailman/history.htm
Reference: BID:2063
Reference:
URL:http://www.securityfocus.com/bid/2063
Reference: XF:mailman-alternate-templates
Reference:
URL:http://xforce.iss.net/static/5649.php
Name: CVE-2001-0026
Description:
rp-pppoe PPPoE client allows remote attackers to cause a
denial of service via the Clamp MSS option and a TCP
packet with a zero-length TCP option. Status:
Entry
Reference: BUGTRAQ:20001211 DoS vulnerability in
rp-pppoe versions <= 2.4
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0134.html
Reference: CONECTIVA:CLA-2000:357
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000357
Reference: MANDRAKE:MDKSA-2000:084
Reference:
URL:http://www.linux-mandrake.com/en/security/MDKSA-2000-084.php3
Reference: REDHAT:RHSA-2000:130
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2000-130.html
Reference: BID:2098
Reference:
URL:http://www.securityfocus.com/bid/2098
Reference: XF:rppppoe-zero-length-dos
Reference:
URL:http://xforce.iss.net/static/5727.php
Name: CVE-2001-0028
Description:
Buffer overflow in the HTML parsing code in oops WWW
proxy server 1.5.2 and earlier allows remote attackers
to execute arbitrary commands via a large number of "
(quotation) characters. Status: Entry
Reference: BUGTRAQ:20001211 [pkc] remote heap
buffer overflow in oops
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0127.html
Reference: FREEBSD:FreeBSD-SA-00:79
Reference:
URL:http://archives.neohapsis.com/archives/freebsd/2000-12/0418.html
Reference: BID:2099
Reference:
URL:http://www.securityfocus.com/bid/2099
Reference: XF:oops-ftputils-bo
Reference:
URL:http://xforce.iss.net/static/5725.php
Name: CVE-2001-0033
Description:
KTH Kerberos IV allows local users to change the
configuration of a Kerberos server running at an
elevated privilege by specifying an alternate directory
using with the KRBCONFDIR environmental variable, which
allows the user to gain additional privileges.
Status: Entry
Reference: BUGTRAQ:20001208 Vulnerabilities in
KTH Kerberos IV
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html
Reference: BUGTRAQ:20001210 KTH upgrade and FIX
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html
Reference: XF:kerberos4-user-config
Reference:
URL:http://xforce.iss.net/static/5738.php
Name: CVE-2001-0034
Description:
KTH Kerberos IV allows local users to specify an
alternate proxy using the krb4_proxy variable, which
allows the user to generate false proxy responses and
possibly gain privileges. Status: Entry
Reference: BUGTRAQ:20001208 Vulnerabilities in
KTH Kerberos IV
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html
Reference: BUGTRAQ:20001210 KTH upgrade and FIX
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html
Reference: XF:kerberos4-arbitrary-proxy
Reference:
URL:http://xforce.iss.net/static/5733.php
Name: CVE-2001-0035
Description:
Buffer overflow in the kdc_reply_cipher function in KTH
Kerberos IV allows remote attackers to cause a denial of
service and possibly execute arbitrary commands via a
long authentication request. Status: Entry
Reference: BUGTRAQ:20001208 Vulnerabilities in
KTH Kerberos IV
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html
Reference: BUGTRAQ:20001210 KTH upgrade and FIX
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html
Reference: BUGTRAQ:20010130 Buffer overflow in
old ssh-1.2.2x-afs-kerberosv4 patches
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0511.html
Reference: XF:kerberos4-auth-packet-overflow
Reference:
URL:http://xforce.iss.net/static/5734.php
Name: CVE-2001-0036
Description:
KTH Kerberos IV allows local users to overwrite
arbitrary files via a symlink attack on a ticket file.
Status: Entry
Reference: BUGTRAQ:20001208 Vulnerabilities in
KTH Kerberos IV
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html
Reference: BUGTRAQ:20001210 KTH upgrade and FIX
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html
Reference: REDHAT:RHSA-2001:025
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-025.html
Reference: XF:kerberos4-tmpfile-dos
Reference:
URL:http://xforce.iss.net/static/5754.php
Name: CVE-2001-0039
Description:
IPSwitch IMail 6.0.5 allows remote attackers to cause a
denial of service using the SMTP AUTH command by sending
a base64-encoded user password whose length is between
80 and 136 bytes. Status: Entry
Reference: BUGTRAQ:20001206 DoS by SMTP AUTH
command in IPSwitch IMail server
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0071.html
Reference: BID:2083
Reference:
URL:http://www.securityfocus.com/bid/2083
Reference:
CONFIRM:http://www.ipswitch.com/Support/IMail/news.html
Reference: XF:imail-smtp-auth-dos
Reference:
URL:http://xforce.iss.net/static/5674.php
Name: CVE-2001-0040
Description:
APC UPS daemon, apcupsd, saves its process ID in a
world-writable file, which allows local users to kill an
arbitrary process by specifying the target process ID in
the apcupsd.pid file. Status: Entry
Reference: BUGTRAQ:20001206 apcupsd 3.7.2 Denial
of Service
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0066.html
Reference: MANDRAKE:MDKSA-2000:077
Reference:
URL:http://www.linux-mandrake.com/en/security/MDKSA-2000-077.php3
Reference: BID:2070
Reference:
URL:http://www.securityfocus.com/bid/2070
Reference: XF:apc-apcupsd-dos
Reference:
URL:http://xforce.iss.net/static/5654.php
Name: CVE-2001-0041
Description:
Memory leak in Cisco Catalyst 4000, 5000, and 6000
series switches allows remote attackers to cause a
denial of service via a series of failed telnet
authentication attempts. Status: Entry
Reference: CISCO:20001206 Cisco Catalyst Memory
Leak Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/catalyst-memleak-pub.shtml
Reference: BID:2072
Reference:
URL:http://www.securityfocus.com/bid/2072
Reference: XF:cisco-catalyst-telnet-dos
Reference:
URL:http://xforce.iss.net/static/5656.php
Reference: OSVDB:801
Reference: URL:http://www.osvdb.org/801
Name: CVE-2001-0042
Description:
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers
to read arbitrary files via a modified .. (dot dot)
attack containing "%5c" (encoded backslash) sequences.
Status: Entry
Reference: BUGTRAQ:20001206 CHINANSL Security
Advisory(CSA-200011)
Reference:
URL:http://www.securityfocus.com/archive/1/149210
Reference: BID:2060
Reference:
URL:http://www.securityfocus.com/bid/2060
Reference: XF:apache-php-disclose-files
Reference:
URL:http://xforce.iss.net/static/5659.php
Name: CVE-2001-0043
Description:
phpGroupWare before 0.9.7 allows remote attackers to
execute arbitrary PHP commands by specifying a malicious
include file in the phpgw_info parameter of the
phpgw.inc.php program. Status: Entry
Reference: BUGTRAQ:20001206 (SRADV00006) Remote
command execution vulnerabilities in phpGroupWare
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0053.html
Reference:
MISC:http://sourceforge.net/project/shownotes.php?release_id=17604
Reference: BID:2069
Reference:
URL:http://www.securityfocus.com/bid/2069
Reference: XF:phpgroupware-include-files
Reference:
URL:http://xforce.iss.net/static/5650.php
Reference: OSVDB:1682
Reference: URL:http://www.osvdb.org/1682
Name: CVE-2001-0050
Description:
Buffer overflow in BitchX IRC client allows remote
attackers to cause a denial of service and possibly
execute arbitrary commands via an IP address that
resolves to a long DNS hostname or domain name.
Status: Entry
Reference: BUGTRAQ:20001207 BitchX DNS Overflow
Patch
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0081.html
Reference: BUGTRAQ:20001207 bitchx/ircd DNS
overflow demonstration
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0086.html
Reference: REDHAT:RHSA-2000:126
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2000-126.html
Reference: MANDRAKE:MDKSA-2000:079
Reference:
URL:http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-079.php3
Reference: FREEBSD:FreeBSD-SA-00:78
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:78.bitchx.v1.1.asc
Reference: CONECTIVA:CLA-2000:364
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000364
Reference: BID:2087
Reference:
URL:http://www.securityfocus.com/bid/2087
Reference: XF:irc-bitchx-dns-bo
Reference:
URL:http://xforce.iss.net/static/5701.php
Name: CVE-2001-0053
Description:
One-byte buffer overflow in replydirname function in
BSD-based ftpd allows remote attackers to gain root
privileges. Status: Entry
Reference: OPENBSD:20001218
Reference:
URL:http://www.openbsd.org/advisories/ftpd_replydirname.txt
Reference: NETBSD:NetBSD-SA2000-018
Reference:
URL:ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-018.txt.asc
Reference: BUGTRAQ:20001218 Trustix Security
Advisory - ed, tcsh, and ftpd-BSD
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0275.html
Reference: BID:2124
Reference:
URL:http://www.securityfocus.com/bid/2124
Reference: XF:bsd-ftpd-replydirname-bo
Reference:
URL:http://xforce.iss.net/static/5776.php
Name: CVE-2001-0054
Description:
Directory traversal vulnerability in FTP Serv-U before
2.5i allows remote attackers to escape the FTP root and
read arbitrary files by appending a string such as
"/..%20." to a CD command, a variant of a .. (dot dot)
attack. Status: Entry
Reference: BUGTRAQ:20001205 Serv-U FTP directory
traversal vunerability (all versions)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97604119024280&w=2
Reference: BUGTRAQ:20001205 (no subject)
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0043.html
Reference: BID:2052
Reference:
URL:http://www.securityfocus.com/bid/2052
Reference: XF:ftp-servu-homedir-travers
Reference:
URL:http://xforce.iss.net/static/5639.php
Reference: OSVDB:464
Reference: URL:http://www.osvdb.org/464
Name: CVE-2001-0055
Description:
CBOS 2.4.1 and earlier in Cisco 600 routers allows
remote attackers to cause a denial of service via a slow
stream of TCP SYN packets. Status: Entry
Reference: CISCO:20001204 Multiple
Vulnerabilities in CBOS
Reference:
URL:http://www.cisco.com/warp/public/707/CBOS-multiple.shtml
Reference: XF:cisco-cbos-syn-packets
Reference:
URL:http://xforce.iss.net/static/5627.php
Name: CVE-2001-0056
Description:
The Cisco Web Management interface in routers running
CBOS 2.4.1 and earlier does not log invalid logins,
which allows remote attackers to guess passwords without
detection. Status: Entry
Reference: CISCO:20001204 Multiple
Vulnerabilities in CBOS
Reference:
URL:http://www.cisco.com/warp/public/707/CBOS-multiple.shtml
Reference: XF:cisco-cbos-invalid-login
Reference:
URL:http://xforce.iss.net/static/5628.php
Name: CVE-2001-0057
Description:
Cisco 600 routers running CBOS 2.4.1 and earlier allow
remote attackers to cause a denial of service via a
large ICMP echo (ping) packet. Status: Entry
Reference: CISCO:20001204 Multiple
Vulnerabilities in CBOS
Reference:
URL:http://www.cisco.com/warp/public/707/CBOS-multiple.shtml
Reference: XF:cisco-cbos-icmp-echo
Reference:
URL:http://xforce.iss.net/static/5629.php
Name: CVE-2001-0058
Description:
The Web interface to Cisco 600 routers running CBOS
2.4.1 and earlier allow remote attackers to cause a
denial of service via a URL that does not end in a space
character. Status: Entry
Reference: CISCO:20001204 Multiple
Vulnerabilities in CBOS
Reference:
URL:http://www.cisco.com/warp/public/707/CBOS-multiple.shtml
Reference: XF:cisco-cbos-web-access
Reference:
URL:http://xforce.iss.net/static/5626.php
Reference: OSVDB:460
Reference: URL:http://www.osvdb.org/460
Name: CVE-2001-0059
Description:
patchadd in Solaris allows local users to overwrite
arbitrary files via a symlink attack. Status:
Entry
Reference: BUGTRAQ:20001218 Solaris patchadd(1)
(3) symlink vulnerabilty
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97720205217707&w=2
Reference: BID:2127
Reference:
URL:http://www.securityfocus.com/bid/2127
Reference: XF:solaris-patchadd-symlink
Reference:
URL:http://xforce.iss.net/static/5789.php
Name: CVE-2001-0060
Description:
Format string vulnerability in stunnel 3.8 and earlier
allows attackers to execute arbitrary commands via a
malformed ident username. Status: Entry
Reference: BUGTRAQ:20001218 Stunnel format bug
Reference:
URL:http://www.securityfocus.com/archive/1/151719
Reference: REDHAT:RHSA-2000:129
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2000-129.html
Reference: CONECTIVA:CLA-2000:363
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000363
Reference: BUGTRAQ:20001209 Trustix Security
Advisory - stunnel
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0337.html
Reference: DEBIAN:DSA-009
Reference:
URL:http://www.debian.org/security/2001/dsa-009
Reference: FREEBSD:FreeBSD-SA-01:05
Reference: XF:stunnel-format-logfile
Reference:
URL:http://xforce.iss.net/static/5807.php
Reference: BID:2128
Reference:
URL:http://www.securityfocus.com/bid/2128
Name: CVE-2001-0061
Description:
procfs in FreeBSD and possibly other operating systems
does not properly restrict access to per-process mem and
ctl files, which allows local users to gain root
privileges by forking a child process and executing a
privileged process from the child, while the parent
retains access to the child's address space. Status:
Entry
Reference: FREEBSD:FreeBSD-SA-00:77
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc
Reference: BID:2130
Reference:
URL:http://www.securityfocus.com/bid/2130
Reference: XF:procfs-elevate-privileges(6106)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6106
Reference: OSVDB:1697
Reference: URL:http://www.osvdb.org/1697
Name: CVE-2001-0062
Description:
procfs in FreeBSD and possibly other operating systems
allows local users to cause a denial of service by
calling mmap on the process' own mem file, which causes
the kernel to hang. Status: Entry
Reference: FREEBSD:FreeBSD-SA-00:77
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc
Reference: BID:2131
Reference:
URL:http://www.securityfocus.com/bid/2131
Reference: XF:procfs-mmap-dos(6107)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6107
Reference: OSVDB:1698
Reference: URL:http://www.osvdb.org/1698
Reference: OSVDB:6082
Reference: URL:http://www.osvdb.org/6082
Name: CVE-2001-0063
Description:
procfs in FreeBSD and possibly other operating systems
allows local users to bypass access control restrictions
for a jail environment and gain additional privileges.
Status: Entry
Reference: FREEBSD:FreeBSD-SA-00:77
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc
Reference: BID:2132
Reference:
URL:http://www.securityfocus.com/bid/2132
Reference: XF:procfs-access-control-bo(6108)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6108
Reference: OSVDB:1691
Reference: URL:http://www.osvdb.org/1691
Name: CVE-2001-0066
Description:
Secure Locate (slocate) allows local users to corrupt
memory via a malformed database file that specifies an
offset value that accesses memory outside of the
intended buffer. Status: Entry
Reference: BUGTRAQ:20001126 [MSY] S(ecure)Locate
heap corruption vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0356.html
Reference: DEBIAN:DSA-005-1
Reference:
URL:http://www.debian.org/security/2000/20001217a
Reference: DEBIAN:20001217a
Reference: MANDRAKE:MDKSA-2000:085
Reference:
URL:http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-085.php3
Reference: REDHAT:RHSA-2000:128
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2000-128.html
Reference: CONECTIVA:CLA-2001:369
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000369
Reference: TURBO:TLSA2001002-1
Reference:
URL:http://www.turbolinux.com/pipermail/tl-security-announce/2001-February/000144.html
Reference: XF:slocate-heap-execute-code(5594)
Reference:
URL:http://xforce.iss.net/static/5594.php
Reference: BID:2004
Reference:
URL:http://www.securityfocus.com/bid/2004
Name: CVE-2001-0069
Description:
dialog before 0.9a-20000118-3bis in Debian GNU/Linux
allows local users to overwrite arbitrary files via a
symlink attack. Status: Entry
Reference: DEBIAN:DSA-008-1
Reference:
URL:http://www.debian.org/security/2000/20001225
Reference: BID:2151
Reference:
URL:http://www.securityfocus.com/bid/2151
Reference: XF:dialog-symlink
Reference:
URL:http://xforce.iss.net/static/5809.php
Name: CVE-2001-0071
Description:
gpg (aka GnuPG) 1.0.4 and other versions does not
properly verify detached signatures, which allows
attackers to modify the contents of a file without
detection. Status: Entry
Reference: REDHAT:RHSA-2000:131
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2000-131.html
Reference: MANDRAKE:MDKSA-2000-087
Reference:
URL:http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-087.php3
Reference: DEBIAN:DSA-010-1
Reference:
URL:http://www.debian.org/security/2000/20001225b
Reference: XF:gnupg-detached-sig-modify
Reference:
URL:http://xforce.iss.net/static/5802.php
Reference: CONECTIVA:CLA-2000:368
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000368
Reference: BID:2141
Reference:
URL:http://www.securityfocus.com/bid/2141
Reference: BUGTRAQ:20001220 Trustix Security
Advisory - gnupg, ftpd-BSD
Reference:
URL:http://www.securityfocus.com/archive/1/152197
Reference: OSVDB:1699
Reference: URL:http://www.osvdb.org/1699
Name: CVE-2001-0072
Description:
gpg (aka GnuPG) 1.0.4 and other versions imports both
public and private keys from public key servers without
notifying the user about the private keys, which could
allow an attacker to break the web of trust. Status:
Entry
Reference: REDHAT:RHSA-2000:131
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2000-131.html
Reference: MANDRAKE:MDKSA-2000-087
Reference:
URL:http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-087.php3
Reference: DEBIAN:DSA-010-1
Reference:
URL:http://www.debian.org/security/2000/20001225b
Reference: CONECTIVA:CLA-2000:368
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000368
Reference: BUGTRAQ:20001220 Trustix Security
Advisory - gnupg, ftpd-BSD
Reference:
URL:http://www.securityfocus.com/archive/1/152197
Reference: BID:2153
Reference:
URL:http://www.securityfocus.com/bid/2153
Reference: XF:gnupg-reveal-private
Reference:
URL:http://xforce.iss.net/static/5803.php
Reference: OSVDB:1702
Reference: URL:http://www.osvdb.org/1702
Name: CVE-2001-0077
Description:
The clustmon service in Sun Cluster 2.x does not require
authentication, which allows remote attackers to obtain
sensitive information such as system logs and cluster
configurations. Status: Entry
Reference: BUGTRAQ:20001212 Two Holes in Sun
Cluster 2.x
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0180.html
Reference: XF:clustmon-no-authentication(6123)
Reference:
URL:http://xforce.iss.net/static/6123.php
Name: CVE-2001-0078
Description:
in.mond in Sun Cluster 2.x allows local users to read
arbitrary files via a symlink attack on the status file
of a host running HA-NFS. Status: Entry
Reference: BUGTRAQ:20001212 Two Holes in Sun
Cluster 2.x
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0180.html
Reference: XF:ha-nfs-symlink(6125)
Reference:
URL:http://xforce.iss.net/static/6125.php
Reference: OSVDB:6437
Reference: URL:http://www.osvdb.org/6437
Name: CVE-2001-0080
Description:
Cisco Catalyst 6000, 5000, or 4000 switches allow remote
attackers to cause a denial of service by connecting to
the SSH service with a non-SSH client, which generates a
protocol mismatch error. Status: Entry
Reference: CISCO:20001213 Cisco Catalyst SSH
Protocol Mismatch Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/catalyst-ssh-protocolmismatch-pub.shtml
Reference: BID:2117
Reference:
URL:http://www.securityfocus.com/bid/2117
Reference: XF:cisco-catalyst-ssh-mismatch
Reference:
URL:http://xforce.iss.net/static/5760.php
Name: CVE-2001-0081
Description:
swinit in nCipher does not properly disable the Operator
Card Set recovery feature even when explicitly disabled
by the user, which could allow attackers to gain access
to application keys. Status: Entry
Reference: BUGTRAQ:20001212 nCipher Security
Advisory: Operator Cards unexpectedly recoverable
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0152.html
Reference:
CONFIRM:http://active.ncipher.com/updates/advisory.txt
Reference:
XF:ncipher-recover-operator-cards(5999)
Reference:
URL:http://xforce.iss.net/static/5999.php
Reference: OSVDB:4849
Reference: URL:http://www.osvdb.org/4849
Name: CVE-2001-0083
Description:
Windows Media Unicast Service in Windows Media Services
4.0 and 4.1 does not properly shut down some types of
connections, producing a memory leak that allows remote
attackers to cause a denial of service via a series of
severed connections, aka the "Severed Windows Media
Server Connection" vulnerability. Status: Entry
Reference: MS:MS00-097
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS00-097.asp
Reference: MSKB:Q281256
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q281256
Reference:
XF:mediaservices-dropped-connection-dos
Reference:
URL:http://xforce.iss.net/static/5785.php
Name: CVE-2001-0085
Description:
Buffer overflow in Kermit communications software in
HP-UX 11.0 and earlier allows local users to cause a
denial of service and possibly execute arbitrary
commands. Status: Entry
Reference: HP:HPSBUX0012-135
Reference:
URL:http://archives.neohapsis.com/archives/hp/2000-q4/0083.html
Reference: BID:2170
Reference:
URL:http://www.securityfocus.com/bid/2170
Reference: XF:hpux-kermit-bo
Reference:
URL:http://xforce.iss.net/static/5793.php
Name: CVE-2001-0089
Description:
Internet Explorer 5.0 through 5.5 allows remote
attackers to read arbitrary files from the client via
the INPUT TYPE element in an HTML form, aka the "File
Upload via Form" vulnerability. Status: Entry
Reference: MS:MS00-093
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms00-093.asp
Reference: XF:ie-form-file-upload
Reference:
URL:http://xforce.iss.net/static/5615.php
Name: CVE-2001-0090
Description:
The Print Templates feature in Internet Explorer 5.5
executes arbitrary custom print templates without
prompting the user, which could allow an attacker to
execute arbitrary ActiveX controls, aka the "Browser
Print Template" vulnerability. Status: Entry
Reference: MS:MS00-093
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms00-093.asp
Reference: BID:2046
Reference:
URL:http://www.securityfocus.com/bid/2046
Reference: XF:ie-print-template(5614)
Reference:
URL:http://xforce.iss.net/static/5614.php
Name: CVE-2001-0091
Description:
The ActiveX control for invoking a scriptlet in Internet
Explorer 5.0 through 5.5 renders arbitrary file types
instead of HTML, which allows an attacker to read
arbitrary files, aka a variant of the "Scriptlet
Rendering" vulnerability. Status: Entry
Reference: MS:MS00-093
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms00-093.asp
Reference:
XF:ie-scriptlet-rendering-read-files(6085)
Reference:
URL:http://xforce.iss.net/static/6085.php
Reference: OSVDB:7820
Reference: URL:http://www.osvdb.org/7820
Name: CVE-2001-0092
Description:
A function in Internet Explorer 5.0 through 5.5 does not
properly verify the domain of a frame within a browser
window, which allows a remote attacker to read client
files, aka a new variant of the "Frame Domain
Verification" vulnerability. Status: Entry
Reference: MS:MS00-093
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms00-093.asp
Reference:
XF:ie-frame-verification-read-files(6086)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6086
Reference: OSVDB:7817
Reference: URL:http://www.osvdb.org/7817
Name: CVE-2001-0094
Description:
Buffer overflow in kdc_reply_cipher of libkrb (Kerberos
4 authentication library) in NetBSD 1.5 and FreeBSD 4.2
and earlier, as used in Kerberised applications such as
telnetd and login, allows local users to gain root
privileges. Status: Entry
Reference: NETBSD:NetBSD-SA2000-017
Reference:
URL:ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-017.txt.asc
Reference: FREEBSD:FreeBSD-SA-01:25
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:25.kerberosIV.asc
Reference:
XF:kerberos4-auth-packet-overflow(5734)
Reference:
URL:http://xforce.iss.net/static/5734.php
Name: CVE-2001-0095
Description:
catman in Solaris 2.7 and 2.8 allows local users to
overwrite arbitrary files via a symlink attack on the
sman_PID temporary file. Status: Entry
Reference: BUGTRAQ:20001218 Catman file
clobbering vulnerability Solaris 2.x
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0313.html
Reference: SUNBUG:4392144
Reference: XF:solaris-catman-symlink(5788)
Reference:
URL:http://xforce.iss.net/static/5788.php
Reference: OSVDB:6024
Reference: URL:http://www.osvdb.org/6024
Name: CVE-2001-0096
Description:
FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0
allows remote attackers to cause a denial of service via
a malformed form, aka the "Malformed Web Form
Submission" vulnerability. Status: Entry
Reference: MS:MS00-100
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS00-100.asp
Reference: XF:iis-web-form-submit
Reference:
URL:http://xforce.iss.net/static/5823.php
Name: CVE-2001-0099
Description:
bsguest.cgi guestbook script allows remote attackers to
execute arbitrary commands via shell metacharacters in
the email address. Status: Entry
Reference: BUGTRAQ:20001221 BS Scripts
Vulnerabilities
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0390.html
Reference: MISC:http://www.stanback.net/
Reference: XF:bsguest-cgi-execute-commands
Reference:
URL:http://xforce.iss.net/static/5796.php
Name: CVE-2001-0100
Description:
bslist.cgi mailing list script allows remote attackers
to execute arbitrary commands via shell metacharacters
in the email address. Status: Entry
Reference: BUGTRAQ:20001221 BS Scripts
Vulnerabilities
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0390.html
Reference: MISC:http://www.stanback.net/
Reference: XF:bslist-cgi-execute-commands
Reference:
URL:http://xforce.iss.net/static/5797.php
Name: CVE-2001-0105
Description:
Vulnerability in top in HP-UX 11.04 and earlier allows
local users to overwrite files owned by the "sys" group.
Status: Entry
Reference: HP:HPSBUX0012-134
Reference:
URL:http://archives.neohapsis.com/archives/hp/2000-q4/0079.html
Reference: XF:hp-top-sys-files
Reference:
URL:http://xforce.iss.net/static/5773.php
Name: CVE-2001-0106
Description:
Vulnerability in inetd server in HP-UX 11.04 and earlier
allows attackers to cause a denial of service when the
"swait" state is used by a server. Status: Entry
Reference: HP:HPSBUX0101-136
Reference:
URL:http://archives.neohapsis.com/archives/hp/2001-q1/0009.html
Reference: XF:hp-inetd-swait-dos(5904)
Reference:
URL:http://xforce.iss.net/static/5904.php
Name: CVE-2001-0108
Description:
PHP Apache module 4.0.4 and earlier allows remote
attackers to bypass .htaccess access restrictions via a
malformed HTTP request on an unrestricted page that
causes PHP to use those access controls on the next page
that is requested. Status: Entry
Reference: BUGTRAQ:20010112 PHP Security Advisory
- Apache Module bugs
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97957961212852
Reference: MANDRAKE:MDKSA-2001:013
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-013.php3
Reference: CONECTIVA:CLA-2001:373
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000373
Reference: DEBIAN:DSA-020
Reference:
URL:http://www.debian.org/security/2001/dsa-020
Reference: REDHAT:RHSA-2000:136
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2000-136.html
Reference: XF:php-htaccess-unauth-access(5940)
Reference:
URL:http://xforce.iss.net/static/5940.php
Reference: BID:2206
Reference:
URL:http://www.securityfocus.com/bid/2206
Name: CVE-2001-0109
Description:
rctab in SuSE 7.0 and earlier allows local users to
create or overwrite arbitrary files via a symlink attack
on the rctmp temporary file. Status: Entry
Reference: BUGTRAQ:20010113 Serious security flaw
in SuSE rctab
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0226.html
Reference: BUGTRAQ:20010117 Re: Serious security
flaw in SuSE rctab
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0272.html
Reference: BID:2207
Reference:
URL:http://www.securityfocus.com/bid/2207
Reference: XF:rctab-elevate-privileges(5945)
Reference:
URL:http://xforce.iss.net/static/5945.php
Name: CVE-2001-0110
Description:
Buffer overflow in jaZip Zip/Jaz drive manager allows
local users to gain root privileges via a long DISPLAY
environmental variable. Status: Entry
Reference: BUGTRAQ:20010114 Vulnerability in
jaZip.
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0228.html
Reference: DEBIAN:DSA-017
Reference:
URL:http://www.debian.org/security/2001/dsa-017
Reference: XF:jazip-display-bo(5942)
Reference:
URL:http://xforce.iss.net/static/5942.php
Reference: BID:2209
Reference:
URL:http://www.securityfocus.com/bid/2209
Name: CVE-2001-0111
Description:
Format string vulnerability in splitvt before 1.6.5
allows local users to execute arbitrary commands via the
-rcfile command line argument. Status: Entry
Reference: BUGTRAQ:20010114 [MSY] Multiple
vulnerabilities in splitvt
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97958269320974&w=2
Reference: DEBIAN:DSA-014-1
Reference:
URL:http://www.debian.org/security/2001/dsa-014
Reference: XF:splitvt-perserc-format-string(5948)
Reference:
URL:http://xforce.iss.net/static/5948.php
Reference: BID:2210
Reference:
URL:http://www.securityfocus.com/bid/2210
Name: CVE-2001-0115
Description:
Buffer overflow in arp command in Solaris 7 and earlier
allows local users to execute arbitrary commands via a
long -f parameter. Status: Entry
Reference: BUGTRAQ:20010111 Solaris Arp
Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97934312727101&w=2
Reference: BUGTRAQ:20010112 arp exploit
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97957435729702&w=2
Reference: SUN:00200
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/200&type=0&nav=sec.sba
Reference: XF:solaris-arp-bo(5928)
Reference:
URL:http://xforce.iss.net/static/5928.php
Reference: BID:2193
Reference:
URL:http://www.securityfocus.com/bid/2193
Name: CVE-2001-0116
Description:
gpm 1.19.3 allows local users to overwrite arbitrary
files via a symlink attack. Status: Entry
Reference: BUGTRAQ:20010110 Immunix OS Security
update for lots of temp file problems
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916374410647&w=2
Reference: MANDRAKE:MDKSA-2001:006
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-006.php3
Reference: BID:2188
Reference:
URL:http://www.securityfocus.com/bid/2188
Reference: XF:linux-gpm-symlink(5917)
Reference:
URL:http://xforce.iss.net/static/5917.php
Name: CVE-2001-0117
Description:
sdiff 2.7 in the diffutils package allows local users to
overwrite files via a symlink attack. Status:
Entry
Reference: BUGTRAQ:20010110 Immunix OS Security
update for lots of temp file problems
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916374410647&w=2
Reference: IMMUNIX:IMNX-2000-70-028-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2000-70-028-01
Reference: MANDRAKE:MDKSA-2001:008-1
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-008.php3
Reference: REDHAT:RHSA-2001:116
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-116.html
Reference: CERT-VN:VU#579928
Reference:
URL:http://www.kb.cert.org/vuls/id/579928
Reference: XF:linux-diffutils-sdiff-symlink(5914)
Reference:
URL:http://xforce.iss.net/static/5914.php
Reference: BID:2191
Reference:
URL:http://www.securityfocus.com/bid/2191
Name: CVE-2001-0118
Description:
rdist 6.1.5 allows local users to overwrite arbitrary
files via a symlink attack. Status: Entry
Reference: BUGTRAQ:20010110 Immunix OS Security
update for lots of temp file problems
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916374410647&w=2
Reference: MANDRAKE:MDKSA-2001-005
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-005.php3
Reference: BID:2195
Reference:
URL:http://www.securityfocus.com/bid/2195
Reference: XF:rdist-symlink(5925)
Reference:
URL:http://xforce.iss.net/static/5925.php
Name: CVE-2001-0119
Description:
getty_ps 2.0.7j allows local users to overwrite
arbitrary files via a symlink attack. Status:
Entry
Reference: BUGTRAQ:20010110 Immunix OS Security
update for lots of temp file problems
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916374410647&w=2
Reference: MANDRAKE:MDKSA-2001:004
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-004.php3
Reference: BID:2194
Reference:
URL:http://www.securityfocus.com/bid/2194
Reference: XF:gettyps-symlink(5924)
Reference:
URL:http://xforce.iss.net/static/5924.php
Name: CVE-2001-0120
Description:
useradd program in shadow-utils program may allow local
users to overwrite arbitrary files via a symlink attack.
Status: Entry
Reference: BUGTRAQ:20010110 Immunix OS Security
update for lots of temp file problems
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916374410647&w=2
Reference: MANDRAKE:MDKSA-2001:007
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-007.php3
Reference: BID:2196
Reference:
URL:http://www.securityfocus.com/bid/2196
Reference: XF:shadow-utils-useradd-symlink(5927)
Reference:
URL:http://xforce.iss.net/static/5927.php
Name: CVE-2001-0121
Description:
ImageCast Control Center 4.1.0 allows remote attackers
to cause a denial of service (resource exhaustion or
system crash) via a long string to port 12002.
Status: Entry
Reference: BUGTRAQ:20010108 def-2001-01:
ImageCast IC3 Control Center DoS
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0071.html
Reference: XF:storagesoft-imagecast-dos(5901)
Reference:
URL:http://xforce.iss.net/static/5901.php
Reference: BID:2174
Reference:
URL:http://www.securityfocus.com/bid/2174
Name: CVE-2001-0122
Description:
Kernel leak in AfpaCache module of the Fast Response
Cache Accelerator (FRCA) component of IBM HTTP Server
1.3.x and Websphere 3.52 allows remote attackers to
cause a denial of service via a series of malformed HTTP
requests that generate a "bad request" error. Status:
Entry
Reference: BUGTRAQ:20010108 def-2001-02: IBM
Websphere 3.52 Kernel Leak DoS
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0079.html
Reference: BUGTRAQ:20010307 def-2001-02: IBM HTTP
Server Kernel Leak DoS (re-release)
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0061.html
Reference:
CONFIRM:http://www-4.ibm.com/software/webservers/security.html
Reference: BID:2175
Reference:
URL:http://www.securityfocus.com/bid/2175
Reference: XF:ibm-websphere-dos(5900)
Reference:
URL:http://xforce.iss.net/static/5900.php
Name: CVE-2001-0123
Description:
Directory traversal vulnerability in eXtropia
bbs_forum.cgi 1.0 allows remote attackers to read
arbitrary files via a .. (dot dot) attack on the file
parameter. Status: Entry
Reference: BUGTRAQ:20010107 Cgisecurity.com
Advisory #3.1
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97905792214999&w=2
Reference:
CONFIRM:http://www.extropia.com/hacks/bbs_security.html
Reference: BID:2177
Reference:
URL:http://www.securityfocus.com/bid/2177
Reference: XF:http-cgi-bbs-forum(5906)
Reference:
URL:http://xforce.iss.net/static/5906.php
Reference: OSVDB:3546
Reference: URL:http://www.osvdb.org/3546
Name: CVE-2001-0124
Description:
Buffer overflow in exrecover in Solaris 2.6 and earlier
possibly allows local users to gain privileges via a
long command line argument. Status: Entry
Reference: BUGTRAQ:20010109 Solaris
/usr/lib/exrecover buffer overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97908386502156&w=2
Reference: SUNBUG:4161925
Reference: XF:solaris-exrecover-bo(5913)
Reference:
URL:http://xforce.iss.net/static/5913.php
Reference: BID:2179
Reference:
URL:http://www.securityfocus.com/bid/2179
Name: CVE-2001-0125
Description:
exmh 2.2 and earlier allows local users to overwrite
arbitrary files via a symlink attack on the exmhErrorMsg
temporary file. Status: Entry
Reference: BUGTRAQ:20001231 Advisory: exmh
symlink vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97846489313059&w=2
Reference: BUGTRAQ:20010112 exmh security
vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97958594330100&w=2
Reference:
CONFIRM:http://www.beedub.com/exmh/symlink.html
Reference: FREEBSD:FreeBSD-SA-01:17
Reference:
URL:http://archives.neohapsis.com/archives/freebsd/2001-01/0543.html
Reference: MANDRAKE:MDKSA-2001:015
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-015.php3
Reference: DEBIAN:DSA-022
Reference:
URL:http://www.debian.org/security/2001/dsa-022
Reference: XF:exmh-error-symlink
Reference:
URL:http://xforce.iss.net/static/5829.php
Name: CVE-2001-0126
Description:
Oracle XSQL servlet 1.0.3.0 and earlier allows remote
attackers to execute arbitrary Java code by redirecting
the XSQL server to another source via the xml-stylesheet
parameter in the xslt stylesheet. Status: Entry
Reference: BUGTRAQ:20010109 Oracle XSQL servlet
and xml-stylesheet allow executing java on the web
server
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97906670012796&w=2
Reference: BUGTRAQ:20010123 Patch for Potential
Vulnerability in Oracle XSQL Servlet
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98027700625521&w=2
Reference: XF:oracle-xsql-execute-code(5905)
Reference:
URL:http://xforce.iss.net/static/5905.php
Name: CVE-2001-0128
Description:
Zope before 2.2.4 does not properly compute local roles,
which could allow users to bypass specified access
restrictions and gain privileges. Status: Entry
Reference: MANDRAKE:MDKSA-2000-083
Reference:
URL:http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-083.php3
Reference: CONECTIVA:CLA-2000:365
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000365
Reference: REDHAT:RHSA-2000:127
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2000-127.html
Reference: DEBIAN:DSA-006-1
Reference:
URL:http://www.debian.org/security/2000/20001219
Reference: FREEBSD:FreeBSD-SA-01:06
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:06.zope.asc
Reference: XF:zope-calculate-roles
Reference:
URL:http://xforce.iss.net/static/5777.php
Reference: OSVDB:6284
Reference: URL:http://www.osvdb.org/6284
Name: CVE-2001-0129
Description:
Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and
earlier allows remote attackers to cause a denial of
service and possibly execute arbitrary commands via a
long connect request. Status: Entry
Reference: BUGTRAQ:20010117 [pkc] remote heap
overflow in tinyproxy
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97975486527750&w=2
Reference: DEBIAN:DSA-018
Reference:
URL:http://www.debian.org/security/2001/dsa-018
Reference: FREEBSD:FreeBSD-SA-01:15
Reference: BID:2217
Reference:
URL:http://www.securityfocus.com/bid/2217
Reference: XF:tinyproxy-remote-bo(5954)
Reference:
URL:http://xforce.iss.net/static/5954.php
Name: CVE-2001-0130
Description:
Buffer overflow in HTML parser of the Lotus R5 Domino
Server before 5.06, and Domino Client before 5.05,
allows remote attackers to cause a denial of service and
possibly execute arbitrary commands via a malformed font
size specifier. Status: Entry
Reference:
MISC:http://service1.symantec.com/sarc/sarc.nsf/info/html/Lotus.Domino.Denial.of.Service.Malformed.HTML.Email.html
Reference: XF:lotus-html-bo(6207)
Reference:
URL:http://xforce.iss.net/static/6207.php
Name: CVE-2001-0136
Description:
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers
to cause a denial of service via a series of USER
commands, and possibly SIZE commands if the server has
been improperly installed. Status: Entry
Reference: BUGTRAQ:20001220 ProFTPD 1.2.0 Memory
leakage - denial of service
Reference:
URL:http://www.securityfocus.com/archive/1/152206
Reference: BUGTRAQ:20010109 Memory leakage in
ProFTPd leads to remote DoS (SIZE FTP); (Exploit Code)
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0122.html
Reference: BUGTRAQ:20010110 Re: Memory leakage in
ProFTPd leads to remote DoS (SIZE FTP); (Exploit Code)
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0132.html
Reference: MANDRAKE:MDKSA-2001:021
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-021.php3
Reference: DEBIAN:DSA-029
Reference:
URL:http://www.debian.org/security/2001/dsa-029
Reference: CONECTIVA:CLA-2001:380
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000380
Reference: BUGTRAQ:20010213 Trustix Security
Advisory - proftpd, kernel
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html
Reference: XF:proftpd-size-memory-leak
Reference:
URL:http://xforce.iss.net/static/5801.php
Name: CVE-2001-0137
Description:
Windows Media Player 7 allows remote attackers to
execute malicious Java applets in Internet Explorer
clients by enclosing the applet in a skin file named
skin.wmz, then referencing that skin in the codebase
parameter to an applet tag, aka the Windows Media Player
Skins File Download" vulnerability. Status: Entry
Reference: BUGTRAQ:20010115 Windows Media Player
7 and IE java vulnerability - executing arbitrary
programs
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97958100816503&w=2
Reference: MS:MS01-010
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-010.asp
Reference:
XF:win-mediaplayer-arbitrary-code(5937)
Reference:
URL:http://xforce.iss.net/static/5937.php
Reference: BID:2203
Reference:
URL:http://www.securityfocus.com/bid/2203
Name: CVE-2001-0138
Description:
privatepw program in wu-ftpd before 2.6.1-6 allows local
users to overwrite arbitrary files via a symlink attack.
Status: Entry
Reference: BUGTRAQ:20010110 Immunix OS Security
update for lots of temp file problems
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916374410647&w=2
Reference: MANDRAKE:MDKSA-2001-001
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-001.php3
Reference: DEBIAN:DSA-016
Reference:
URL:http://www.debian.org/security/2001/dsa-016
Reference: BID:2189
Reference:
URL:http://www.securityfocus.com/bid/2189
Reference:
XF:linux-wuftpd-privatepw-symlink(5915)
Reference:
URL:http://xforce.iss.net/static/5915.php
Name: CVE-2001-0139
Description:
inn 2.2.3 allows local users to overwrite arbitrary
files via a symlink attack in some configurations.
Status: Entry
Reference: BUGTRAQ:20010110 Immunix OS Security
update for lots of temp file problems
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916374410647&w=2
Reference: MANDRAKE:MDKSA-2001:010
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-010.php3
Reference: CALDERA:CSSA-2001-001.0
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-001.0.txt
Reference: XF:linux-inn-symlink(5916)
Reference:
URL:http://xforce.iss.net/static/5916.php
Reference: BID:2190
Reference:
URL:http://www.securityfocus.com/bid/2190
Name: CVE-2001-0140
Description:
arpwatch 2.1a4 allows local users to overwrite arbitrary
files via a symlink attack in some configurations.
Status: Entry
Reference: BUGTRAQ:20010110 Immunix OS Security
update for lots of temp file problems
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916374410647&w=2
Reference: MANDRAKE:MDKSA-2001:002
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-002.php3
Reference: XF:tcpdump-arpwatch-symlink(5922)
Reference:
URL:http://xforce.iss.net/static/5922.php
Reference: BID:2183
Reference:
URL:http://www.securityfocus.com/bid/2183
Name: CVE-2001-0141
Description:
mgetty 1.1.22 allows local users to overwrite arbitrary
files via a symlink attack in some configurations.
Status: Entry
Reference: BUGTRAQ:20010110 Immunix OS Security
update for lots of temp file problems
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916374410647&w=2
Reference: MANDRAKE:MDKSA-2001:009
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-009.php3
Reference: DEBIAN:DSA-011
Reference:
URL:http://www.debian.org/security/2001/dsa-011
Reference: CALDERA:CSSA-2001-002.0
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-002.0.txt
Reference: REDHAT:RHSA-2001:050
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-050.html
Reference: BID:2187
Reference:
URL:http://www.securityfocus.com/bid/2187
Reference: XF:linux-mgetty-symlink(5918)
Reference:
URL:http://xforce.iss.net/static/5918.php
Name: CVE-2001-0142
Description:
squid 2.3 and earlier allows local users to overwrite
arbitrary files via a symlink attack in some
configurations. Status: Entry
Reference: BUGTRAQ:20010112 Trustix Security
Advisory - diffutils squid
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0212.html
Reference: BUGTRAQ:20010110 Immunix OS Security
update for lots of temp file problems
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916374410647&w=2
Reference: MANDRAKE:MDKSA-2001:003
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-003.php3
Reference: DEBIAN:DSA-019
Reference:
URL:http://www.debian.org/security/2001/dsa-019
Reference: XF:squid-email-symlink(5921)
Reference:
URL:http://xforce.iss.net/static/5921.php
Reference: BID:2184
Reference:
URL:http://www.securityfocus.com/bid/2184
Name: CVE-2001-0143
Description:
vpop3d program in linuxconf 1.23r and earlier allows
local users to overwrite arbitrary files via a symlink
attack. Status: Entry
Reference: BUGTRAQ:20010110 Immunix OS Security
update for lots of temp file problems
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916374410647&w=2
Reference: MANDRAKE:MDKSA-2001:011
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-011.php3
Reference: BID:2186
Reference:
URL:http://www.securityfocus.com/bid/2186
Reference: XF:linuxconf-vpop3d-symlink(5923)
Reference:
URL:http://xforce.iss.net/static/5923.php
Name: CVE-2001-0144
Description:
CORE SDI SSH1 CRC-32 compensation attack detector allows
remote attackers to execute arbitrary commands on an SSH
server or client via an integer overflow. Status:
Entry
Reference: BINDVIEW:20010208 Remote vulnerability
in SSH daemon crc32 compensation attack detector
Reference:
URL:http://razor.bindview.com/publish/advisories/adv_ssh1crc.html
Reference: BUGTRAQ:20010208 [CORE SDI ADVISORY]
SSH1 CRC-32 compensation attack detector
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98168366406903&w=2
Reference: BUGTRAQ:20011122 Secure Computing
SafeWord uses vulnerable ssh server
Reference: CERT:CA-2001-35
Reference:
URL:http://www.cert.org/advisories/CA-2001-35.html
Reference: BID:2347
Reference:
URL:http://www.securityfocus.com/bid/2347
Reference: OSVDB:503
Reference: URL:http://www.osvdb.org/503
Reference: OSVDB:795
Reference: URL:http://www.osvdb.org/795
Reference: XF:ssh-deattack-overwrite-memory(6083)
Reference:
URL:http://xforce.iss.net/static/6083.php
Name: CVE-2001-0147
Description:
Buffer overflow in Windows 2000 event viewer snap-in
allows attackers to execute arbitrary commands via a
malformed field that is improperly handled during the
detailed view of event records. Status: Entry
Reference: MS:MS01-013
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-013.asp
Name: CVE-2001-0148
Description:
The WMP ActiveX Control in Windows Media Player 7 allows
remote attackers to execute commands in Internet
Explorer via javascript URLs, a variant of the "Frame
Domain Verification" vulnerability. Status: Entry
Reference: BUGTRAQ:20010101 Windows Media Player
7 and IE vulnerability - executing arbitrary programs
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0000.html
Reference: MS:MS01-015
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-015.asp
Reference: XF:media-player-execute-commands(6227)
Reference:
URL:http://xforce.iss.net/static/6227.php
Name: CVE-2001-0149
Description:
Windows Scripting Host in Internet Explorer 5.5 and
earlier allows remote attackers to read arbitrary files
via the GetObject Javascript function and the htmlfile
ActiveX object. Status: Entry
Reference: BUGTRAQ:20000926 IE 5.5/Outlook
Express security vulnerability - GetObject() expose
user's files
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0305.html
Reference: NTBUGTRAQ:20000926 IE 5.5/Outlook
Express security vulnerability - GetObject() expose
user's files
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=96999020527583&w=2
Reference: MS:MS01-015
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-015.asp
Reference: BID:1718
Reference:
URL:http://www.securityfocus.com/bid/1718
Reference: XF:ie-getobject-expose-files(5293)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/5293
Name: CVE-2001-0150
Description:
Internet Explorer 5.5 and earlier executes Telnet
sessions using command line arguments that are specified
by the web site, which could allow remote attackers to
execute arbitrary commands if the IE client is using the
Telnet client provided in Services for Unix (SFU) 2.0,
which creates session transcripts. Status: Entry
Reference: BUGTRAQ:20010313 Internet Explorer and
Services for Unix 2.0 Telnet Client
Reference: MS:MS01-015
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-015.asp
Reference: BID:2463
Reference:
URL:http://www.securityfocus.com/bid/2463
Reference: OSVDB:7816
Reference: URL:http://www.osvdb.org/7816
Reference: XF:ie-telnet-execute-commands(6230)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6230
Name: CVE-2001-0151
Description:
IIS 5.0 allows remote attackers to cause a denial of
service via a series of malformed WebDAV requests.
Status: Entry
Reference: MS:MS01-016
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-016.asp
Reference: XF:iis-webdav-dos(6205)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6205
Reference: OVAL:oval:org.mitre.oval:def:90
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:90
Name: CVE-2001-0152
Description:
The password protection option for the Compressed
Folders feature in Plus! for Windows 98 and Windows Me
writes password information to a file, which allows
local users to recover the passwords and read the
compressed folders. Status: Entry
Reference: MS:MS01-019
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-019.asp
Name: CVE-2001-0153
Description:
Buffer overflow in VB-TSQL debugger object
(vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition
allows remote attackers to execute arbitrary commands.
Status: Entry
Reference: BINDVIEW:20010327 Remote buffer
overflow in DCOM VB T-SQL debugger
Reference:
URL:http://razor.bindview.com/publish/advisories/adv_vbtsql.html
Reference: MS:MS01-018
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-018.asp
Name: CVE-2001-0154
Description:
HTML e-mail feature in Internet Explorer 5.5 and earlier
allows attackers to execute attachments by setting an
unusual MIME type for the attachment, which Internet
Explorer does not process correctly. Status:
Entry
Reference: BUGTRAQ:20010330 Incorrect MIME Header
Can Cause IE to Execute E-mail Attachment
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98596775905044&w=2
Reference: MS:MS01-020
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-020.asp
Reference: CERT:CA-2001-06
Reference:
URL:http://www.cert.org/advisories/CA-2001-06.html
Reference: CIAC:L-066
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-066.shtml
Reference: BID:2524
Reference:
URL:http://www.securityfocus.com/bid/2524
Reference: OSVDB:7806
Reference: URL:http://www.osvdb.org/7806
Reference: OVAL:oval:org.mitre.oval:def:141
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:141
Reference: SECTRACK:1001197
Reference:
URL:http://securitytracker.com/id?1001197
Reference: XF:ie-mime-execute-code(6306)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6306
Name: CVE-2001-0155
Description:
Format string vulnerability in VShell SSH gateway 1.0.1
and earlier allows remote attackers to execute arbitrary
commands via a user name that contains format string
specifiers. Status: Entry
Reference: ATSTAKE:A021601-1
Reference:
URL:http://www.atstake.com/research/advisories/2001/a021601-1.txt
Reference:
CONFIRM:http://www.vandyke.com/products/vshell/security102.html
Name: CVE-2001-0156
Description:
VShell SSH gateway 1.0.1 and earlier has a default port
forwarding rule of 0.0.0.0/0.0.0.0, which could allow
local users conduct arbitrary port forwarding to other
systems. Status: Entry
Reference: ATSTAKE:A021601-1
Reference:
URL:http://www.atstake.com/research/advisories/2001/a021601-1.txt
Reference:
CONFIRM:http://www.vandyke.com/products/vshell/security102.html
Reference: XF:vshell-port-forwarding-rule(6148)
Reference:
URL:http://xforce.iss.net/static/6148.php
Reference: BID:2402
Reference:
URL:http://www.securityfocus.com/bid/2402
Name: CVE-2001-0157
Description:
Debugging utility in the backdoor mode of Palm OS 3.5.2
and earlier allows attackers with physical access to a
Palm device to bypass access restrictions and obtain
passwords, even if the system lockout mechanism is
enabled. Status: Entry
Reference: ATSTAKE:A030101-1
Reference:
URL:http://www.atstake.com/research/advisories/2001/a030101-1.txt
Reference: XF:palm-debug-bypass-password(6196)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6196
Name: CVE-2001-0164
Description:
Buffer overflow in Netscape Directory Server 4.12 and
earlier allows remote attackers to cause a denial of
service or execute arbitrary commands via a malformed
recipient field. Status: Entry
Reference: ATSTAKE:A030701-1
Reference:
URL:http://www.atstake.com/research/advisories/2001/a030701-1.txt
Reference: XF:netscape-directory-server-bo(6233)
Reference:
URL:http://xforce.iss.net/static/6233.php
Name: CVE-2001-0165
Description:
Buffer overflow in ximp40 shared library in Solaris 7
and Solaris 8 allows local users to gain privileges via
a long "arg0" (process name) argument. Status:
Entry
Reference: BUGTRAQ:20010131
[SPSadvisory#40]Solaris7/8 ximp40 shared library buffer
overflow
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0517.html
Reference: SUNBUG:4409148
Reference: XF:solaris-ximp40-bo
Reference:
URL:http://xforce.iss.net/static/6039.php
Reference: BID:2322
Reference:
URL:http://www.securityfocus.com/bid/2322
Name: CVE-2001-0166
Description:
Macromedia Shockwave Flash plugin version 8 and earlier
allows remote attackers to cause a denial of service via
malformed tag length specifiers in a SWF file.
Status: Entry
Reference: BUGTRAQ:20001229 Shockwave Flash
buffer overflow
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0491.html
Reference: XF:shockwave-flash-swf-bo
Reference:
URL:http://xforce.iss.net/static/5826.php
Name: CVE-2001-0169
Description:
When using the LD_PRELOAD environmental variable in SUID
or SGID applications, glibc does not verify that
preloaded libraries in /etc/ld.so.cache are also
SUID/SGID, which could allow a local user to overwrite
arbitrary files by loading a library from /lib or
/usr/lib. Status: Entry
Reference: MANDRAKE:MDKSA-2001:012
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-012.php3?dis=7.2
Reference: SUSE:SuSE-SA:2001:01
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_001_glibc_txt.html
Reference: CALDERA:CSSA-2001-007
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-007.0.txt
Reference: REDHAT:RHSA-2001:002
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-002.html
Reference: DEBIAN:DSA-039
Reference:
URL:http://www.debian.org/security/2001/dsa-039
Reference: TURBO:TLSA2000021-2
Reference:
URL:http://archives.neohapsis.com/archives/linux/turbolinux/2001-q1/0004.html
Reference: BUGTRAQ:20010121 Trustix Security
Advisory - glibc
Reference:
URL:http://www.securityfocus.com/archive/1/157650
Reference: BID:2223
Reference:
URL:http://www.securityfocus.com/bid/2223
Reference: XF:linux-glibc-preload-overwrite
Reference:
URL:http://xforce.iss.net/static/5971.php
Name: CVE-2001-0170
Description:
glibc 2.1.9x and earlier does not properly clear the
RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS
environmental variables when executing setuid/setgid
programs, which could allow local users to read
arbitrary files. Status: Entry
Reference: BUGTRAQ:20010110 Glibc Local Root
Exploit
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0131.html
Reference: BUGTRAQ:20010110 [slackware-security]
glibc 2.2 local vulnerability on setuid binaries
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0186.html
Reference: REDHAT:RHSA-2001:001
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-001.html
Reference: BID:2181
Reference:
URL:http://www.securityfocus.com/bid/2181
Reference: XF:linux-glibc-read-files
Reference:
URL:http://xforce.iss.net/static/5907.php
Name: CVE-2001-0174
Description:
Buffer overflow in Trend Micro Virus Buster 2001 8.00
allows remote attackers to cause a denial of service,
and possibly execute arbitrary commands, via a large
"To" address. Status: Entry
Reference: BUGTRAQ:20010130 Security hole in
Virus Buster 2001
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0500.html
Reference: XF:virusbuster-mua-bo(6034)
Reference:
URL:http://xforce.iss.net/static/6034.php
Reference: OSVDB:6138
Reference: URL:http://www.osvdb.org/6138
Name: CVE-2001-0175
Description:
The caching module in Netscape Fasttrack Server 4.1
allows remote attackers to cause a denial of service
(resource exhaustion) by requesting a large number of
non-existent URLs. Status: Entry
Reference: BUGTRAQ:20010122 def-2001-05: Netscape
Fasttrack Server Caching DoS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98021351718874&w=2
Reference: BUGTRAQ:20010124 iPlanet
FastTrack/Enterprise 4.1 DoS clarifications
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98035833331446&w=2
Reference: BID:2273
Reference:
URL:http://www.securityfocus.com/bid/2273
Reference: XF:netscape-fasttrack-cache-dos(5985)
Reference:
URL:http://xforce.iss.net/static/5985.php
Name: CVE-2001-0176
Description:
The setuid doroot program in Voyant Sonata 3.x executes
arbitrary command line arguments, which allows local
users to gain root privileges. Status: Entry
Reference: BUGTRAQ:20001218 More Sonata
Conferencing software vulnerabilities.
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0278.html
Reference: BID:2125
Reference:
URL:http://www.securityfocus.com/bid/2125
Reference: XF:sonata-command-execute(5787)
Reference:
URL:http://xforce.iss.net/static/5787.php
Name: CVE-2001-0178
Description:
kdesu program in KDE2 (KDE before 2.2.0-6) does not
properly verify the owner of a UNIX socket that is used
to send a password, which allows local users to steal
passwords and gain privileges. Status: Entry
Reference: MANDRAKE:MDKSA-2001:018
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-018.php3?dis=7.2
Reference: CALDERA:CSSA-2001-005.0
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-005.0.txt
Reference: SUSE:SuSE-SA:2001:02
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_002_kdesu_txt.html
Reference: XF:kde2-kdesu-retrieve-passwords
Reference:
URL:http://xforce.iss.net/static/5995.php
Name: CVE-2001-0179
Description:
Allaire JRun 3.0 allows remote attackers to list
contents of the WEB-INF directory, and the web.xml file
in the WEB-INF directory, via a malformed URL that
contains a "." Status: Entry
Reference: ALLAIRE:ASB01-02
Reference:
URL:http://www.allaire.com/handlers/index.cfm?ID=19546&Method=Full
Reference: XF:jrun-webinf-file-retrieval
Reference:
URL:http://xforce.iss.net/static/6008.php
Name: CVE-2001-0182
Description:
FireWall-1 4.1 with a limited-IP license allows remote
attackers to cause a denial of service by sending a
large number of spoofed IP packets with various source
addresses to the inside interface, which floods the
console with warning messages and consumes CPU
resources. Status: Entry
Reference: BUGTRAQ:20010117 Licensing Firewall-1
DoS Attack
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0298.html
Reference: XF:fw1-limited-license-dos
Reference:
URL:http://xforce.iss.net/static/5966.php
Reference: BID:2238
Reference:
URL:http://www.securityfocus.com/bid/2238
Reference: OSVDB:1733
Reference: URL:http://www.osvdb.org/1733
Name: CVE-2001-0183
Description:
ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote
attackers to bypass access restrictions by setting the
ECE flag in a TCP packet, which makes the packet appear
to be part of an established connection. Status:
Entry
Reference: BUGTRAQ:20010125 ecepass - proof of
concept code for FreeBSD ipfw bypass
Reference:
URL:http://www.security-express.com/archives/bugtraq/2001-01/0424.html
Reference: FREEBSD:FreeBSD-SA-01:08
Reference:
URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:08.ipfw.asc
Reference: CIAC:L-029
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-029.shtml
Reference: BID:2293
Reference:
URL:http://www.securityfocus.com/bid/2293
Reference: OSVDB:1743
Reference: URL:http://www.osvdb.org/1743
Reference: XF:ipfw-bypass-firewall(5998)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/5998
Name: CVE-2001-0185
Description:
Netopia R9100 router version 4.6 allows authenticated
users to cause a denial of service by using the router's
telnet program to connect to the router's IP address,
which causes a crash. Status: Entry
Reference: BUGTRAQ:20010123 Make The Netopia
R9100 Router To Crash
Reference:
URL:http://www.securityfocus.com/archive/1/157952
Reference: BID:2287
Reference:
URL:http://www.securityfocus.com/bid/2287
Reference: XF:netopia-telnet-dos
Reference:
URL:http://xforce.iss.net/static/6001.php
Name: CVE-2001-0187
Description:
Format string vulnerability in wu-ftp 2.6.1 and earlier,
when running with debug mode enabled, allows remote
attackers to execute arbitrary commands via a malformed
argument that is recorded in a PASV port assignment.
Status: Entry
Reference: DEBIAN:DSA-016
Reference:
URL:http://www.debian.org/security/2001/dsa-016
Reference:
CONFIRM:ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_current/missing_format_strings.patch
Reference: CONECTIVA:CLA-2001:443
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000443
Reference: BID:2296
Reference:
URL:http://www.securityfocus.com/bid/2296
Reference: XF:wuftp-debug-format-string
Reference:
URL:http://xforce.iss.net/static/6020.php
Name: CVE-2001-0189
Description:
Directory traversal vulnerability in LocalWEB2000 HTTP
server allows remote attackers to read arbitrary
commands via a .. (dot dot) attack in an HTTP GET
request. Status: Entry
Reference: BUGTRAQ:20010119 LocalWEB2000
Directory Traversal Vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0346.html
Reference: BID:2268
Reference:
URL:http://www.securityfocus.com/bid/2268
Reference: XF:localweb2k-directory-traversal
Reference:
URL:http://xforce.iss.net/static/5982.php
Name: CVE-2001-0190
Description:
Buffer overflow in /usr/bin/cu in Solaris 2.8 and
earlier, and possibly other operating systems, allows
local users to gain privileges by executing cu with a
long program name (arg0). Status: Entry
Reference: BUGTRAQ:20010117 Solaris /usr/bin/cu
Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97983943716311&w=2
Reference: BUGTRAQ:20010123 Solaris /usr/bin/cu
Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98028642319440&w=2
Reference: SUNBUG:4406722
Reference: XF:cu-argv-bo(6224)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6224
Name: CVE-2001-0191
Description:
gnuserv before 3.12, as shipped with XEmacs, does not
properly check the specified length of an X Windows
MIT-MAGIC-COOKIE cookie, which allows remote attackers
to execute arbitrary commands via a buffer overflow, or
brute force authentication by using a short cookie
length. Status: Entry
Reference: BUGTRAQ:20010202 Remote vulnerability
in gnuserv/XEmacs
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0030.html
Reference: REDHAT:RHSA-2001:010
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-010.html
Reference: REDHAT:RHSA-2001:011
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-011.html
Reference: MANDRAKE:MDKSA-2001:019
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-019.php3
Reference: XF:gnuserv-tcp-cookie-overflow(6056)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6056
Name: CVE-2001-0193
Description:
Format string vulnerability in man in some Linux
distributions allows local users to gain privileges via
a malformed -l parameter. Status: Entry
Reference: BUGTRAQ:20010131 SuSe / Debian man
package format string vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98096782126481&w=2
Reference: DEBIAN:DSA-028
Reference:
URL:http://www.debian.org/security/2001/dsa-028
Reference: BID:2327
Reference:
URL:http://www.securityfocus.com/bid/2327
Reference: XF:man-i-format-string(6059)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6059
Name: CVE-2001-0194
Description:
Buffer overflow in httpGets function in CUPS 1.1.5
allows remote attackers to execute arbitrary commands
via a long input line. Status: Entry
Reference: MANDRAKE:MDKSA-2001:020-1
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-020.php3
Reference: XF:cups-httpgets-dos(6043)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6043
Reference: OSVDB:6064
Reference: URL:http://www.osvdb.org/6064
Name: CVE-2001-0195
Description:
sash before 3.4-4 in Debian GNU/Linux does not properly
clone /etc/shadow, which makes it world-readable and
could allow local users to gain privileges via password
cracking. Status: Entry
Reference: DEBIAN:DSA-015
Reference:
URL:http://www.debian.org/security/2001/dsa-015
Reference: XF:linux-sash-shadow-readable
Reference:
URL:http://xforce.iss.net/static/5994.php
Name: CVE-2001-0196
Description:
inetd ident server in FreeBSD 4.x and earlier does not
properly set group permissions, which allows remote
attackers to read the first 16 bytes of files that are
accessible by the wheel group. Status: Entry
Reference: FREEBSD:FreeBSD-SA-01:11
Reference:
URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:11.inetd.v1.1.asc
Reference: BID:2324
Reference:
URL:http://www.securityfocus.com/bid/2324
Reference: XF:inetd-ident-read-files(6052)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6052
Reference: OSVDB:1753
Reference: URL:http://www.osvdb.org/1753
Name: CVE-2001-0197
Description:
Format string vulnerability in print_client in icecast
1.3.8beta2 and earlier allows remote attackers to
execute arbitrary commands. Status: Entry
Reference: BUGTRAQ:20010121 [pkc] format bugs in
icecast 1.3.8b2 and prior
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0348.html
Reference: CONECTIVA:CLA-2001:374
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000374
Reference: REDHAT:RHSA-2001:004
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-004.html
Reference: XF:icecast-format-string
Reference:
URL:http://xforce.iss.net/static/5978.php
Reference: BID:2264
Reference:
URL:http://www.securityfocus.com/bid/2264
Name: CVE-2001-0203
Description:
Watchguard Firebox II firewall allows users with
read-only access to gain read-write access, and
administrative privileges, by accessing a file that
contains hashed passphrases, and using the hashes during
authentication. Status: Entry
Reference: BUGTRAQ:20010120 Watchguard Firewall
Elevated Privilege Vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0342.html
Reference: BID:2284
Reference:
URL:http://www.securityfocus.com/bid/2284
Reference:
XF:watchguard-firebox-obtain-passphrase
Reference:
URL:http://xforce.iss.net/static/5979.php
Name: CVE-2001-0204
Description:
Watchguard Firebox II allows remote attackers to cause a
denial of service by establishing multiple connections
and sending malformed PPTP packets. Status: Entry
Reference: BUGTRAQ:20010214 def-2001-07:
Watchguard Firebox II PPTP DoS
Reference:
URL:http://www.securityfocus.com/archive/1/162965
Reference: BID:2369
Reference:
URL:http://www.securityfocus.com/bid/2369
Reference: XF:firebox-pptp-dos(6109)
Reference:
URL:http://xforce.iss.net/static/6109.php
Name: CVE-2001-0207
Description:
Buffer overflow in bing allows remote attackers to
execute arbitrary commands via a long hostname, which is
copied to a small buffer after a reverse DNS lookup
using the gethostbyaddr function. Status: Entry
Reference: BUGTRAQ:20010119 Buffer overflow in
bing
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0330.html
Reference: XF:linux-bing-bo
Reference:
URL:http://xforce.iss.net/static/6036.php
Reference: BID:2279
Reference:
URL:http://www.securityfocus.com/bid/2279
Name: CVE-2001-0215
Description:
ROADS search.pl program allows remote attackers to read
arbitrary files by specifying the file name in the form
parameter and terminating the filename with a null byte.
Status: Entry
Reference: BUGTRAQ:20010212 ROADS search system
"show files" Vulnerability with "null bite" bug
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0213.html
Reference:
CONFIRM:http://www.roads.lut.ac.uk/lists/open-roads/2001/02/0001.html
Reference: XF:roads-search-view-files(6097)
Reference:
URL:http://xforce.iss.net/static/6097.php
Reference: BID:2371
Reference:
URL:http://www.securityfocus.com/bid/2371
Name: CVE-2001-0218
Description:
Format string vulnerability in mars_nwe 0.99.pl19 allows
remote attackers to execute arbitrary commands.
Status: Entry
Reference: BUGTRAQ:20010126 format string
vulnerability in mars_nwe 0.99pl19
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0456.html
Reference: FREEBSD:FreeBSD-SA-01:20
Reference:
URL:http://archives.neohapsis.com/archives/freebsd/2001-02/0081.html
Reference: XF:mars-nwe-format-string(6019)
Reference:
URL:http://xforce.iss.net/static/6019.php
Name: CVE-2001-0219
Description:
Vulnerability in Support Tools Manager (xstm,cstm,stm)
in HP-UX 11.11 and earlier allows local users to cause a
denial of service. Status: Entry
Reference: HP:HPSBUX0101-137
Reference:
URL:http://archives.neohapsis.com/archives/hp/2001-q1/0016.html
Reference: XF:hp-stm-dos
Reference:
URL:http://xforce.iss.net/static/5957.php
Reference: BID:2239
Reference:
URL:http://www.securityfocus.com/bid/2239
Reference: OSVDB:6991
Reference: URL:http://www.osvdb.org/6991
Reference: OSVDB:7029
Reference: URL:http://www.osvdb.org/7029
Reference: OSVDB:7030
Reference: URL:http://www.osvdb.org/7030
Name: CVE-2001-0221
Description:
Buffer overflow in ja-xklock 2.7.1 and earlier allows
local users to gain root privileges. Status:
Entry
Reference: FREEBSD:FreeBSD-SA-01:19
Reference:
URL:http://archives.neohapsis.com/archives/freebsd/2001-02/0079.html
Reference: XF:ja-xklock-bo(6073)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6073
Name: CVE-2001-0222
Description:
webmin 0.84 and earlier allows local users to overwrite
and create arbitrary files via a symlink attack.
Status: Entry
Reference: MANDRAKE:MDKSA-2001-016
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-016.php3
Reference: CALDERA:CSSA-2001-004.0
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-004.0.txt
Reference: XF:linux-webmin-tmpfiles
Reference:
URL:http://xforce.iss.net/static/6011.php
Name: CVE-2001-0230
Description:
Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and
possibly other operating systems, allows local users to
gain privileges. Status: Entry
Reference: FREEBSD:FreeBSD-SA-01:22
Reference:
URL:http://archives.neohapsis.com/archives/freebsd/2001-02/0083.html
Reference: XF:dc20ctrl-port-bo(6077)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6077
Reference: OSVDB:6081
Reference: URL:http://www.osvdb.org/6081
Name: CVE-2001-0233
Description:
Buffer overflow in micq client 0.4.6 and earlier allows
remote attackers to cause a denial of service, and
possibly execute arbitrary commands, via a long
Description field. Status: Entry
Reference: BUGTRAQ:20010124 patch Re: [PkC]
Advisory #003: micq-0.4.6 remote buffer overflow
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0395.html
Reference: BUGTRAQ:20010118 [PkC] Advisory #003:
micq-0.4.6 remote buffer overflow
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0307.html
Reference: DEBIAN:DSA-012
Reference:
URL:http://www.debian.org/security/2001/dsa-012
Reference: FREEBSD:FreeBSD-SA-01:14
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:14.micq.asc
Reference: REDHAT:RHSA-2001:005
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-005.html
Reference: XF:micq-sprintf-remote-bo(5962)
Reference:
URL:http://xforce.iss.net/static/5962.php
Name: CVE-2001-0234
Description:
NewsDaemon before 0.21b allows remote attackers to
execute arbitrary SQL queries and gain privileges via a
malformed user_username parameter. Status: Entry
Reference: BUGTRAQ:20010126 NewsDaemon remote
administrator access
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0460.html
Reference:
CONFIRM:http://sourceforge.net/forum/forum.php?forum_id=60570
Reference: XF:newsdaemon-gain-admin-access
Reference:
URL:http://xforce.iss.net/static/6010.php
Name: CVE-2001-0235
Description:
Vulnerability in crontab allows local users to read
crontab files of other users by replacing the temporary
file that is being edited while crontab is running.
Status: Entry
Reference: DEBIAN:DSA-024
Reference:
URL:http://www.debian.org/security/2001/dsa-024
Reference: FREEBSD:FreeBSD-SA-01:09
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:09.crontab.v1.1.asc
Reference: BID:2332
Reference:
URL:http://www.securityfocus.com/bid/2332
Reference: XF:crontab-read-files(6225)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6225
Name: CVE-2001-0236
Description:
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper
daemon allows remote attackers to execute arbitrary
commands via a long "indication" event. Status:
Entry
Reference: BUGTRAQ:20010314 Solaris
/usr/lib/dmi/snmpXdmid vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98462536724454&w=2
Reference: CERT:CA-2001-05
Reference:
URL:http://www.cert.org/advisories/CA-2001-05.html
Reference: CIAC:L-065
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-065.shtml
Reference: SUN:00207
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/207
Reference: XF:solaris-snmpxdmid-bo(6245)
Reference:
URL:http://xforce.iss.net/static/6245.php
Reference: BID:2417
Reference:
URL:http://www.securityfocus.com/bid/2417
Name: CVE-2001-0237
Description:
Memory leak in Microsoft 2000 domain controller allows
remote attackers to cause a denial of service by
repeatedly connecting to the Kerberos service and then
disconnecting without sending any data. Status:
Entry
Reference: BUGTRAQ:20010509 def-2001-24: Windows
2000 Kerberos DoS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98942093221908&w=2
Reference: MS:MS01-024
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-024.asp
Reference: CIAC:L-079
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/l-079.shtml
Reference: XF:win2k-kerberos-dos(6506)
Reference:
URL:http://xforce.iss.net/static/6506.php
Reference: BID:2707
Reference:
URL:http://www.securityfocus.com/bid/2707
Name: CVE-2001-0238
Description:
Microsoft Data Access Component Internet Publishing
Provider 8.103.2519.0 and earlier allows remote
attackers to bypass Security Zone restrictions via
WebDAV requests. Status: Entry
Reference: MS:MS01-022
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-022.asp
Reference: CIAC:L-074
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-074.shtml
Reference: XF:ms-dacipp-webdav-access(6405)
Reference:
URL:http://xforce.iss.net/static/6405.php
Name: CVE-2001-0239
Description:
Microsoft Internet Security and Acceleration (ISA)
Server 2000 Web Proxy allows remote attackers to cause a
denial of service via a long web request with a specific
type. Status: Entry
Reference: BUGTRAQ:20010416 [SX-20010320-2] -
Microsoft ISA Server Denial of Service
Reference:
URL:http://www.securityfocus.com/archive/1/176912
Reference: BUGTRAQ:20010427 Microsoft ISA Server
Vulnerability
Reference:
URL:http://www.securityfocus.com/archive/1/179986
Reference: BUGTRAQ:20010417 [SX-20010320-2b] -
Followup re. Microsoft ISA Server Denial of Service
Reference:
URL:http://www.securityfocus.com/archive/1/177160
Reference: MS:MS01-021
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-021.asp
Reference: CIAC:L-073
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-073.shtml
Reference: BID:2600
Reference:
URL:http://www.securityfocus.com/bid/2600
Reference: XF:isa-web-proxy-dos(6383)
Reference:
URL:http://xforce.iss.net/static/6383.php
Name: CVE-2001-0240
Description:
Microsoft Word before Word 2002 allows attackers to
automatically execute macros without warning the user
via a Rich Text Format (RTF) document that links to a
template with the embedded macro. Status: Entry
Reference: MS:MS01-028
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-028.asp
Reference: XF:word-rtf-macro-execution(6571)
Reference:
URL:http://xforce.iss.net/static/6571.php
Reference: BID:2753
Reference:
URL:http://www.securityfocus.com/bid/2753
Name: CVE-2001-0241
Description:
Buffer overflow in Internet Printing ISAPI extension in
Windows 2000 allows remote attackers to gain root
privileges via a long print request that is passed to
the extension through IIS 5.0. Status: Entry
Reference: BUGTRAQ:20010501 Windows 2000 IIS 5.0
Remote buffer overflow vulnerability (Remote SYSTEM
Level Access)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98874912915948&w=2
Reference: MS:MS01-023
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-023.asp
Reference: CERT:CA-2001-10
Reference:
URL:http://www.cert.org/advisories/CA-2001-10.html
Reference: BID:2674
Reference:
URL:http://www.securityfocus.com/bid/2674
Reference: XF:iis-isapi-printer-bo(6485)
Reference:
URL:http://xforce.iss.net/static/6485.php
Reference: OSVDB:3323
Reference: URL:http://www.osvdb.org/3323
Reference: OVAL:oval:org.mitre.oval:def:1068
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1068
Name: CVE-2001-0243
Description:
Windows Media Player 7 and earlier stores Internet
shortcuts in a user's Temporary Files folder with a
fixed filename instead of in the Internet Explorer
cache, which causes the HTML in those shortcuts to run
in the Local Computer Zone instead of the Internet Zone,
which allows remote attackers to read certain files.
Status: Entry
Reference: MS:MS01-029
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-029.asp
Reference: XF:mediaplayer-html-shortcut(6584)
Reference:
URL:http://xforce.iss.net/static/6584.php
Reference: BID:2765
Reference:
URL:http://www.securityfocus.com/bid/2765
Name: CVE-2001-0244
Description:
Buffer overflow in Microsoft Index Server 2.0 allows
remote attackers to execute arbitrary commands via a
long search parameter. Status: Entry
Reference: MS:MS01-025
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-025.asp
Reference: BID:2709
Reference:
URL:http://www.securityfocus.com/bid/2709
Reference: XF:winnt-indexserver-search-bo(6517)
Reference:
URL:http://xforce.iss.net/static/6517.php
Name: CVE-2001-0245
Description:
Microsoft Index Server 2.0 in Windows NT 4.0, and
Indexing Service in Windows 2000, allows remote
attackers to read server-side include files via a
malformed search request, aka a new variant of the
"Malformed Hit-Highlighting" vulnerability. Status:
Entry
Reference: MS:MS01-025
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-025.asp
Reference: XF:win-indexserver-view-files(6518)
Reference:
URL:http://xforce.iss.net/static/6518.php
Name: CVE-2001-0252
Description:
iPlanet (formerly Netscape) Enterprise Server 4.1 allows
remote attackers to cause a denial of service via a long
HTTP GET request that contains many "/../" (dot dot)
sequences. Status: Entry
Reference: BUGTRAQ:20010122 def-2001-04: Netscape
Enterprise Server Dot-DoS
Reference:
URL:http://www.securityfocus.com/archive/1/157641
Reference: BUGTRAQ:20010124 iPlanet
FastTrack/Enterprise 4.1 DoS clarifications
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98035833331446&w=2
Reference: BID:2282
Reference:
URL:http://www.securityfocus.com/bid/2282
Reference: XF:netscape-enterprise-dot-dos
Reference:
URL:http://xforce.iss.net/static/5983.php
Name: CVE-2001-0259
Description:
ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can
allow local attackers to recover a SUN-DES-1 magic
phrase generated by another user, which the attacker can
use to decrypt that user's private key file. Status:
Entry
Reference: BUGTRAQ:20010116 Bug in SSH1
secure-RPC support can expose users' private keys
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0262.html
Reference:
CONFIRM:http://www.ssh.com/products/ssh/patches/secureRPCvulnerability.html
Reference: BID:2222
Reference:
URL:http://www.securityfocus.com/bid/2222
Reference: XF:ssh-rpc-private-key
Reference:
URL:http://xforce.iss.net/static/5963.php
Name: CVE-2001-0260
Description:
Buffer overflow in Lotus Domino Mail Server 5.0.5 and
earlier allows a remote attacker to crash the server or
execute arbitrary code via a long "RCPT TO" command.
Status: Entry
Reference: BUGTRAQ:20010123 [SAFER] Security
Bulletin 010123.EXP.1.10
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0360.html
Reference: XF:lotus-domino-smtp-bo
Reference:
URL:http://xforce.iss.net/static/5993.php
Reference: BID:2283
Reference:
URL:http://www.securityfocus.com/bid/2283
Reference: OSVDB:3321
Reference: URL:http://www.osvdb.org/3321
Name: CVE-2001-0265
Description:
ASCII Armor parser in Windows PGP 7.0.3 and earlier
allows attackers to create files in arbitrary locations
via a malformed ASCII armored file. Status: Entry
Reference: ATSTAKE:A040901-1
Reference:
URL:http://www.atstake.com/research/advisories/2001/a040901-1.txt
Reference: XF:pgp-armor-code-execution(6643)
Reference:
URL:http://xforce.iss.net/static/6643.php
Reference: BID:2556
Reference:
URL:http://www.securityfocus.com/bid/2556
Reference: OSVDB:1782
Reference: URL:http://www.osvdb.org/1782
Name: CVE-2001-0266
Description:
Vulnerability in Software Distributor SD-UX in HP-UX
11.0 and earlier allows local users to gain privileges.
Status: Entry
Reference: HP:HPSBUX0102-143
Reference:
URL:http://archives.neohapsis.com/archives/hp/2001-q1/0069.html
Reference: OSVDB:6033
Reference: URL:http://www.osvdb.org/6033
Name: CVE-2001-0267
Description:
NM debug in HP MPE/iX 6.5 and earlier does not properly
handle breakpoints, which allows local users to gain
privileges. Status: Entry
Reference: HP:HPSBMP0102-008
Reference:
URL:http://archives.neohapsis.com/archives/hp/2001-q1/0050.html
Reference: XF:hp-nmdebug-gain-privileges(6226)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6226
Reference: OSVDB:6032
Reference: URL:http://www.osvdb.org/6032
Name: CVE-2001-0268
Description:
The i386_set_ldt system call in NetBSD 1.5 and earlier,
and OpenBSD 2.8 and earlier, when the USER_LDT kernel
option is enabled, does not validate a call gate target,
which allows local users to gain root privileges by
creating a segment call gate in the Local Descriptor
Table (LDT) with a target that specifies an arbitrary
kernel address. Status: Entry
Reference: CALDERA:CSSA-2001-SCO.35
Reference:
URL:http://archives.neohapsis.com/archives/linux/caldera/2001-q4/0014.html
Reference: NETBSD:NetBSD-SA:2001-002
Reference:
URL:http://archives.neohapsis.com/archives/netbsd/2001-q1/0093.html
Reference: BUGTRAQ:20010219 Re: your mail
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0353.html
Reference: OPENBSD:20010302 The USER_LDT kernel
option allows an attacker to gain access to privileged
areas of kernel memory.
Reference:
URL:http://www.openbsd.org/errata.html#userldt
Reference: CERT-VN:VU#358960
Reference:
URL:http://www.kb.cert.org/vuls/id/358960
Reference: BID:2739
Reference:
URL:http://www.securityfocus.com/bid/2739
Reference: OSVDB:6141
Reference: URL:http://www.osvdb.org/6141
Reference: XF:user-ldt-validation(6222)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6222
Name: CVE-2001-0269
Description:
pam_ldap authentication module in Solaris 8 allows
remote attackers to bypass authentication via a NULL
password. Status: Entry
Reference: BUGTRAQ:20010217 Solaris 8
pam_ldap.so.1 module broken
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0344.html
Reference: SUNBUG:4384816
Reference:
XF:solaris-pamldap-bypass-authentication(6440)
Reference:
URL:http://xforce.iss.net/static/6440.php
Reference: OSVDB:6030
Reference: URL:http://www.osvdb.org/6030
Name: CVE-2001-0274
Description:
kicq IRC client 1.0.0, and possibly later versions,
allows remote attackers to execute arbitrary commands
via shell metacharacters in a URL. Status: Entry
Reference: BUGTRAQ:20010214 Security hole in kicq
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0276.html
Reference: BUGTRAQ:20010303 Re: Security hole in
kicq
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0536.html
Reference: XF:kicq-execute-commands(6112)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6112
Name: CVE-2001-0276
Description:
ext.dll in BadBlue 1.02.07 Personal Edition web server
allows remote attackers to determine the physical path
of the server by directly calling ext.dll without any
arguments, which produces an error message that contains
the path. Status: Entry
Reference: BUGTRAQ:20010217 BadBlue Web Server
Ext.dll Vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98263019502565&w=2
Reference:
CONFIRM:http://www.badblue.com/p010219.htm
Reference: BID:2390
Reference:
URL:http://www.securityfocus.com/bid/2390
Reference: XF:badblue-ext-reveal-path(6130)
Reference:
URL:http://xforce.iss.net/static/6130.php
Name: CVE-2001-0278
Description:
Vulnerability in linkeditor in HP MPE/iX 6.5 and earlier
allows local users to gain privileges. Status:
Entry
Reference: HP:HPSBMP0102-009
Reference:
URL:http://archives.neohapsis.com/archives/hp/2001-q1/0050.html
Reference: XF:hp-linkeditor-gain-privileges(6223)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6223
Name: CVE-2001-0279
Description:
Buffer overflow in sudo earlier than 1.6.3p6 allows
local users to gain root privileges. Status:
Entry
Reference: BUGTRAQ:20010222 Sudo version 1.6.3p6
now available (fwd)
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0414.html
Reference: MANDRAKE:MDKSA-2001:024
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-024.php3
Reference: DEBIAN:DSA-031
Reference:
URL:http://www.debian.org/security/2001/dsa-031
Reference: CONECTIVA:CLA-2001:381
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000381
Reference: REDHAT:RHSA-2001:018
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-018.html
Reference: REDHAT:RHSA-2001:019
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-019.html
Reference: BUGTRAQ:20010225 [slackware-security]
buffer overflow in sudo fixed
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0437.html
Reference: BUGTRAQ:20010226 Trustix Security
Advisory - sudo
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0427.html
Name: CVE-2001-0280
Description:
Buffer overflow in MERCUR SMTP server 3.30 allows remote
attackers to execute arbitrary commands via a long EXPN
command. Status: Entry
Reference: BUGTRAQ:20010223 Mercur Mailserver 3.3
buffer overflow with EXPN
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0413.html
Reference: XF:mercur-expn-bo(6149)
Reference:
URL:http://xforce.iss.net/static/6149.php
Reference: OSVDB:6027
Reference: URL:http://www.osvdb.org/6027
Name: CVE-2001-0284
Description:
Buffer overflow in IPSEC authentication mechanism for
OpenBSD 2.8 and earlier allows remote attackers to cause
a denial of service and possibly execute arbitrary
commands via a malformed Authentication header (AH) IPv4
option. Status: Entry
Reference: OPENBSD:20010302 Insufficient checks
in the IPSEC AH IPv4 option handling code can lead to a
buffer overrun in the kernel.
Reference:
URL:http://www.openbsd.org/errata.html#ipsec_ah
Reference: OSVDB:6026
Reference: URL:http://www.osvdb.org/6026
Name: CVE-2001-0287
Description:
VERITAS Cluster Server (VCS) 1.3.0 on Solaris allows
local users to cause a denial of service (system panic)
via the -L option to the lltstat command. Status:
Entry
Reference: BUGTRAQ:20010302 Option to VERITAS
Cluster Server (VCS) lltstat command will panic system.
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0528.html
Reference:
CONFIRM:http://seer.support.veritas.com/docs/234326.htm
Reference: OSVDB:6025
Reference: URL:http://www.osvdb.org/6025
Name: CVE-2001-0288
Description:
Cisco switches and routers running IOS 12.1 and earlier
produce predictable TCP Initial Sequence Numbers (ISNs),
which allows remote attackers to spoof or hijack TCP
connections. Status: Entry
Reference: CISCO:20010228 Cisco IOS Software TCP
Initial Sequence Number Randomization Improvements
Reference:
URL:http://www.cisco.com/warp/public/707/ios-tcp-isn-random-pub.shtml
Name: CVE-2001-0289
Description:
Joe text editor 2.8 searches the current working
directory (CWD) for the .joerc configuration file, which
could allow local users to gain privileges of other
users by placing a Trojan Horse .joerc file into a
directory, then waiting for users to execute joe from
that directory. Status: Entry
Reference: BUGTRAQ:20010228 Joe's Own Editor File
Handling Error
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0490.html
Reference: MANDRAKE:MDKSA-2001:026
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-026.php3
Reference: DEBIAN:DSA-041
Reference:
URL:http://www.debian.org/security/2001/dsa-041
Reference: REDHAT:RHSA-2001:024
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-024.html
Name: CVE-2001-0290
Description:
Vulnerability in Mailman 2.0.1 and earlier allows list
administrators to obtain user passwords. Status:
Entry
Reference: BUGTRAQ:20010306 [Mailman-Announce]
ANNOUNCE Mailman 2.0.2 (important privacy patch)
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0031.html
Name: CVE-2001-0295
Description:
Directory traversal vulnerability in War FTP 1.67.04
allows remote attackers to list directory contents and
possibly read files via a "dir *./../.." command.
Status: Entry
Reference: BUGTRAQ:20010306 Warftp 1.67b04
Directory Traversal
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98390925726814&w=2
Reference:
CONFIRM:http://support.jgaa.com/?cmd=ShowArticle&ID=31
Reference: BID:2444
Reference:
URL:http://www.securityfocus.com/bid/2444
Reference: OSVDB:874
Reference: URL:http://www.osvdb.org/874
Name: CVE-2001-0299
Description:
Buffer overflow in Voyager web administration server for
Nokia IP440 allows local users to cause a denial of
service, and possibly execute arbitrary commands, via a
long URL. Status: Entry
Reference: BUGTRAQ:20001127 Nokia firewalls
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97535202912588&w=2
Reference: BUGTRAQ:20001205 Nokia firewalls -
Response from Nokia
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97603879517777&w=2
Reference: XF:nokia-ip440-bo(5640)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/5640
Reference: BID:2054
Reference:
URL:http://www.securityfocus.com/bid/2054
Reference: OSVDB:6020
Reference: URL:http://www.osvdb.org/6020
Name: CVE-2001-0301
Description:
Buffer overflow in Analog before 4.16 allows remote
attackers to execute arbitrary commands by using the
ALIAS command to construct large strings. Status:
Entry
Reference: BUGTRAQ:20010213 Security advisory for
analog
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0264.html
Reference:
CONFIRM:http://www.analog.cx/security2.html
Reference: REDHAT:RHSA-2001:017
Reference:
URL:http://archives.neohapsis.com/archives/linux/redhat/2001-q1/0056.html
Reference: DEBIAN:DSA-033
Reference:
URL:http://www.debian.org/security/2001/dsa-033
Reference: BID:2377
Reference:
URL:http://www.securityfocus.com/bid/2377
Reference: XF:analog-alias-bo(6105)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6105
Reference: OSVDB:1762
Reference: URL:http://www.osvdb.org/1762
Name: CVE-2001-0309
Description:
inetd in Red Hat 6.2 does not properly close sockets for
internal services such as chargen, daytime, echo, etc.,
which allows remote attackers to cause a denial of
service via a series of connections to the internal
services. Status: Entry
Reference: REDHAT:RHSA-2001:006
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-006.html
Reference: XF:inetd-internal-socket-dos(6380)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6380
Name: CVE-2001-0310
Description:
sort in FreeBSD 4.1.1 and earlier, and possibly other
operating systems, uses predictable temporary file names
and does not properly handle when the temporary file
already exists, which causes sort to crash and possibly
impacts security-sensitive scripts. Status: Entry
Reference: FREEBSD:FreeBSD-SA-01:13
Reference:
URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:13.sort.asc
Reference: BID:3960
Reference:
URL:http://www.securityfocus.com/bid/3960
Reference: XF:sort-temp-file-abort
Reference:
URL:http://xforce.iss.net/static/6038.php
Name: CVE-2001-0311
Description:
Vulnerability in OmniBackII A.03.50 in HP 11.x and
earlier allows attackers to gain unauthorized access to
an OmniBack client. Status: Entry
Reference: HP:HPSBUX0102-142
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0102-142
Reference: HPBUG:PHSS_22914
Reference:
URL:http://archives.neohapsis.com/archives/hp/2001-q1/0022.html
Reference: HPBUG:PHSS_22915
Reference:
URL:http://archives.neohapsis.com/archives/hp/2001-q1/0023.html
Reference: XF:omniback-unauthorized-access(6434)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6434
Name: CVE-2001-0316
Description:
Linux kernel 2.4 and 2.2 allows local users to read
kernel memory and possibly gain privileges via a
negative argument to the sysctl call. Status:
Entry
Reference: REDHAT:RHSA-2001:013
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-013.html
Reference: CALDERA:CSSA-2001-009
Reference:
URL:http://www.caldera.com/support/security/advisories/CSSA-2001-009.0.txt
Reference: BUGTRAQ:20010213 Trustix Security
Advisory - proftpd, kernel
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html
Reference: BID:2364
Reference:
URL:http://www.securityfocus.com/bid/2364
Reference: OSVDB:6017
Reference: URL:http://www.osvdb.org/6017
Reference: XF:linux-sysctl-read-memory(6079)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6079
Name: CVE-2001-0317
Description:
Race condition in ptrace in Linux kernel 2.4 and 2.2
allows local users to gain privileges by using ptrace to
track and modify a running setuid process. Status:
Entry
Reference: BUGTRAQ:20010213 Trustix Security
Advisory - proftpd, kernel
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html
Reference: REDHAT:RHSA-2001:013
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-013.html
Reference: CALDERA:CSSA-2001-009
Reference:
URL:http://www.caldera.com/support/security/advisories/CSSA-2001-009.0.txt
Reference: XF:linux-ptrace-modify-process(6080)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6080
Name: CVE-2001-0318
Description:
Format string vulnerability in ProFTPD 1.2.0rc2 may
allow attackers to execute arbitrary commands by
shutting down the FTP server while using a malformed
working directory (cwd). Status: Entry
Reference: BUGTRAQ:20010110 proftpd 1.2.0rc2 --
example of bad coding
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916525715657&w=2
Reference: BUGTRAQ:20010206 Response to ProFTPD
issues
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0117.html
Reference: MANDRAKE:MDKSA-2001:021
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-021.php3
Reference: DEBIAN:DSA-029
Reference:
URL:http://www.debian.org/security/2001/dsa-029
Reference: CONECTIVA:CLA-2001:380
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000380
Reference: XF:proftpd-format-string(6433)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6433
Name: CVE-2001-0319
Description:
orderdspc.d2w macro in IBM Net.Commerce 3.x allows
remote attackers to execute arbitrary SQL queries by
inserting them into the order_rn option of the report
capability. Status: Entry
Reference: BUGTRAQ:20010205 IBM NetCommerce
Security
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0072.html
Reference:
CONFIRM:http://www-4.ibm.com/software/webservers/commerce/netcomletter.html
Reference: BID:2350
Reference:
URL:http://www.securityfocus.com/bid/2350
Reference:
XF:ibm-netcommerce-reveal-information(6067)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6067
Name: CVE-2001-0321
Description:
opendir.php script in PHP-Nuke allows remote attackers
to read arbitrary files by specifying the filename as an
argument to the requesturl parameter. Status:
Entry
Reference: BUGTRAQ:20010212 Fwd: Re: phpnuke,
security problem...
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0214.html
Reference: XF:phpnuke-opendir-read-files(6512)
Reference:
URL:http://xforce.iss.net/static/6512.php
Name: CVE-2001-0326
Description:
Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and
Oracle Application Server 9iAS Release 1.0.2.0.1 allows
remote attackers to read arbitrary files via the .jsp
and .sqljsp file extensions when the server is
configured to use the <<ALL FILES>> FilePermission.
Status: Entry
Reference: BUGTRAQ:20010212 Solution for
Potential Vunerability in Granting FilePermission to
Oracle Java Virtual Machine
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0255.html
Reference: XF:oracle-jvm-file-permissions(6438)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6438
Reference: OSVDB:5706
Reference: URL:http://www.osvdb.org/5706
Name: CVE-2001-0327
Description:
iPlanet Web Server Enterprise Edition 4.1 and earlier
allows remote attackers to retrieve sensitive data from
memory allocation pools, or cause a denial of service,
via a URL-encoded Host: header in the HTTP request,
which reveals memory in the Location: header that is
returned by the server. Status: Entry
Reference: ATSTAKE:A041601-1
Reference:
URL:http://www.atstake.com/research/advisories/2001/a041601-1.txt
Reference:
CONFIRM:http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html
Reference: CERT-VN:VU#276767
Reference:
URL:http://www.kb.cert.org/vuls/id/276767
Reference: OSVDB:5704
Reference: URL:http://www.osvdb.org/5704
Name: CVE-2001-0330
Description:
Bugzilla 2.10 allows remote attackers to access
sensitive information, including the database username
and password, via an HTTP request for the globals.pl
file, which is normally returned by the web server
without being executed. Status: Entry
Reference: ATSTAKE:A043001-1
Reference:
URL:http://www.atstake.com/research/advisories/2001/a043001-1.txt
Reference: BID:2671
Reference:
URL:http://www.securityfocus.com/bid/2671
Reference:
XF:bugzilla-gobalpl-gain-information(6489)
Reference:
URL:http://xforce.iss.net/static/6489.php
Name: CVE-2001-0331
Description:
Buffer overflow in Embedded Support Partner (ESP) daemon
(rpc.espd) in IRIX 6.5.8 and earlier allows remote
attackers to execute arbitrary commands. Status:
Entry
Reference: ISS:20010509 Remote Buffer Overflow
Vulnerability in IRIX Embedded Support Partner
Infrastructure
Reference:
URL:http://xforce.iss.net/alerts/advise76.php
Reference: SGI:20010501-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20010501-01-P
Reference: CERT-VN:VU#258632
Reference:
URL:http://www.kb.cert.org/vuls/id/258632
Reference: BID:2714
Reference:
URL:http://www.securityfocus.com/bid/2714
Reference: OSVDB:1822
Reference: URL:http://www.osvdb.org/1822
Reference: XF:irix-espd-bo(6502)
Reference:
URL:http://xforce.iss.net/static/6502.php
Name: CVE-2001-0333
Description:
Directory traversal vulnerability in IIS 5.0 and earlier
allows remote attackers to execute arbitrary commands by
encoding .. (dot dot) and "\" characters twice.
Status: Entry
Reference: BUGTRAQ:20010515 NSFOCUS SA2001-02 :
Microsoft IIS CGI Filename Decode Error Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98992056521300&w=2
Reference: MS:MS01-026
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-026.asp
Reference: CERT:CA-2001-12
Reference:
URL:http://www.cert.org/advisories/CA-2001-12.html
Reference: XF:iis-url-decoding(6534)
Reference:
URL:http://xforce.iss.net/static/6534.php
Reference: BID:2708
Reference:
URL:http://www.securityfocus.com/bid/2708
Reference: OVAL:oval:org.mitre.oval:def:1018
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1018
Reference: OVAL:oval:org.mitre.oval:def:1051
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1051
Reference: OVAL:oval:org.mitre.oval:def:37
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:37
Reference: OVAL:oval:org.mitre.oval:def:78
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:78
Name: CVE-2001-0334
Description:
FTP service in IIS 5.0 and earlier allows remote
attackers to cause a denial of service via a wildcard
sequence that generates a long string when it is
expanded. Status: Entry
Reference: MS:MS01-026
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-026.asp
Reference: XF:iis-ftp-wildcard-dos(6535)
Reference:
URL:http://xforce.iss.net/static/6535.php
Name: CVE-2001-0335
Description:
FTP service in IIS 5.0 and earlier allows remote
attackers to enumerate Guest accounts in trusted domains
by preceding the username with a special sequence of
characters. Status: Entry
Reference: MS:MS01-026
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-026.asp
Reference: XF:iis-ftp-domain-authentication(6545)
Reference:
URL:http://xforce.iss.net/static/6545.php
Reference: BID:2719
Reference:
URL:http://www.securityfocus.com/bid/2719
Name: CVE-2001-0336
Description:
The Microsoft MS00-060 patch for IIS 5.0 and earlier
introduces an error which allows attackers to cause a
denial of service via a malformed request. Status:
Entry
Reference: MS:MS01-026
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-026.asp
Reference:
XF:iis-crosssitescripting-patch-dos(6858)
Reference:
URL:http://xforce.iss.net/static/6858.php
Reference: OSVDB:5693
Reference: URL:http://www.osvdb.org/5693
Name: CVE-2001-0338
Description:
Internet Explorer 5.5 and earlier does not properly
validate digital certificates when Certificate
Revocation List (CRL) checking is enabled, which could
allow remote attackers to spoof trusted web sites, aka
the "Server certificate validation vulnerability."
Status: Entry
Reference: MS:MS01-027
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-027.asp
Reference: CIAC:L-087
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-087.shtml
Reference: XF:ie-crl-certificate-spoofing(6555)
Reference:
URL:http://xforce.iss.net/static/6555.php
Reference: BID:2735
Reference:
URL:http://www.securityfocus.com/bid/2735
Name: CVE-2001-0339
Description:
Internet Explorer 5.5 and earlier allows remote
attackers to display a URL in the address bar that is
different than the URL that is actually being displayed,
which could be used in web site spoofing attacks, aka
the "Web page spoofing vulnerability." Status:
Entry
Reference: MS:MS01-027
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-027.asp
Reference: CIAC:L-087
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-087.shtml
Reference: XF:ie-html-url-spoofing(6556)
Reference:
URL:http://xforce.iss.net/static/6556.php
Reference: BID:2737
Reference:
URL:http://www.securityfocus.com/bid/2737
Reference: OSVDB:5694
Reference: URL:http://www.osvdb.org/5694
Reference: OVAL:oval:org.mitre.oval:def:1096
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1096
Name: CVE-2001-0340
Description:
An interaction between the Outlook Web Access (OWA)
service in Microsoft Exchange 2000 Server and Internet
Explorer allows attackers to execute malicious script
code against a user's mailbox via a message attachment
that contains HTML code, which is executed
automatically. Status: Entry
Reference: MS:MS01-030
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-030.asp
Reference: CIAC:L-091
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-091.shtml
Reference: XF:exchange-owa-script-execution(6652)
Reference:
URL:http://xforce.iss.net/static/6652.php
Name: CVE-2001-0341
Description:
Buffer overflow in Microsoft Visual Studio RAD Support
sub-component of FrontPage Server Extensions allows
remote attackers to execute arbitrary commands via a
long registration request (URL) to fp30reg.dll.
Status: Entry
Reference: BUGTRAQ:20010625 NSFOCUS SA2001-03 :
Microsoft FrontPage 2000 Server Extensions Buffer
Overflow Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99348216322147&w=2
Reference: MS:MS01-035
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-035.asp
Reference: BID:2906
Reference:
URL:http://www.securityfocus.com/bid/2906
Reference: XF:frontpage-ext-rad-bo(6730)
Reference:
URL:http://xforce.iss.net/static/6730.php
Reference: OSVDB:577
Reference: URL:http://www.osvdb.org/577
Name: CVE-2001-0344
Description:
An SQL query method in Microsoft SQL Server 2000 Gold
and 7.0 using Mixed Mode allows local database users to
gain privileges by reusing a cached connection of the sa
administrator account. Status: Entry
Reference: MS:MS01-032
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-032.asp
Reference: CIAC:L-095
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-095.shtml
Reference:
XF:mssql-cached-connection-access(6684)
Reference:
URL:http://xforce.iss.net/static/6684.php
Reference: OVAL:oval:org.mitre.oval:def:71
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:71
Name: CVE-2001-0345
Description:
Microsoft Windows 2000 telnet service allows attackers
to prevent idle Telnet sessions from timing out, causing
a denial of service by creating a large number of idle
sessions. Status: Entry
Reference: MS:MS01-031
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-031.asp
Reference: BID:2843
Reference:
URL:http://www.securityfocus.com/bid/2843
Reference:
XF:win2k-telnet-idle-sessions-dos(6667)
Reference:
URL:http://xforce.iss.net/static/6667.php
Name: CVE-2001-0346
Description:
Handle leak in Microsoft Windows 2000 telnet service
allows attackers to cause a denial of service by
starting a large number of sessions and terminating
them. Status: Entry
Reference: MS:MS01-031
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-031.asp
Reference: XF:win2k-telnet-handle-leak-dos(6668)
Reference:
URL:http://xforce.iss.net/static/6668.php
Name: CVE-2001-0347
Description:
Information disclosure vulnerability in Microsoft
Windows 2000 telnet service allows remote attackers to
determine the existence of user accounts such as Guest,
or log in to the server without specifying the domain
name, via a malformed userid. Status: Entry
Reference: MS:MS01-031
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-031.asp
Reference: CIAC:L-092
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-092.shtml
Reference: BID:2847
Reference:
URL:http://www.securityfocus.com/bid/2847
Reference:
XF:win2k-telnet-domain-authentication(6665)
Reference:
URL:http://xforce.iss.net/static/6665.php
Reference: OSVDB:5686
Reference: URL:http://www.osvdb.org/5686
Name: CVE-2001-0348
Description:
Microsoft Windows 2000 telnet service allows attackers
to cause a denial of service (crash) via a long logon
command that contains a backspace. Status: Entry
Reference: BUGTRAQ:20050511 Microsoft Windows
2000 Telnet server vulnerability
Reference: BINDVIEW:20010608 Range checking fault
condition in Microsoft Windows 2000 Telnet server
Reference:
URL:http://razor.bindview.com/publish/advisories/adv_mstelnet.html
Reference: MS:MS01-031
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-031.asp
Reference: CIAC:L-092
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-092.shtml
Reference: BID:2838
Reference: XF:win2k-telnet-username-dos(6666)
Reference:
URL:http://xforce.iss.net/static/6666.php
Name: CVE-2001-0351
Description:
Microsoft Windows 2000 telnet service allows a local
user to make a certain system call that allows the user
to terminate a Telnet session and cause a denial of
service. Status: Entry
Reference: MS:MS01-031
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-031.asp
Reference: CIAC:L-092
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-092.shtml
Reference: XF:win2k-telnet-system-call-dos(6669)
Reference:
URL:http://xforce.iss.net/static/6669.php
Reference: BID:2846
Reference:
URL:http://www.securityfocus.com/bid/2846
Name: CVE-2001-0353
Description:
Buffer overflow in the line printer daemon (in.lpd) for
Solaris 8 and earlier allows local and remote attackers
to gain root privileges via a "transfer job" routine.
Status: Entry
Reference: ISS:20010619 Remote Buffer Overflow
Vulnerability in Solaris Print Protocol Daemon
Reference:
URL:http://xforce.iss.net/alerts/advise80.php
Reference: SUN:00206
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/206
Reference: CERT:CA-2001-15
Reference:
URL:http://www.cert.org/advisories/CA-2001-15.html
Reference: XF:solaris-lpd-bo(6718)
Reference:
URL:http://xforce.iss.net/static/6718.php
Reference: BID:2894
Reference:
URL:http://www.securityfocus.com/bid/2894
Name: CVE-2001-0361
Description:
Implementations of SSH version 1.5, including (1)
OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1
up to version 1.2.31, in certain configurations, allow a
remote attacker to decrypt and/or alter traffic via a
"Bleichenbacher attack" on PKCS#1 version 1.5.
Status: Entry
Reference: BUGTRAQ:20010207 [CORE SDI ADVISORY]
SSH1 session key recovery vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98158450021686&w=2
Reference: CIAC:L-047
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-047.shtml
Reference: FREEBSD:FreeBSD-SA-01:24
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:24.ssh.asc
Reference: DEBIAN:DSA-023
Reference:
URL:http://www.debian.org/security/2001/dsa-023
Reference: DEBIAN:DSA-027
Reference:
URL:http://www.debian.org/security/2001/dsa-027
Reference: DEBIAN:DSA-086
Reference:
URL:http://www.debian.org/security/2001/dsa-086
Reference: CISCO:20010627 Multiple SSH
Vulnerabilities
Reference: SUSE:SuSE-SA:2001:04
Reference:
URL:http://www.novell.com/linux/security/advisories/adv004_ssh.html
Reference: XF:ssh-session-key-recovery(6082)
Reference:
URL:http://xforce.iss.net/static/6082.php
Reference: BID:2344
Reference:
URL:http://www.securityfocus.com/bid/2344
Reference: OSVDB:2116
Reference: URL:http://www.osvdb.org/2116
Name: CVE-2001-0364
Description:
SSH Communications Security sshd 2.4 for Windows allows
remote attackers to create a denial of service via a
large number of simultaneous connections. Status:
Entry
Reference: BUGTRAQ:20010315 Remote DoS attack
against SSH Secure Shell for Windows Servers
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98467799732241&w=2
Reference: BID:2477
Reference:
URL:http://www.securityfocus.com/bid/2477
Reference: XF:ssh-ssheloop-dos(6241)
Reference:
URL:http://xforce.iss.net/static/6241.php
Name: CVE-2001-0365
Description:
Eudora before 5.1 allows a remote attacker to execute
arbitrary code, when the 'Use Microsoft Viewer' and
'allow executables in HTML content' options are enabled,
via an HTML email message containing Javascript, with
ActiveX controls and malicious code within IMG tags.
Status: Entry
Reference: BUGTRAQ:20010318
feeble.you!dora.exploit
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98503741910995&w=2
Reference: XF:eudora-html-execute-code(6262)
Reference:
URL:http://xforce.iss.net/static/6262.php
Reference: BID:2490
Reference:
URL:http://www.securityfocus.com/bid/2490
Name: CVE-2001-0366
Description:
saposcol in SAP R/3 Web Application Server Demo before
1.5 trusts the PATH environmental variable to find and
execute the expand program, which allows local users to
obtain root access by modifying the PATH to point to a
Trojan horse expand program. Status: Entry
Reference: BUGTRAQ:20010429 SAP R/3 Web
Application Server Demo for Linux: root exploit
Reference:
URL:http://www.securityfocus.com/archive/1/180498
Reference:
CONFIRM:ftp://ftp.sap.com/pub/linuxlab/saptools/README.saposcol
Reference: BID:2662
Reference:
URL:http://www.securityfocus.com/bid/2662
Reference: XF:linux-sap-execute-code(6487)
Reference:
URL:http://xforce.iss.net/static/6487.php
Name: CVE-2001-0368
Description:
Directory traversal vulnerability in BearShare 2.2.2 and
earlier allows a remote attacker to read certain files
via a URL containing a series of . characters, a
variation of the .. (dot dot) attack. Status:
Entry
Reference: BUGTRAQ:20010430 A Serious Security
Vulnerability Found in BearShare (Directory Traversal)
Reference:
URL:http://www.securityfocus.com/archive/1/180644
Reference: BID:2672
Reference:
URL:http://www.securityfocus.com/bid/2672
Reference: XF:bearshare-dot-download-files(6481)
Reference:
URL:http://xforce.iss.net/static/6481.php
Reference: OSVDB:1810
Reference: URL:http://www.osvdb.org/1810
Name: CVE-2001-0371
Description:
Race condition in the UFS and EXT2FS file systems in
FreeBSD 4.2 and earlier, and possibly other operating
systems, makes deleted data available to user processes
before it is zeroed out, which allows a local user to
access otherwise restricted information. Status:
Entry
Reference: FREEBSD:FreeBSD-SA-01:30
Reference:
URL:http://archives.neohapsis.com/archives/freebsd/2001-03/0403.html
Reference: XF:ufs-ext2fs-data-disclosure(6268)
Reference:
URL:http://xforce.iss.net/static/6268.php
Reference: OSVDB:5682
Reference: URL:http://www.osvdb.org/5682
Name: CVE-2001-0373
Description:
The default configuration of the Dr. Watson program in
Windows NT and Windows 2000 generates user.dmp crash
dump files with world-readable permissions, which could
allow a local user to gain access to sensitive
information. Status: Entry
Reference: BUGTRAQ:20010323 NT crash dump files
insecure by default
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0336.html
Reference: BID:2501
Reference:
URL:http://www.securityfocus.com/bid/2501
Reference:
XF:win-userdmp-insecure-permission(6275)
Reference:
URL:http://xforce.iss.net/static/6275.php
Reference: OSVDB:5683
Reference: URL:http://www.osvdb.org/5683
Name: CVE-2001-0375
Description:
Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa
authentication to a TACACS+ server allows remote
attackers to cause a denial of service via a large
number of authentication requests. Status: Entry
Reference: BUGTRAQ:20010406 PIX Firewall 5.1 DoS
Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98658271707833&w=2
Reference: CISCO:20011003 Cisco PIX Firewall
Authentication Denial of Service Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/pixfirewall-authen-flood-pub.shtml
Reference: XF:cisco-pix-tacacs-dos(6353)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6353
Reference: BID:2551
Reference:
URL:http://www.securityfocus.com/bid/2551
Name: CVE-2001-0377
Description:
Infradig Inframail prior to 3.98a allows a remote
attacker to create a denial of service via a malformed
POST request which includes a space followed by a large
string. Status: Entry
Reference: BUGTRAQ:20010328 Inframail Denial of
Service Vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0428.html
Reference: XF:inframail-post-dos(6297)
Reference:
URL:http://xforce.iss.net/static/6297.php
Reference: OSVDB:5685
Reference: URL:http://www.osvdb.org/5685
Name: CVE-2001-0378
Description:
readline prior to 4.1, in OpenBSD 2.8 and earlier,
creates history files with insecure permissions, which
allows a local attacker to recover potentially sensitive
information via readline history files. Status:
Entry
Reference:
CONFIRM:ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/024_readline.patch
Reference: XF:bsd-readline-permissions(6586)
Reference:
URL:http://xforce.iss.net/static/6586.php
Reference: OSVDB:5680
Reference: URL:http://www.osvdb.org/5680
Name: CVE-2001-0379
Description:
Vulnerability in the newgrp program included with HP9000
servers running HP-UX 11.11 allows a local attacker to
obtain higher access rights. Status: Entry
Reference: HP:HPSBUX0103-147
Reference:
URL:http://archives.neohapsis.com/archives/hp/2001-q1/0101.html
Reference: CERT-VN:VU#249224
Reference:
URL:http://www.kb.cert.org/vuls/id/249224
Reference:
XF:hp-newgrp-additional-privileges(6282)
Reference:
URL:http://xforce.iss.net/static/6282.php
Reference: OSVDB:5681
Reference: URL:http://www.osvdb.org/5681
Name: CVE-2001-0383
Description:
banners.php in PHP-Nuke 4.4 and earlier allows remote
attackers to modify banner ad URLs by directly calling
the Change operation, which does not require
authentication. Status: Entry
Reference: BUGTRAQ:20010401 Php-nuke exploit...
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0017.html
Reference:
CONFIRM:http://phpnuke.org/download.php?dcategory=Fixes
Reference: XF:php-nuke-url-redirect(6342)
Reference:
URL:http://xforce.iss.net/static/6342.php
Reference: BID:2544
Reference:
URL:http://www.securityfocus.com/bid/2544
Name: CVE-2001-0386
Description:
AnalogX SimpleServer:WWW 1.08 allows remote attackers to
cause a denial of service via an HTTP request to the
/aux directory. Status: Entry
Reference: BUGTRAQ:20010417 Advisory for
SimpleServer:WWW (analogX)
Reference:
URL:http://www.securityfocus.com/archive/1/177156
Reference: BID:2608
Reference:
URL:http://www.securityfocus.com/bid/2608
Reference: XF:analogx-simpleserver-aux-dos(6395)
Reference:
URL:http://xforce.iss.net/static/6395.php
Reference: OSVDB:3781
Reference: URL:http://www.osvdb.org/3781
Name: CVE-2001-0387
Description:
Format string vulnerability in hfaxd in HylaFAX before
4.1.b2_2 allows local users to gain privileges via the
-q command line argument. Status: Entry
Reference: BUGTRAQ:20010412 HylaFAX vulnerability
Reference:
URL:http://www.securityfocus.com/archive/1/175963
Reference: BUGTRAQ:20010415 **SECURITY ADVISORY**
- HylaFAX format string vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0236.html
Reference: FREEBSD:FreeBSD-SA-01:34
Reference:
URL:http://archives.neohapsis.com/archives/freebsd/2001-04/0606.html
Reference: SUSE:SuSE-SA:2001:15
Reference:
URL:http://lists.suse.com/archives/suse-security-announce/2001-Apr/0005.html
Reference: MANDRAKE:MDKSA-2001:041
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-041.php3
Reference: BID:2574
Reference:
URL:http://www.securityfocus.com/bid/2574
Reference: XF:hylafax-hfaxd-format-string(6377)
Reference:
URL:http://xforce.iss.net/static/6377.php
Reference: OSVDB:5679
Reference: URL:http://www.osvdb.org/5679
Name: CVE-2001-0388
Description:
time server daemon timed allows remote attackers to
cause a denial of service via malformed packets.
Status: Entry
Reference: FREEBSD:FreeBSD-SA-01:28
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:28.timed.asc
Reference: MANDRAKE:MDKSA-2001:034
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-034.php3
Reference: SUSE:SuSE-SA:2001:07
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_007_nkitserv.html
Reference: XF:timed-remote-dos(6228)
Reference:
URL:http://xforce.iss.net/static/6228.php
Name: CVE-2001-0394
Description:
Remote manager service in Website Pro 3.0.37 allows
remote attackers to cause a denial of service via a
series of malformed HTTP requests to the /dyn directory.
Status: Entry
Reference: BUGTRAQ:20010328 def-2001-15: Website
Pro Remote Manager DoS
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0425.html
Reference: XF:website-pro-remote-dos(6295)
Reference:
URL:http://xforce.iss.net/static/6295.php
Reference: OSVDB:5669
Reference: URL:http://www.osvdb.org/5669
Name: CVE-2001-0402
Description:
IPFilter 3.4.16 and earlier does not include sufficient
session information in its cache, which allows remote
attackers to bypass access restrictions by sending
fragmented packets to a restricted port after sending
unfragmented packets to an unrestricted port. Status:
Entry
Reference: BUGTRAQ:20010408 A fragmentation
attack against IP Filter
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98679734015538&w=2
Reference: FREEBSD:FreeBSD-SA-01:32
Reference:
URL:http://archives.neohapsis.com/archives/freebsd/2001-04/0338.html
Reference: XF:ipfilter-access-ports(6331)
Reference:
URL:http://xforce.iss.net/static/6331.php
Name: CVE-2001-0405
Description:
ip_conntrack_ftp in the IPTables firewall for Linux 2.4
allows remote attackers to bypass access restrictions
for an FTP server via a PORT command that lists an
arbitrary IP address and port number, which is added to
the RELATED table and allowed by the firewall.
Status: Entry
Reference: BUGTRAQ:20010416 Tempest Security
Techonologies -- Adivsory #01/2001 -- Linux IPTables
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0271.html
Reference: REDHAT:RHSA-2001:052
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-052.html
Reference: REDHAT:RHSA-2001:084
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-084.html
Reference: MANDRAKE:MDKSA-2001:071
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-071.php3
Reference: BID:2602
Reference:
URL:http://www.securityfocus.com/bid/2602
Reference: XF:linux-netfilter-iptables(6390)
Reference:
URL:http://xforce.iss.net/static/6390.php
Name: CVE-2001-0407
Description:
Directory traversal vulnerability in MySQL before
3.23.36 allows local users to modify arbitrary files and
gain privileges by creating a database whose name starts
with .. (dot dot). Status: Entry
Reference: BUGTRAQ:20010318 potential
vulnerability of mysqld running with root privileges
(can be used as good DoS or r00t expoloit)
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0237.html
Reference: BUGTRAQ:20010327 MySQL 3.23.36 is
relased (fwd)
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0396.html
Reference: XF:mysql-dot-directory-traversal(6617)
Reference:
URL:http://xforce.iss.net/static/6617.php
Reference: BID:2522
Reference:
URL:http://www.securityfocus.com/bid/2522
Name: CVE-2001-0408
Description:
vim (aka gvim) processes VIM control codes that are
embedded in a file, which could allow attackers to
execute arbitrary commands when another user opens a
file containing malicious VIM control codes. Status:
Entry
Reference: MANDRAKE:MDKSA-2001:035
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-035.php3
Reference: REDHAT:RHSA-2001:008
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-008.html
Reference: SUSE:SuSE-SA:2001:12
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_012_vim.html
Reference: CALDERA:CSSA-2001-014.0
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-014.0.txt
Reference: BUGTRAQ:20010329 Immunix OS Security
update for vim
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98593106111968&w=2
Reference: BID:2510
Reference:
URL:http://www.securityfocus.com/bid/2510
Reference: XF:vim-elevate-privileges(6259)
Reference:
URL:http://xforce.iss.net/static/6259.php
Name: CVE-2001-0409
Description:
vim (aka gvim) allows local users to modify files being
edited by other users via a symlink attack on the backup
and swap files, when the victim is editing the file in a
world writable directory. Status: Entry
Reference: SUSE:SuSE-SA:2001:12
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_012_vim.html
Reference: CALDERA:CSSA-2001-014.0
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-014.0.txt
Reference: XF:vim-tmp-symlink(6628)
Reference:
URL:http://xforce.iss.net/static/6628.php
Name: CVE-2001-0412
Description:
Cisco Content Services (CSS) switch products 11800 and
earlier, aka Arrowpoint, allows local users to gain
privileges by entering debug mode. Status: Entry
Reference: CISCO:20010404 Cisco Content Services
Switch User Account Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/arrowpoint-useraccnt-debug-pub.shtml
Reference: BID:2559
Reference:
URL:http://www.securityfocus.com/bid/2559
Reference: XF:cisco-css-elevate-privileges(6322)
Reference:
URL:http://xforce.iss.net/static/6322.php
Reference: OSVDB:1784
Reference: URL:http://www.osvdb.org/1784
Name: CVE-2001-0413
Description:
BinTec X4000 Access router, and possibly other versions,
allows remote attackers to cause a denial of service via
a SYN port scan, which causes the router to hang.
Status: Entry
Reference: BUGTRAQ:20010404 BinTec X4000 Access
Router DoS Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98644414226344&w=2
Reference: BUGTRAQ:20010406 X4000 DoS: Details
and workaround
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98659862317070&w=2
Reference: BUGTRAQ:20010410 BinTec Router DoS:
Workaround and Details
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0145.html
Reference: BUGTRAQ:20010409 BINTEC X1200
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98697054804197&w=2
Reference: XF:bintec-x4000-nmap-dos(6323)
Reference:
URL:http://xforce.iss.net/static/6323.php
Name: CVE-2001-0414
Description:
Buffer overflow in ntpd ntp daemon 4.0.99k and earlier
(aka xntpd and xntp3) allows remote attackers to cause a
denial of service and possibly execute arbitrary
commands via a long readvar argument. Status:
Entry
Reference: BUGTRAQ:20010404 ntpd =< 4.0.99k
remote buffer overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98642418618512&w=2
Reference: BUGTRAQ:20010405 Re: ntpd =< 4.0.99k
remote buffer overflow]
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98654963328381&w=2
Reference: REDHAT:RHSA-2001:045
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-045.html
Reference: CALDERA:CSSA-2001-013
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-013.0.txt
Reference: MANDRAKE:MDKSA-2001:036
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-036.php3
Reference: DEBIAN:DSA-045
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98651866104663&w=2
Reference: NETBSD:NetBSD-SA2001-004
Reference:
URL:ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2001-004.txt.asc
Reference: SUSE:SuSE-SA:2001:10
Reference:
URL:http://lists.suse.com/archives/suse-security-announce/2001-Apr/0000.html
Reference: CONECTIVA:CLA-2001:392
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000392
Reference: FREEBSD:FreeBSD-SA-01:31
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:31.ntpd.asc
Reference: SCO:SSE073
Reference: URL:ftp://ftp.sco.com/SSE/sse073.ltr
Reference: SCO:SSE074
Reference: URL:ftp://ftp.sco.com/SSE/sse074.ltr
Reference: BUGTRAQ:20010408 [slackware-security]
buffer overflow fix for NTP
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98679815917014&w=2
Reference: BUGTRAQ:20010409 PROGENY-SA-2001-02:
ntpd remote buffer overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98684202610470&w=2
Reference: BUGTRAQ:20010409 ntpd - new Debian 2.2
(potato) version is also vulnerable
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98684532921941&w=2
Reference: BUGTRAQ:20010406 Immunix OS Security
update for ntp and xntp3
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98659782815613&w=2
Reference: BUGTRAQ:20010409 ntp-4.99k23.tar.gz is
available
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98683952401753&w=2
Reference: BUGTRAQ:20010418 IBM MSS Outside
Advisory Redistribution: IBM AIX: Buffer Overflow
Vulnerability in (x)ntp
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0314.html
Reference: BUGTRAQ:20010409 [ESA-20010409-01]
xntp buffer overflow
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0127.html
Reference: BUGTRAQ:20010413 PROGENY-SA-2001-02A:
[UPDATE] ntpd remote buffer overflow
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0225.html
Reference: BID:2540
Reference:
URL:http://www.securityfocus.com/bid/2540
Reference: OSVDB:805
Reference: URL:http://www.osvdb.org/805
Reference: OVAL:oval:org.mitre.oval:def:3831
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3831
Reference: XF:ntpd-remote-bo(6321)
Reference:
URL:http://xforce.iss.net/static/6321.php
Name: CVE-2001-0416
Description:
sgml-tools (aka sgmltools) before 1.0.9-15 creates
temporary files with insecure permissions, which allows
other users to read files that are being processed by
sgml-tools. Status: Entry
Reference: DEBIAN:DSA-038
Reference:
URL:http://www.debian.org/security/2001/dsa-038
Reference: REDHAT:RHSA-2001:027
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-027.html
Reference: BUGTRAQ:20010316 Immunix OS Security
update for sgml-tools
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98477491130367&w=2
Reference: MANDRAKE:MDKSA-2001:030
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-030.php3
Reference: CONECTIVA:CLA-2001:390
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000390
Reference: XF:sgmltools-symlink
Reference:
URL:http://xforce.iss.net/static/6201.php
Reference: SUSE:SuSE-SA:2001:16
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_016_sgmltool_txt.html
Reference: BID:2683
Reference:
URL:http://www.securityfocus.com/bid/2683
Reference: BID:2506
Reference:
URL:http://www.securityfocus.com/bid/2506
Name: CVE-2001-0422
Description:
Buffer overflow in Xsun in Solaris 8 and earlier allows
local users to execute arbitrary commands via a long
HOME environmental variable. Status: Entry
Reference: BUGTRAQ:20010410 Solaris Xsun buffer
overflow vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0158.html
Reference: SUNBUG:4356377
Reference: SUNBUG:4425845
Reference: SUNBUG:4440161
Reference: BID:2561
Reference:
URL:http://www.securityfocus.com/bid/2561
Reference: OVAL:oval:org.mitre.oval:def:555
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:555
Reference: XF:solaris-xsun-home-bo(6343)
Reference:
URL:http://xforce.iss.net/static/6343.php
Name: CVE-2001-0423
Description:
Buffer overflow in ipcs in Solaris 7 x86 allows local
users to execute arbitrary code via a long TZ (timezone)
environmental variable, a different vulnerability than
CAN-2002-0093. Status: Entry
Reference: BUGTRAQ:20010412 Solaris ipcs
vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0217.html
Reference: BID:2581
Reference:
URL:http://www.securityfocus.com/bid/2581
Reference: XF:solaris-ipcs-bo(6369)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6369
Name: CVE-2001-0427
Description:
Cisco VPN 3000 series concentrators before 2.5.2(F)
allow remote attackers to cause a denial of service via
a flood of invalid login requests to (1) the SSL
service, or (2) the telnet service, which do not
properly disconnect the user after several failed login
attempts. Status: Entry
Reference: CISCO:20010328 VPN3000 Concentrator
TELNET Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/vpn3k-telnet-vuln-pub.shtml
Reference: XF:cisco-vpn-telnet-dos(6298)
Reference:
URL:http://xforce.iss.net/static/6298.php
Reference: OSVDB:5643
Reference: URL:http://www.osvdb.org/5643
Name: CVE-2001-0428
Description:
Cisco VPN 3000 series concentrators before 2.5.2(F)
allow remote attackers to cause a denial of service via
an IP packet with an invalid IP option. Status:
Entry
Reference: CISCO:20010412 VPN 3000 Concentrator
IP Options Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/vpn3k-ipoptions-vuln-pub.shtml
Reference: BID:2573
Reference:
URL:http://www.securityfocus.com/bid/2573
Reference: XF:cisco-vpn-ip-dos(6360)
Reference:
URL:http://xforce.iss.net/static/6360.php
Reference: OSVDB:1786
Reference: URL:http://www.osvdb.org/1786
Name: CVE-2001-0429
Description:
Cisco Catalyst 5000 series switches 6.1(2) and earlier
will forward an 802.1x frame on a Spanning Tree Protocol
(STP) blocked port, which causes a network storm and a
denial of service. Status: Entry
Reference: CISCO:20010416 Catalyst 5000 Series
802.1x Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/cat5k-8021x-vuln-pub.shtml
Reference: CIAC:L-072
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-072.shtml
Reference: BID:2604
Reference:
URL:http://www.securityfocus.com/bid/2604
Reference: XF:cisco-catalyst-8021x-dos(6379)
Reference:
URL:http://xforce.iss.net/static/6379.php
Name: CVE-2001-0430
Description:
Vulnerability in exuberant-ctags before 3.2.4-0.1
insecurely creates temporary files. Status: Entry
Reference: DEBIAN:DSA-046
Reference:
URL:http://archives.neohapsis.com/archives/vendor/2001-q2/0005.html
Reference: XF:exuberant-ctags-symlink(6388)
Reference:
URL:http://xforce.iss.net/static/6388.php
Reference: OSVDB:5642
Reference: URL:http://www.osvdb.org/5642
Name: CVE-2001-0434
Description:
The LogDataListToFile ActiveX function used in (1)
Knowledge Center and (2) Back web components of Compaq
Presario computers allows remote attackers to modify
arbitrary files and cause a denial of service.
Status: Entry
Reference: COMPAQ:SSRT0716
Reference:
URL:http://ftp.support.compaq.com/patches/.new/html/SSRT0716-01.shtml
Reference: XF:compaq-activex-dos(6355)
Reference:
URL:http://xforce.iss.net/static/6355.php
Name: CVE-2001-0439
Description:
licq before 1.0.3 allows remote attackers to execute
arbitrary commands via shell metacharacters in a URL.
Status: Entry
Reference: CONECTIVA:CLA-2001:389
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000389
Reference: MANDRAKE:MDKSA-2001:032
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-032.php3
Reference: FREEBSD:FreeBSD-SA-01:35
Reference:
URL:http://archives.neohapsis.com/archives/freebsd/2001-04/0607.html
Reference: REDHAT:RHSA-2001:022
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-022.html
Reference: REDHAT:RHSA-2001:023
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-023.html
Reference: XF:licq-url-execute-commands(6261)
Reference:
URL:http://xforce.iss.net/static/6261.php
Reference: OSVDB:5641
Reference: URL:http://www.osvdb.org/5641
Name: CVE-2001-0440
Description:
Buffer overflow in logging functions of licq before
1.0.3 allows remote attackers to cause a denial of
service, and possibly execute arbitrary commands.
Status: Entry
Reference: CONECTIVA:CLA-2001:389
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000389
Reference: MANDRAKE:MDKSA-2001:032
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-032.php3
Reference: FREEBSD:FreeBSD-SA-01:35
Reference:
URL:http://archives.neohapsis.com/archives/freebsd/2001-04/0607.html
Reference: REDHAT:RHSA-2001:022
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-022.html
Reference: REDHAT:RHSA-2001:023
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-023.html
Reference: XF:licq-logging-bo(6645)
Reference:
URL:http://xforce.iss.net/static/6645.php
Reference: OSVDB:5601
Reference: URL:http://www.osvdb.org/5601
Name: CVE-2001-0442
Description:
Buffer overflow in Mercury MTA POP3 server for NetWare
1.48 and earlier allows remote attackers to cause a
denial of service and possibly execute arbitrary code
via a long APOP command. Status: Entry
Reference: BUGTRAQ:20010421 Mercury for NetWare
POP3 server vulnerable to remote buffer overflow
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0378.html
Reference: BUGTRAQ:20010424 Re: Mercury for
NetWare POP3 server vulnerable to remote buffer overflow
Reference:
URL:http://online.securityfocus.com/archive/1/179217
Reference: BID:2641
Reference:
URL:http://www.securityfocus.com/bid/2641
Reference: XF:mercury-mta-bo(6444)
Reference:
URL:http://www.iss.net/security_center/static/6444.php
Name: CVE-2001-0444
Description:
Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka
"show nat") command to the terminal of the next user who
attempts to connect to the router via telnet, which
could allow that user to obtain sensitive information.
Status: Entry
Reference: BUGTRAQ:20010420 Bug in Cisco CBOS
v2.3.0.053
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0380.html
Reference: XF:cisco-cbos-gain-information(6453)
Reference:
URL:http://xforce.iss.net/static/6453.php
Reference: BID:2635
Reference:
URL:http://www.securityfocus.com/bid/2635
Reference: OSVDB:1796
Reference: URL:http://www.osvdb.org/1796
Name: CVE-2001-0449
Description:
Buffer overflow in WinZip 8.0 allows attackers to
execute arbitrary commands via a long file name that is
processed by the /zipandemail command line option.
Status: Entry
Reference: BUGTRAQ:20010302 def-2001-09: Winzip32
zipandemail Buffer Overflow
Reference:
URL:http://www.securityfocus.com/archive/1/166211
Reference: XF:winzip-zipandemail-bo(6191)
Reference:
URL:http://xforce.iss.net/static/6191.php
Name: CVE-2001-0455
Description:
Cisco Aironet 340 Series wireless bridge before 8.55
does not properly disable access to the web interface,
which allows remote attackers to modify its
configuration. Status: Entry
Reference: CISCO:20010307 Access to the Cisco
Aironet 340 Series Wireless Bridge via Web Interface
Reference:
URL:http://www.cisco.com/warp/public/707/Aironet340-pub.shtml
Reference: XF:cisco-aironet-web-access(6200)
Reference:
URL:http://xforce.iss.net/static/6200.php
Reference: OSVDB:5597
Reference: URL:http://www.osvdb.org/5597
Name: CVE-2001-0456
Description:
postinst installation script for Proftpd in Debian 2.2
does not properly change the "run as uid/gid root"
configuration when the user enables anonymous access,
which causes the server to run at a higher privilege
than intended. Status: Entry
Reference: DEBIAN:DSA-032
Reference:
URL:http://www.debian.org/security/2001/dsa-032
Reference: XF:proftpd-postinst-root(6208)
Reference:
URL:http://xforce.iss.net/static/6208.php
Name: CVE-2001-0457
Description:
man2html before 1.5-22 allows remote attackers to cause
a denial of service (memory exhaustion). Status:
Entry
Reference: DEBIAN:DSA-035
Reference:
URL:http://www.debian.org/security/2001/dsa-035
Reference: XF:man2html-remote-dos(6211)
Reference:
URL:http://xforce.iss.net/static/6211.php
Reference: OSVDB:5631
Reference: URL:http://www.osvdb.org/5631
Name: CVE-2001-0461
Description:
template.cgi in Free On-Line Dictionary of Computing
(FOLDOC) allows remote attackers to read files and
execute commands via shell metacharacters in the
argument to template.cgi. Status: Entry
Reference: BUGTRAQ:20010309 Cgisecurity.com
advisory #4 The Free On-line Dictionary of Computing
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0109.html
Reference:
CONFIRM:http://wombat.doc.ic.ac.uk/foldoc/index.html
Reference: XF:foldoc-cgi-execute-commands
Reference:
URL:http://xforce.iss.net/static/6217.php
Reference: OSVDB:5591
Reference: URL:http://www.osvdb.org/5591
Name: CVE-2001-0462
Description:
Directory traversal vulnerability in Perl web server 0.3
and earlier allows remote attackers to read arbitrary
files via a .. (dot dot) in the URL. Status:
Entry
Reference: BUGTRAQ:20010424 Advisory for perl
webserver
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0426.html
Reference:
XF:perl-webserver-directory-traversal(6451)
Reference:
URL:http://xforce.iss.net/static/6451.php
Reference: BID:2648
Reference:
URL:http://www.securityfocus.com/bid/2648
Name: CVE-2001-0463
Description:
Directory traversal vulnerability in cal_make.pl in
PerlCal allows remote attackers to read arbitrary files
via a .. (dot dot) in the p0 parameter. Status:
Entry
Reference: BUGTRAQ:20010427 PerlCal (CGI) show
files vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0506.html
Reference:
CONFIRM:http://www.perlcal.com/calendar/docs/bugs.txt
Reference: BID:2663
Reference:
URL:http://www.securityfocus.com/bid/2663
Reference:
XF:perlcal-calmake-directory-traversal(6480)
Reference:
URL:http://xforce.iss.net/static/6480.php
Name: CVE-2001-0465
Description:
TurboTax saves passwords in a temporary file when a user
imports investment tax information from a financial
institution, which could allow local users to obtain
sensitive information. Status: Entry
Reference: BUGTRAQ:20010405
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98653594732053&w=2
Reference:
CONFIRM:http://www.turbotax.com/atr/update/
Reference: XF:turbotax-save-passwords(6622)
Reference:
URL:http://xforce.iss.net/static/6622.php
Name: CVE-2001-0467
Description:
Directory traversal vulnerability in RobTex Viking Web
server before 1.07-381 allows remote attackers to read
arbitrary files via a \... (modified dot dot) in an HTTP
URL request. Status: Entry
Reference: BUGTRAQ:20010423 Vulnerability in
Viking Web Server
Reference:
URL:http://www.securityfocus.com/archive/1/178935
Reference:
CONFIRM:http://www.robtex.com/files/viking/beta/chglog.txt
Reference: BID:2643
Reference:
URL:http://www.securityfocus.com/bid/2643
Reference:
XF:viking-dot-directory-traversal(6450)
Reference:
URL:http://xforce.iss.net/static/6450.php
Name: CVE-2001-0469
Description:
rwho daemon rwhod in FreeBSD 4.2 and earlier, and
possibly other operating systems, allows remote
attackers to cause a denial of service via malformed
packets with a short length. Status: Entry
Reference: FREEBSD:FreeBSD-SA-01:29
Reference:
URL:http://archives.neohapsis.com/archives/freebsd/2001-03/0163.html
Reference: BID:2473
Reference:
URL:http://www.securityfocus.com/bid/2473
Reference: XF:rwhod-remote-dos(6229)
Reference:
URL:http://xforce.iss.net/static/6229.php
Name: CVE-2001-0473
Description:
Format string vulnerability in Mutt before 1.2.5 allows
a remote malicious IMAP server to execute arbitrary
commands. Status: Entry
Reference: MANDRAKE:MDKSA-2001-031
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-031.php3
Reference: REDHAT:RHSA-2001:029
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-029.html
Reference: BUGTRAQ:20010315 Immunix OS Security
update for mutt
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98473109630421&w=2
Reference: CONECTIVA:CLA-2001:385
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000385
Reference: BUGTRAQ:20010320 Trustix Security
Advisory - mutt
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0246.html
Reference: XF:mutt-imap-format-string(6235)
Reference:
URL:http://xforce.iss.net/static/6235.php
Reference: OSVDB:5615
Reference: URL:http://www.osvdb.org/5615
Name: CVE-2001-0474
Description:
Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2
allows local users to overwrite arbitrary files via a
symlink attack on the /tmp/glxmemory file. Status:
Entry
Reference: MANDRAKE:MDKSA-2001:029
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-029.php3
Reference: XF:mesa-utahglx-symlink(6231)
Reference:
URL:http://xforce.iss.net/static/6231.php
Name: CVE-2001-0475
Description:
index.php in Jelsoft vBulletin does not properly
initialize a PHP variable that is used to store template
information, which allows remote attackers to execute
arbitrary PHP code via special characters in the
templatecache parameter. Status: Entry
Reference: BUGTRAQ:20010315 vBulletin allows
arbitrary code execution
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0180.html
Reference: BID:2474
Reference:
URL:http://www.securityfocus.com/bid/2474
Reference:
CONFIRM:http://www.vbulletin.com/forum/showthread.php?s=b20af207b5b908ecf7a4ecf56fbe3cd3&threadid=10839
Reference:
XF:vbulletin-php-elevate-privileges(6237)
Reference:
URL:http://xforce.iss.net/static/6237.php
Name: CVE-2001-0481
Description:
Vulnerability in rpmdrake in Mandrake Linux 8.0 related
to insecure temporary file handling. Status:
Entry
Reference: MANDRAKE:MDKSA-2001:043
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-043.php3
Reference: XF:linux-rpmdrake-temp-file(6494)
Reference:
URL:http://xforce.iss.net/static/6494.php
Reference: OSVDB:5612
Reference: URL:http://www.osvdb.org/5612
Name: CVE-2001-0482
Description:
Configuration error in Argus PitBull LX allows root
users to bypass specified access control restrictions
and cause a denial of service or execute arbitrary
commands by modifying kernel variables such as MaxFiles,
MaxInodes, and ModProbePath in /proc/sys via calls to
sysctl. Status: Entry
Reference: BUGTRAQ:20010330 Serious Pitbull LX
Vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0475.html
Reference: XF:pitbull-lx-modify-kernel(6623)
Reference:
URL:http://xforce.iss.net/static/6623.php
Name: CVE-2001-0485
Description:
Unknown vulnerability in netprint in IRIX 6.2, and
possibly other versions, allows local users with lp
privileges attacker to execute arbitrary commands via
the -n option. Status: Entry
Reference: BUGTRAQ:20010426 IRIX
/usr/lib/print/netprint local root symbols exploit.
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0475.html
Reference: BUGTRAQ:20010427 Re: IRIX
/usr/lib/print/netprint local root symbols exploit.
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0502.html
Reference: SGI:20010701-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20010701-01-P
Reference: BID:2656
Reference:
URL:http://www.securityfocus.com/bid/2656
Reference: OSVDB:8571
Reference: URL:http://www.osvdb.org/8571
Reference: XF:irix-netprint-shared-library(6473)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6473
Name: CVE-2001-0486
Description:
Remote attackers can cause a denial of service in Novell
BorderManager 3.6 and earlier by sending TCP SYN flood
to port 353. Status: Entry
Reference: VULN-DEV:20010402 (no subject)
Reference:
URL:http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0020.html
Reference: BUGTRAQ:20010420 Novell BorderManager
3.5 VPN Denial of Service
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98779821207867&w=2
Reference:
CONFIRM:http://support.novell.com/cgi-bin/search/searchtid.cgi?/2959062.htm
Reference: BUGTRAQ:20010429 Proof of concept DoS
against novell border manager enterprise
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98865027328391&w=2
Reference: BUGTRAQ:20010501 Re: Proof of concept
DoS against novell border manager enterprise edition 3.5
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0000.html
Reference: BID:2623
Reference:
URL:http://www.securityfocus.com/bid/2623
Reference: XF:bordermanager-vpn-syn-dos(6429)
Reference:
URL:http://xforce.iss.net/static/6429.php
Name: CVE-2001-0487
Description:
AIX SNMP server snmpd allows remote attackers to cause a
denial of service via a RST during the TCP connection.
Status: Entry
Reference: AIXAPAR:IY17630
Reference:
URL:http://www-1.ibm.com/support/search.wss?rs=0&q=IY17630&apar=only
Reference: XF:aix-snmpd-rst-dos(6996)
Reference:
URL:http://www.iss.net/security_center/static/6996.php
Reference: OSVDB:5611
Reference: URL:http://www.osvdb.org/5611
Name: CVE-2001-0488
Description:
pcltotiff in HP-UX 10.x has unnecessary set group id
permissions, which allows local users to cause a denial
of service. Status: Entry
Reference: HP:HPSBUX0104-149
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0104-149
Reference: BID:2646
Reference:
URL:http://www.securityfocus.com/bid/2646
Reference:
XF:hp-pcltotiff-insecure-permissions(6447)
Reference:
URL:http://xforce.iss.net/static/6447.php
Reference: OSVDB:2188
Reference: URL:http://www.osvdb.org/2188
Name: CVE-2001-0489
Description:
Format string vulnerability in gftp prior to 2.0.8
allows remote malicious FTP servers to execute arbitrary
commands. Status: Entry
Reference: VULN-DEV:20010417 gftp exploitable?
Reference:
URL:http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0231.html
Reference: REDHAT:RHSA-2001:053
Reference:
URL:http://archives.neohapsis.com/archives/linux/redhat/2001-q2/0043.html
Reference: MANDRAKE:MDKSA-2001-044
Reference: DEBIAN:DSA-057
Reference:
URL:http://www.debian.org/security/2001/dsa-057
Reference: BID:2657
Reference:
URL:http://www.securityfocus.com/bid/2657
Reference: XF:gftp-format-string(6478)
Reference:
URL:http://xforce.iss.net/static/6478.php
Reference: OSVDB:1805
Reference: URL:http://www.osvdb.org/1805
Name: CVE-2001-0493
Description:
Small HTTP server 2.03 allows remote attackers to cause
a denial of service via a URL that contains an MS-DOS
device name such as aux. Status: Entry
Reference: BUGTRAQ:20010424 Advisory for Small
HTTP Server
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0428.html
Reference:
CONFIRM:http://home.lanck.net/mf/srv/index.htm
Reference: BID:2649
Reference:
URL:http://www.securityfocus.com/bid/2649
Reference: XF:small-http-aux-dos(6446)
Reference:
URL:http://xforce.iss.net/static/6446.php
Name: CVE-2001-0494
Description:
Buffer overflow in IPSwitch IMail SMTP server 6.06 and
possibly prior versions allows remote attackers to
execute arbitrary code via a long From: header.
Status: Entry
Reference: BUGTRAQ:20010424 IPSwitch IMail 6.06
SMTP Remote System Access Vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0433.html
Reference:
CONFIRM:http://ipswitch.com/Support/IMail/news.html
Reference: XF:ipswitch-imail-smtp-bo(6445)
Reference:
URL:http://xforce.iss.net/static/6445.php
Reference: OSVDB:5610
Reference: URL:http://www.osvdb.org/5610
Name: CVE-2001-0495
Description:
Directory traversal in DataWizard WebXQ server 1.204
allows remote attackers to view files outside of the web
root via a .. (dot dot) attack. Status: Entry
Reference: BUGTRAQ:20010426 Vulnerability in
WebXQ Server
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0490.html
Reference: BID:2660
Reference:
URL:http://www.securityfocus.com/bid/2660
Reference: XF:webxq-dot-directory-traversal(6466)
Reference:
URL:http://xforce.iss.net/static/6466.php
Reference: OSVDB:1799
Reference: URL:http://www.osvdb.org/1799
Name: CVE-2001-0497
Description:
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen
in BIND 9.1.2 and earlier, set insecure permissions for
a HMAC-MD5 shared secret key file used for DNS
Transactional Signatures (TSIG), which allows attackers
to obtain the keys and perform dynamic DNS updates.
Status: Entry
Reference: ISS:20010611 BIND Inadvertent Local
Exposure of HMAC-MD5 (TSIG) Keys
Reference:
URL:http://xforce.iss.net/alerts/advise78.php
Reference: XF:bind-local-key-exposure(6694)
Reference:
URL:http://xforce.iss.net/static/6694.php
Reference: OSVDB:5609
Reference: URL:http://www.osvdb.org/5609
Name: CVE-2001-0500
Description:
Buffer overflow in ISAPI extension (idq.dll) in Index
Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and
earlier allows remote attackers to execute arbitrary
commands via a long argument to Internet Data
Administration (.ida) and Internet Data Query (.idq)
files such as default.ida, as commonly exploited by Code
Red. Status: Entry
Reference: BUGTRAQ:20010618 All versions of
Microsoft Internet Information Services, Remote buffer
overflow (SYSTEM Level Access)
Reference:
URL:http://www.securityfocus.com/archive/1/191873
Reference: MS:MS01-033
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-033.asp
Reference: CERT:CA-2001-13
Reference:
URL:http://www.cert.org/advisories/CA-2001-13.html
Reference: BID:2880
Reference:
URL:http://www.securityfocus.com/bid/2880
Reference: XF:iis-isapi-idq-bo(6705)
Reference:
URL:http://www.iss.net/security_center/static/6705.php
Reference: CIAC:L-098
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-098.shtml
Reference: OVAL:oval:org.mitre.oval:def:197
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:197
Name: CVE-2001-0501
Description:
Microsoft Word 2002 and earlier allows attackers to
automatically execute macros without warning the user by
embedding the macros in a manner that escapes detection
by the security scanner. Status: Entry
Reference: BUGTRAQ:20010622 Fwd: Microsoft Word
macro vulnerability advisory MS01-034
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99325144322224&w=2
Reference: MS:MS01-034
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-034.asp
Reference: BID:2876
Reference:
URL:http://www.securityfocus.com/bid/2876
Reference: XF:msword-macro-bypass-security(6732)
Reference:
URL:http://xforce.iss.net/static/6732.php
Name: CVE-2001-0502
Description:
Running Windows 2000 LDAP Server over SSL, a function
does not properly check the permissions of a user
request when the directory principal is a domain user
and the data attribute is the domain password, which
allows local users to modify the login password of other
users. Status: Entry
Reference: MS:MS01-036
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-036.asp
Reference: CIAC:L-101
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-101.shtml
Reference: XF:win2k-ldap-change-passwords(6745)
Reference:
URL:http://xforce.iss.net/static/6745.php
Reference: BID:2929
Reference:
URL:http://www.securityfocus.com/bid/2929
Name: CVE-2001-0503
Description:
Microsoft NetMeeting 3.01 with Remote Desktop Sharing
enabled allows remote attackers to cause a denial of
service via a malformed string to the NetMeeting service
port, aka a variant of the "NetMeeting Desktop Sharing"
vulnerability. Status: Entry
Reference: MS:MS00-077
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms00-077.asp
Reference:
XF:netmeeting-desktop-sharing-dos(5368)
Reference:
URL:http://www.iss.net/security_center/static/5368.php
Reference: OSVDB:5608
Reference: URL:http://www.osvdb.org/5608
Name: CVE-2001-0504
Description:
Vulnerability in authentication process for SMTP service
in Microsoft Windows 2000 allows remote attackers to use
incorrect credentials to gain privileges and conduct
activites such as mail relaying. Status: Entry
Reference: MS:MS01-037
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-037.asp
Reference: XF:win2k-smtp-mail-relay(6803)
Reference:
URL:http://xforce.iss.net/static/6803.php
Reference: BID:2988
Reference:
URL:http://www.securityfocus.com/bid/2988
Reference: CIAC:L-107
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-107.shtml
Reference: CERT-VN:VU#435963
Reference:
URL:http://www.kb.cert.org/vuls/id/435963
Name: CVE-2001-0506
Description:
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows
local users to gain system privileges via a Server-Side
Includes (SSI) directive for a long filename, which
triggers the overflow when the directory name is added,
aka the "SSI privilege elevation" vulnerability.
Status: Entry
Reference: BUGTRAQ:20010817 NSFOCUS SA2001-06 :
Microsoft IIS ssinc.dll Buffer Overflow Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99802093532233&w=2
Reference: BUGTRAQ:20011127 IIS Server Side
Include Buffer overflow exploit code
Reference:
URL:http://online.securityfocus.com/archive/1/242541
Reference: MS:MS01-044
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-044.asp
Reference: CIAC:L-132
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-132.shtml
Reference: BID:3190
Reference:
URL:http://www.securityfocus.com/bid/3190
Reference: XF:iis-ssi-directive-bo(6984)
Reference:
URL:http://xforce.iss.net/static/6984.php
Name: CVE-2001-0507
Description:
IIS 5.0 uses relative paths to find system files that
will run in-process, which allows local users to gain
privileges via a Trojan horse file, aka the "System file
listing privilege elevation" vulnerability. Status:
Entry
Reference: BUGTRAQ:20010816 ENTERCEPT SECURITY
ALERT: Privilege Escalation Vulnerability in Microsoft
IIS
Reference:
URL:http://online.securityfocus.com/archive/1/205069
Reference: MS:MS01-044
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-044.asp
Reference:
XF:iis-relative-path-privilege-elevation(6985)
Reference:
URL:http://xforce.iss.net/static/6985.php
Reference: CIAC:L-132
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-132.shtml
Reference: OSVDB:5607
Reference: URL:http://www.osvdb.org/5607
Reference: OVAL:oval:org.mitre.oval:def:909
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:909
Reference: OVAL:oval:org.mitre.oval:def:912
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:912
Name: CVE-2001-0508
Description:
Vulnerability in IIS 5.0 allows remote attackers to
cause a denial of service (restart) via a long, invalid
WebDAV request. Status: Entry
Reference: BUGTRAQ:20010506 IIS 5.0 PROPFIND DOS
#2
Reference:
URL:http://online.securityfocus.com/archive/1/182579
Reference: MS:MS01-044
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-044.asp
Reference: XF:iis-webdav-long-request-dos(6982)
Reference:
URL:http://www.iss.net/security_center/static/6982.php
Reference: BID:2690
Reference:
URL:http://www.securityfocus.com/bid/2690
Reference: OSVDB:5606
Reference: URL:http://www.osvdb.org/5606
Reference: OSVDB:5633
Reference: URL:http://www.osvdb.org/5633
Name: CVE-2001-0513
Description:
Oracle listener process on Windows NT redirects
connection requests to another port and creates a
separate thread to process the request, which allows
remote attackers to cause a denial of service by
repeatedly connecting to the Oracle listener but not
connecting to the redirected port. Status: Entry
Reference: ISS:20010619 Oracle Redirect Denial of
Service
Reference:
URL:http://xforce.iss.net/alerts/advise81.php
Reference: CERT-VN:VU#105259
Reference:
URL:http://www.kb.cert.org/vuls/id/105259
Reference: XF:oracle-listener-redirect-dos(6717)
Reference:
URL:http://xforce.iss.net/static/6717.php
Reference: OSVDB:5600
Reference: URL:http://www.osvdb.org/5600
Name: CVE-2001-0514
Description:
SNMP service in Atmel 802.11b VNET-B Access Point 1.3
and earlier, as used in Netgear ME102 and Linksys WAP11,
accepts arbitrary community strings with requested MIB
modifications, which allows remote attackers to obtain
sensitive information such as WEP keys, cause a denial
of service, or gain access to the network. Status:
Entry
Reference: ISS:20010620 Multiple Vendor 802.11b
Access Point SNMP authentication flaw
Reference:
URL:http://xforce.iss.net/alerts/advise83.php
Reference: XF:atmel-vnetb-ap-snmp-security(6576)
Reference:
URL:http://xforce.iss.net/static/6576.php
Reference: BID:2896
Reference:
URL:http://www.securityfocus.com/bid/2896
Name: CVE-2001-0517
Description:
Oracle listener in Oracle 8i on Solaris allows remote
attackers to cause a denial of service via a malformed
connection packet with a maximum transport data size
that is set to 0. Status: Entry
Reference: ISS:20010515 Multiple Oracle Listener
Denial of Service Vulnerabilities
Reference:
URL:http://xforce.iss.net/alerts/advise82.php
Reference:
CONFIRM:http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf
Reference:
XF:oracle-listener-data-transport-dos(6715)
Reference:
URL:http://xforce.iss.net/static/6715.php
Reference: OSVDB:5590
Reference: URL:http://www.osvdb.org/5590
Name: CVE-2001-0518
Description:
Oracle listener before Oracle 9i allows attackers to
cause a denial of service by repeatedly sending the
first portion of a fragmented Oracle command without
sending the remainder of the command, which causes the
listener to hang. Status: Entry
Reference: ISS:20010515 Multiple Oracle Listener
Denial of Service Vulnerabilities
Reference:
URL:http://xforce.iss.net/alerts/advise82.php
Reference:
CONFIRM:http://otn.oracle.com/deploy/security/alerts.htm
Reference:
XF:oracle-listener-fragmentation-dos(6716)
Reference:
URL:http://xforce.iss.net/static/6716.php
Name: CVE-2001-0522
Description:
Format string vulnerability in Gnu Privacy Guard (aka
GnuPG or gpg) 1.05 and earlier can allow an attacker to
gain privileges via format strings in the original
filename that is stored in an encrypted file. Status:
Entry
Reference: BUGTRAQ:20010529 [synnergy] - GnuPG
remote format string vulnerability
Reference: BUGTRAQ:20010601 The GnuPG format
string bug (was: TSLSA-2001-0009 - GnuPG)
Reference:
URL:http://online.securityfocus.com/archive/1/188218
Reference:
CONFIRM:http://www.gnupg.org/whatsnew.html#rn20010529
Reference: MANDRAKE:MDKSA-2001:053
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-053.php3
Reference: CONECTIVA:CLA-2001:399
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000399
Reference: DEBIAN:DSA-061
Reference:
URL:http://www.debian.org/security/2001/dsa-061
Reference: IMMUNIX:IMNX-2001-70-023-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-023-01
Reference: REDHAT:RHSA-2001:073
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-073.html
Reference: CALDERA:CSSA-2001-020.0
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-020.0.txt
Reference: SUSE:SuSE-SA:2001:020
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_020_gpg_txt.html
Reference: TURBO:TLSA2001028
Reference:
URL:http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000439.html
Reference: CERT-VN:VU#403051
Reference:
URL:http://www.kb.cert.org/vuls/id/403051
Reference: BID:2797
Reference:
URL:http://www.securityfocus.com/bid/2797
Reference: OSVDB:1845
Reference: URL:http://www.osvdb.org/1845
Reference: XF:gnupg-tty-format-string(6642)
Reference:
URL:http://xforce.iss.net/static/6642.php
Name: CVE-2001-0525
Description:
Buffer overflow in dsh in dqs 3.2.7 in SuSE Linux 7.0
and earlier, and possibly other operating systems,
allows local users to gain privileges via a long first
command line argument. Status: Entry
Reference: BUGTRAQ:20010519 dqs 3.2.7 local root
exploit.
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0193.html
Reference: BUGTRAQ:20010519 Re: dqs 3.2.7 local
root exploit.
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0195.html
Reference: XF:dqs-dsh-bo(6577)
Reference:
URL:http://xforce.iss.net/static/6577.php
Reference: BID:2749
Reference:
URL:http://www.securityfocus.com/bid/2749
Name: CVE-2001-0526
Description:
Buffer overflow in the Xview library as used by mailtool
in Solaris 8 and earlier allows a local attacker to gain
privileges via the OPENWINHOME environment variable.
Status: Entry
Reference: BUGTRAQ:20010528 [synnergy] - Solaris
mailtool(1) buffer overflow vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0258.html
Reference: SUNBUG:4458476
Reference:
XF:solaris-mailtool-openwinhome-bo(6626)
Reference:
URL:http://xforce.iss.net/static/6626.php
Name: CVE-2001-0527
Description:
DCScripts DCForum versions 2000 and earlier allow a
remote attacker to gain additional privileges by
inserting pipe symbols (|) and newlines into the last
name in the registration form, which will create an
extra entry in the registration database. Status:
Entry
Reference: BUGTRAQ:20010515 DCForum Password File
Manipukation Vulnerability (qDefense Advisory Number
QDAV-5-2000-2)
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0122.html
Reference:
CONFIRM:http://www.dcscripts.com/dcforum/dcfNews/167.html
Reference: XF:dcforum-cgi-admin-access(6538)
Reference:
URL:http://xforce.iss.net/static/6538.php
Reference: BID:2728
Reference:
URL:http://www.securityfocus.com/bid/2728
Reference: OSVDB:480
Reference: URL:http://www.osvdb.org/480
Name: CVE-2001-0528
Description:
Oracle E-Business Suite Release 11i Applications Desktop
Integrator (ADI) version 7.x includes a debug version of
FNDPUB11I.DLL, which logs the APPS schema password in
cleartext in a debug file, which allows local users to
obtain the password and gain privileges. Status:
Entry
Reference: BUGTRAQ:20010507 Oracle's ADI
7.1.1.10.1 Major security hole
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0044.html
Reference: BUGTRAQ:20010522 Vulnerability in
Oracle E-Business Suite Release 11i Applications Desktop
Integrator
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0223.html
Reference: BID:2694
Reference:
URL:http://www.securityfocus.com/bid/2694
Reference:
XF:oracle-adi-plaintext-passwords(6501)
Reference:
URL:http://xforce.iss.net/static/6501.php
Name: CVE-2001-0529
Description:
OpenSSH version 2.9 and earlier, with X forwarding
enabled, allows a local attacker to delete any file
named 'cookies' via a symlink attack. Status:
Entry
Reference: BUGTRAQ:20010604 SSH allows deletion
of other users files...
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0322.html
Reference: BUGTRAQ:20010604 Re: SSH allows
deletion of other users files...
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0007.html
Reference: BUGTRAQ:20010605 OpenSSH_2.5.2p2 RH7.0
<- version info
Reference:
URL:http://online.securityfocus.com/archive/1/188737
Reference: NETBSD:NetBSD-SA2001-010
Reference:
URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-010.txt.asc
Reference: CALDERA:CSSA-2001-023.0
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-023.0.txt
Reference: CERT-VN:VU#655259
Reference:
URL:http://www.kb.cert.org/vuls/id/655259
Reference: OPENBSD:20010612
Reference:
URL:http://www.openbsd.org/errata29.html
Reference: IMMUNIX:IMNX-2001-70-034-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-034-01
Reference: CONECTIVA:CLA-2001:431
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000431
Reference: BID:2825
Reference:
URL:http://www.securityfocus.com/bid/2825
Reference: XF:openssh-symlink-file-deletion(6676)
Reference:
URL:http://xforce.iss.net/static/6676.php
Reference: OSVDB:1853
Reference: URL:http://www.osvdb.org/1853
Name: CVE-2001-0530
Description:
Spearhead NetGAP 200 and 300 before build 78 allow a
remote attacker to bypass file blocking and content
inspection via specially encoded URLs which include '%'
characters. Status: Entry
Reference: BUGTRAQ:20010528 Vulnerability
discovered in SpearHead NetGap
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0256.html
Reference: BUGTRAQ:20010607 SpearHead Security
NetGAP
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0047.html
Reference: BID:2798
Reference:
URL:http://www.securityfocus.com/bid/2798
Reference: XF:netgap-unicode-bypass-filter(6625)
Reference:
URL:http://xforce.iss.net/static/6625.php
Name: CVE-2001-0533
Description:
Buffer overflow in libi18n library in IBM AIX 5.1 and
4.3.x allows local users to gain root privileges via a
long LANG environmental variable. Status: Entry
Reference: IBM:MSS-OAR-E01-2001:271.1
Reference:
URL:http://www-1.ibm.com/services/continuity/recover1.nsf/advisories/85256A3400529A8685256A8D00804A37/$file/oar271.txt
Reference: XF:aix-libi18n-lang-bo(6863)
Reference:
URL:http://xforce.iss.net/static/6863.php
Reference: CIAC:L-123
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-123.shtml
Reference: OSVDB:5585
Reference: URL:http://www.osvdb.org/5585
Name: CVE-2001-0537
Description:
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers
to bypass authentication and execute arbitrary commands,
when local authorization is being used, by specifying a
high access level in the URL. Status: Entry
Reference: CISCO:20010627 IOS HTTP authorization
vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/IOS-httplevel-pub.html
Reference: BUGTRAQ:20010629 Re: Cisco Security
Advisory: IOS HTTP authorization vulnerability
Reference:
URL:http://www.securityfocus.com/archive/1/4.3.2.7.2.20010629095801.0c3e6a70@brussels.cisco.com
Reference: BUGTRAQ:20010702 Cisco IOS HTTP
Configuration Exploit
Reference:
URL:http://www.securityfocus.com/archive/1/1601227034.20010702112207@olympos.org
Reference: BUGTRAQ:20010702 Cisco device HTTP
exploit...
Reference:
URL:http://www.securityfocus.com/archive/1/Pine.LNX.3.96.1010702134611.22995B-100000@Lib-Vai.lib.asu.edu
Reference: BUGTRAQ:20010702 ios-http-auth.sh
Reference:
URL:http://www.securityfocus.com/archive/1/20010703011650.60515.qmail@web14910.mail.yahoo.com
Reference: CERT:CA-2001-14
Reference:
URL:http://www.cert.org/advisories/CA-2001-14.html
Reference: CIAC:L-106
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-106.shtml
Reference: BID:2936
Reference:
URL:http://www.securityfocus.com/bid/2936
Reference: OSVDB:578
Reference: URL:http://www.osvdb.org/578
Reference: XF:cisco-ios-admin-access(6749)
Reference:
URL:http://xforce.iss.net/static/6749.php
Name: CVE-2001-0538
Description:
Microsoft Outlook View ActiveX Control in Microsoft
Outlook 2002 and earlier allows remote attackers to
execute arbitrary commands via a malicious HTML e-mail
message or web page. Status: Entry
Reference: BUGTRAQ:20010712 MS Office XP - the
more money I give to Microsoft, the more vulnerable my
Windows computers are
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99496431214078&w=2
Reference: NTBUGTRAQ:20010712 Vulnerability in
IE/Outlook ActiveX control
Reference:
URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0107&L=ntbugtraq&F=P&S=&P=862
Reference: MS:MS01-038
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-038.asp
Reference: CIAC:L-113
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-113.shtml
Reference: CERT-VN:VU#131569
Reference:
URL:http://www.kb.cert.org/vuls/id/131569
Reference: XF:outlook-activex-view-control(6831)
Reference:
URL:http://xforce.iss.net/static/6831.php
Reference: BID:3025
Reference:
URL:http://www.securityfocus.com/bid/3025
Name: CVE-2001-0540
Description:
Memory leak in Terminal servers in Windows NT and
Windows 2000 allows remote attackers to cause a denial
of service (memory exhaustion) via a large number of
malformed Remote Desktop Protocol (RDP) requests to port
3389. Status: Entry
Reference: MS:MS01-040
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-040.asp
Reference: BID:3099
Reference:
URL:http://www.securityfocus.com/bid/3099
Reference: XF:win-terminal-rdp-dos(6912)
Reference:
URL:http://xforce.iss.net/static/6912.php
Name: CVE-2001-0541
Description:
Buffer overflow in Microsoft Windows Media Player 7.1
and earlier allows remote attackers to execute arbitrary
commands via a malformed Windows Media Station (.NSC)
file. Status: Entry
Reference: BUGTRAQ:20010527 Microsoft Windows
Media Player Buffer Overflow Vulnerability
Reference:
URL:http://www.securityfocus.com/archive/1/187001
Reference: MS:MS01-042
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-042.asp
Reference: XF:mediaplayer-nsc-bo(6907)
Reference:
URL:http://xforce.iss.net/static/6907.php
Reference: BID:3105
Reference:
URL:http://www.securityfocus.com/bid/3105
Name: CVE-2001-0543
Description:
Memory leak in NNTP service in Windows NT 4.0 and
Windows 2000 allows remote attackers to cause a denial
of service (memory exhaustion) via a large number of
malformed posts. Status: Entry
Reference: MS:MS01-043
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-043.asp
Reference: XF:win-nntp-dos(6977)
Reference:
URL:http://xforce.iss.net/static/6977.php
Reference: BID:3183
Reference:
URL:http://www.securityfocus.com/bid/3183
Reference: OVAL:oval:org.mitre.oval:def:334
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:334
Name: CVE-2001-0544
Description:
IIS 5.0 allows local users to cause a denial of service
(hang) via by installing content that produces a certain
invalid MIME Content-Type header, which corrupts the
File Type table. Status: Entry
Reference: MS:MS01-044
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-044.asp
Reference: CIAC:L-132
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-132.shtml
Reference: XF:iis-invalid-mime-header-dos(6983)
Reference:
URL:http://xforce.iss.net/static/6983.php
Reference: BID:3195
Reference:
URL:http://www.securityfocus.com/bid/3195
Name: CVE-2001-0545
Description:
IIS 4.0 with URL redirection enabled allows remote
attackers to cause a denial of service (crash) via a
malformed request that specifies a length that is
different than the actual length. Status: Entry
Reference: MS:MS01-044
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-044.asp
Reference: XF:iis-url-redirection-dos(6981)
Reference:
URL:http://xforce.iss.net/static/6981.php
Reference: CIAC:L-132
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-132.shtml
Reference: OSVDB:5736
Reference: URL:http://www.osvdb.org/5736
Name: CVE-2001-0546
Description:
Memory leak in H.323 Gatekeeper Service in Microsoft
Internet Security and Acceleration (ISA) Server 2000
allows remote attackers to cause a denial of service
(resource exhaustion) via a large amount of malformed
H.323 data. Status: Entry
Reference: MS:MS01-045
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-045.asp
Reference: XF:isa-h323-gatekeeper-dos(6989)
Reference:
URL:http://xforce.iss.net/static/6989.php
Reference: BID:3196
Reference:
URL:http://www.securityfocus.com/bid/3196
Name: CVE-2001-0547
Description:
Memory leak in the proxy service in Microsoft Internet
Security and Acceleration (ISA) Server 2000 allows local
attackers to cause a denial of service (resource
exhaustion). Status: Entry
Reference: MS:MS01-045
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-045.asp
Reference: XF:isa-proxy-memory-leak-dos(6990)
Reference:
URL:http://xforce.iss.net/static/6990.php
Reference: BID:3197
Reference:
URL:http://www.securityfocus.com/bid/3197
Name: CVE-2001-0548
Description:
Buffer overflow in dtmail in Solaris 2.6 and 7 allows
local users to gain privileges via the MAIL environment
variable. Status: Entry
Reference: BUGTRAQ:20010724 NSFOCUS SA2001-04 :
Solaris dtmail Buffer Overflow Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99598918914068&w=2
Reference: XF:solaris-dtmail-bo(6879)
Reference:
URL:http://xforce.iss.net/static/6879.php
Reference: BID:3081
Reference:
URL:http://www.securityfocus.com/bid/3081
Name: CVE-2001-0549
Description:
Symantec LiveUpdate 1.5 stores proxy passwords in
cleartext in a registry key, which could allow local
users to obtain the passwords. Status: Entry
Reference: CERT-VN:VU#814187
Reference:
URL:http://www.kb.cert.org/vuls/id/814187
Reference:
CONFIRM:http://www.sarc.com/avcenter/security/Content/2001_07_20.html
Reference:
XF:liveupdate-obtain-proxy-password(7013)
Reference:
URL:http://xforce.iss.net/static/7013.php
Name: CVE-2001-0550
Description:
wu-ftpd 2.6.1 allows remote attackers to execute
arbitrary commands via a "~{" argument to commands such
as CWD, which is not properly handled by the glob
function (ftpglob). Status: Entry
Reference: VULN-DEV:20010430 some ftpd
implementations mishandle CWD ~{
Reference:
URL:http://www.securityfocus.com/archive/82/180823
Reference: BUGTRAQ:20011128 CORE-20011001: Wu-FTP
glob heap corruption vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100700363414799&w=2
Reference: ISS:20011129 WU-FTPD Heap Corruption
Vulnerability
Reference: CERT:CA-2001-33
Reference:
URL:http://www.cert.org/advisories/CA-2001-33.html
Reference: CERT-VN:VU#886083
Reference:
URL:http://www.kb.cert.org/vuls/id/886083
Reference: CALDERA:CSSA-2001-041.0
Reference:
URL:http://www.caldera.com/support/security/advisories/CSSA-2001-041.0.txt
Reference: CALDERA:CSSA-2001-SCO.36
Reference: CALDERA:CSSA-2002-SCO.1
Reference: CONECTIVA:CLA-2001:442
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000442
Reference: DEBIAN:DSA-087
Reference:
URL:http://www.debian.org/security/2001/dsa-087
Reference: HP:HPSBUX0107-162
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0107-162
Reference: IMMUNIX:IMNX-2001-70-036-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-036-01
Reference: MANDRAKE:MDKSA-2001:090
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-090.php3
Reference: REDHAT:RHSA-2001:157
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-157.html
Reference: SUSE:SuSE-SA:2001:043
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_043_wuftpd_txt.html
Reference: BID:3581
Reference:
URL:http://www.securityfocus.com/bid/3581
Reference: XF:wuftp-glob-heap-corruption(7611)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7611
Name: CVE-2001-0553
Description:
SSH Secure Shell 3.0.0 on Unix systems does not properly
perform password authentication to the sshd2 daemon,
which allows local users to gain access to accounts with
short password fields, such as locked accounts that use
"NP" in the password field. Status: Entry
Reference: BUGTRAQ:20010720 URGENT SECURITY
ADVISORY FOR SSH SECURE SHELL 3.0.0
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0486.html
Reference:
CONFIRM:http://www.ssh.com/products/ssh/exploit.cfm
Reference: CERT-VN:VU#737451
Reference:
URL:http://www.kb.cert.org/vuls/id/737451
Reference: CIAC:L-121
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-121.shtml
Reference: BID:3078
Reference:
URL:http://www.securityfocus.com/bid/3078
Reference:
XF:ssh-password-length-unauth-access(6868)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6868
Reference: OSVDB:586
Reference: URL:http://www.osvdb.org/586
Name: CVE-2001-0554
Description:
Buffer overflow in BSD-based telnetd telnet daemon on
various operating systems allows remote attackers to
execute arbitrary commands via a set of options
including AYT (Are You There), which is not properly
handled by the telrcv function. Status: Entry
Reference: BUGTRAQ:20010718 multiple vendor
telnet daemon vulnerability
Reference:
URL:http://www.securityfocus.com/archive/1/197804
Reference: BUGTRAQ:20010725 Telnetd AYT overflow
scanner
Reference:
URL:http://online.securityfocus.com/archive/1/199496
Reference: BUGTRAQ:20010810 ADV/EXP: netkit
<=0.17 in.telnetd remote buffer overflow
Reference:
URL:http://online.securityfocus.com/archive/1/203000
Reference: BUGTRAQ:20010725 SCO - Telnetd AYT
overflow ?
Reference:
URL:http://online.securityfocus.com/archive/1/199541
Reference: CERT:CA-2001-21
Reference:
URL:http://www.cert.org/advisories/CA-2001-21.html
Reference: CIAC:L-131
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-131.shtml
Reference: CALDERA:CSSA-2001-030.0
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-030.0.txt
Reference: CALDERA:CSSA-2001-SCO.10
Reference:
URL:ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.10/CSSA-2001-SCO.10.txt
Reference: CISCO:20020129 Cisco CatOS Telnet
Buffer Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/catos-telrcv-vuln-pub.shtml
Reference: COMPAQ:SSRT0745U
Reference:
URL:http://ftp.support.compaq.com/patches/.new/html/SSRT0745U.shtml
Reference: CONECTIVA:CLA-2001:413
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000413
Reference: DEBIAN:DSA-070
Reference:
URL:http://www.debian.org/security/2001/dsa-070
Reference: DEBIAN:DSA-075
Reference:
URL:http://www.debian.org/security/2001/dsa-075
Reference: FREEBSD:FreeBSD-SA-01:49
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:49.telnetd.asc
Reference: HP:HPSBUX0110-172
Reference:
URL:http://archives.neohapsis.com/archives/hp/2001-q4/0014.html
Reference: IBM:MSS-OAR-E01-2001:298
Reference:
URL:http://online.securityfocus.com/advisories/3476
Reference: MANDRAKE:MDKSA-2001:068
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-068.php3
Reference: NETBSD:NetBSD-SA2001-012
Reference:
URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-012.txt.asc
Reference: SGI:20010801-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20010801-01-P
Reference: REDHAT:RHSA-2001:099
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-099.html
Reference: REDHAT:RHSA-2001:100
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-100.html
Reference: SUSE:SuSE-SA:2001:029
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_029_nkitb_txt.html
Reference: BID:3064
Reference:
URL:http://www.securityfocus.com/bid/3064
Reference: OSVDB:809
Reference: URL:http://www.osvdb.org/809
Reference: XF:telnetd-option-telrcv-bo(6875)
Reference:
URL:http://xforce.iss.net/static/6875.php
Name: CVE-2001-0558
Description:
T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a
remote attacker to create a denial of service via a URL
request which includes a MS-DOS device name (i.e. GET
/aux HTTP/1.0). Status: Entry
Reference: BUGTRAQ:20010507 Advisory for Jana
server
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0086.html
Reference: XF:jana-server-device-dos(6521)
Reference:
URL:http://xforce.iss.net/static/6521.php
Reference: BID:2704
Reference:
URL:http://www.securityfocus.com/bid/2704
Reference: OSVDB:1817
Reference: URL:http://www.osvdb.org/1817
Name: CVE-2001-0559
Description:
crontab in Vixie cron 3.0.1 and earlier does not
properly drop privileges after the failed parsing of a
modification operation, which could allow a local
attacker to gain additional privileges when an editor is
called to correct the error. Status: Entry
Reference: BUGTRAQ:20010507 Vixie cron
vulnerability
Reference:
URL:http://www.securityfocus.com/archive/1/183029
Reference: DEBIAN:DSA-054
Reference:
URL:http://www.debian.org/security/2001/dsa-054
Reference: MANDRAKE:MDKSA-2001:050
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-050.php3
Reference: SUSE:SuSE-SA:2001:17
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_017_cron_txt.html
Reference: BID:2687
Reference:
URL:http://www.securityfocus.com/bid/2687
Reference: XF:vixie-cron-gain-privileges(6508)
Reference:
URL:http://xforce.iss.net/static/6508.php
Name: CVE-2001-0560
Description:
Buffer overflow in Vixie cron 3.0.1-56 and earlier could
allow a local attacker to gain additional privileges via
a long username (> 20 characters). Status: Entry
Reference: BUGTRAQ:20010210 vixie cron possible
local root compromise
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0197.html
Reference: AIXAPAR:IY17048
Reference:
URL:http://www-1.ibm.com/support/search.wss?rs=0&q=IY17048&apar=only
Reference: AIXAPAR:IY17261
Reference:
URL:http://www-1.ibm.com/support/search.wss?rs=0&q=IY17261&apar=only
Reference: MANDRAKE:MDKSA-2001:022
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-022.php3
Reference: REDHAT:RHSA-2001:014
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-014.html
Reference: BUGTRAQ:20010220 Immunix OS Security
update for vixie-cron
Reference:
URL:http://archives.neohapsis.com/archives/linux/immunix/2001-q1/0066.html
Reference: XF:vixie-crontab-bo(6098)
Reference:
URL:http://xforce.iss.net/static/6098.php
Reference: OSVDB:5583
Reference: URL:http://www.osvdb.org/5583
Name: CVE-2001-0563
Description:
ElectroSystems Engineering Inc. ElectroComm 2.0 and
earlier allows a remote attacker to create a denial of
service via large (> 160000 character) strings sent to
port 23. Status: Entry
Reference: BUGTRAQ:20010507 Advisory for
Electrocomm 2.0
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0049.html
Reference: XF:electrocomm-telnet-dos(6514)
Reference:
URL:http://xforce.iss.net/static/6514.php
Reference: BID:2706
Reference:
URL:http://www.securityfocus.com/bid/2706
Name: CVE-2001-0564
Description:
APC Web/SNMP Management Card prior to Firmware 310 only
supports one telnet connection, which allows a remote
attacker to create a denial of service via repeated
failed logon attempts which temporarily locks the card.
Status: Entry
Reference: BUGTRAQ:20010225 APC web/snmp/telnet
management card dos
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0436.html
Reference:
MISC:ftp://ftp.apcftp.com/hardware/webcard/firmware/sy/v310/install.txt
Reference: XF:apc-telnet-dos(6199)
Reference:
URL:http://xforce.iss.net/static/6199.php
Reference: BID:2430
Reference:
URL:http://www.securityfocus.com/bid/2430
Name: CVE-2001-0565
Description:
Buffer overflow in mailx in Solaris 8 and earlier allows
a local attacker to gain additional privileges via a
long '-F' command line option. Status: Entry
Reference: BUGTRAQ:20010502 Solaris mailx
Vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0016.html
Reference: BUGTRAQ:20010511 Solaris
/usr/bin/mailx exploit (SPARC)
Reference:
URL:http://online.securityfocus.com/archive/1/184210
Reference: SUNBUG:4452732
Reference: XF:solaris-mailx-f-bo(8246)
Reference:
URL:http://xforce.iss.net/static/8246.php
Reference: CERT-VN:VU#446864
Reference:
URL:http://www.kb.cert.org/vuls/id/446864
Reference: BID:2610
Reference:
URL:http://www.securityfocus.com/bid/2610
Name: CVE-2001-0567
Description:
Digital Creations Zope 2.3.2 and earlier allows a local
attacker to gain additional privileges via the changing
of ZClass permission mappings for objects and methods in
the ZClass. Status: Entry
Reference:
CONFIRM:http://www.zope.org/Products/Zope/Hotfix_2001-05-01/security_alert
Reference: DEBIAN:DSA-055
Reference:
URL:http://www.debian.org/security/2001/dsa-055
Reference: MANDRAKE:MDKSA-2001:049
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-049.php3
Reference: REDHAT:RHSA-2001:065
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-065.html
Reference: CONECTIVA:CLA-2001:407
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000407
Reference: XF:zope-zclass-gain-privileges(6958)
Reference:
URL:http://xforce.iss.net/static/6958.php
Name: CVE-2001-0573
Description:
lsfs in AIX 4.x allows a local user to gain additional
privileges by creating Trojan horse programs named (1)
grep or (2) lslv in a certain directory that is under
the user's control, which cause lsfs to access the
programs in that directory. Status: Entry
Reference: AIXAPAR:IY16909
Reference:
URL:http://archives.neohapsis.com/archives/aix/2001-q2/0000.html
Reference: XF:aix-lsfs-path(7007)
Reference:
URL:http://xforce.iss.net/static/7007.php
Reference: CERT-VN:VU#123651
Reference:
URL:http://www.kb.cert.org/vuls/id/123651
Reference: OSVDB:5582
Reference: URL:http://www.osvdb.org/5582
Name: CVE-2001-0574
Description:
Directory traversal vulnerability in MP3Mystic prior to
1.04b3 allows a remote attacker to download arbitrary
files via a '..' (dot dot) in the URL. Status:
Entry
Reference: BUGTRAQ:20010507 Advisory for
MP3Mystic
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0046.html
Reference:
CONFIRM:http://mp3mystic.com/mp3mystic/news.phtml
Reference:
XF:mp3mystic-dot-directory-traversal(6504)
Reference:
URL:http://xforce.iss.net/static/6504.php
Reference: BID:2699
Reference:
URL:http://www.securityfocus.com/bid/2699
Reference: OSVDB:1815
Reference: URL:http://www.osvdb.org/1815
Name: CVE-2001-0585
Description:
Gordano NTMail 6.0.3c allows a remote attacker to create
a denial of service via a long (>= 255 characters) URL
request to port 8000 or port 9000. Status: Entry
Reference: BUGTRAQ:20010320 def-2001-13: NTMail
Web Services DoS
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0248.html
Reference: BID:2494
Reference:
URL:http://www.securityfocus.com/bid/2494
Reference: XF:ntmail-long-url-dos(6249)
Reference:
URL:http://xforce.iss.net/static/6249.php
Name: CVE-2001-0586
Description:
TrendMicro ScanMail for Exchange 3.5 Evaluation allows a
local attacker to recover the administrative credentials
for ScanMail via a combination of unprotected registry
keys and weakly encrypted passwords. Status:
Entry
Reference: BUGTRAQ:20010330 STAT Security
Advisory: Trend Micro's ScanMail for Exchange store s
passwords in registry unprotected
Reference:
URL:http://archives.neohapsis.com/archives/ntbugtraq/2001-q1/0049.html
Reference: XF:scanmail-reveals-credentials(6311)
Reference:
URL:http://xforce.iss.net/static/6311.php
Reference: OSVDB:5581
Reference: URL:http://www.osvdb.org/5581
Name: CVE-2001-0589
Description:
NetScreen ScreenOS prior to 2.5r6 on the NetScreen-10
and Netscreen-100 can allow a local attacker to bypass
the DMZ 'denial' policy via specific traffic patterns.
Status: Entry
Reference: BUGTRAQ:20010326 Netscreen: DMZ
Network Receives Some "Denied" Traffic
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0375.html
Reference: BID:2523
Reference:
URL:http://www.securityfocus.com/bid/2523
Reference:
XF:netscreen-screenos-bypass-firewall(6317)
Reference:
URL:http://xforce.iss.net/static/6317.php
Reference: OSVDB:1780
Reference: URL:http://www.osvdb.org/1780
Name: CVE-2001-0590
Description:
Apache Software Foundation Tomcat Servlet prior to 3.2.2
allows a remote attacker to read the source code to
arbitrary 'jsp' files via a malformed URL request which
does not end with an HTTP protocol specification (i.e.
HTTP/1.0). Status: Entry
Reference: BUGTRAQ:20010403 Re: Tomcat may reveal
script source code by URL trickery
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0031.html
Reference: HP:HPSBTL0112-004
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0112-004
Reference: XF:jakarta-tomcat-jsp-source(6971)
Reference:
URL:http://xforce.iss.net/static/6971.php
Reference: OSVDB:5580
Reference: URL:http://www.osvdb.org/5580
Name: CVE-2001-0591
Description:
Directory traversal vulnerability in Oracle JSP 1.0.x
through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can
allow a remote attacker to read or execute arbitrary
.jsp files via a '..' (dot dot) attack. Status:
Entry
Reference: WIN2KSEC:20010122 Oracle JSP/SQLJS
handlers allow viewing files and executing JSP outside
the web root
Reference: BUGTRAQ:20010212 Patch for Potential
Vulnerability in the execution of JSPs outside doc_root
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0239.html
Reference: BID:2286
Reference:
URL:http://www.securityfocus.com/bid/2286
Reference:
XF:oracle-handlers-directory-traversal(5986)
Reference:
URL:http://xforce.iss.net/static/5986.php
Name: CVE-2001-0593
Description:
Ananconda Partners Clipper 3.3 and earlier allows a
remote attacker to read arbitrary files via a '..' (dot
dot) attack in the template parameter. Status:
Entry
Reference: BUGTRAQ:20010327 advisory
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0395.html
Reference:
MISC:http://anacondapartners.com/cgi-local/apexec.pl?template=ap_releasenotestemplate.html&f1=ap_af_updates_menu&f2=ap_af_releasenotes_clip
Reference: BID:2512
Reference:
URL:http://www.securityfocus.com/bid/2512
Reference:
XF:anaconda-clipper-directory-traversal(6286)
Reference:
URL:http://xforce.iss.net/static/6286.php
Name: CVE-2001-0594
Description:
kcms_configure as included with Solaris 7 and 8 allows a
local attacker to gain additional privileges via a
buffer overflow in a command line argument. Status:
Entry
Reference: BUGTRAQ:20010409 Solaris
kcms_configure vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0140.html
Reference: SUNBUG:4199722
Reference: BID:2558
Reference:
URL:http://www.securityfocus.com/bid/2558
Reference: XF:solaris-kcms-command-bo(6359)
Reference:
URL:http://xforce.iss.net/static/6359.php
Reference: OVAL:oval:org.mitre.oval:def:65
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:65
Reference: OVAL:oval:org.mitre.oval:def:7
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7
Name: CVE-2001-0595
Description:
Buffer overflow in the kcsSUNWIOsolf.so library in
Solaris 7 and 8 allows local attackers to execute
arbitrary commands via the KCMS_PROFILES environment
variable, e.g. as demonstrated using the kcms_configure
program. Status: Entry
Reference: BUGTRAQ:20010411 [LSD] Solaris
kcsSUNWIOsolf.so and dtsession vulnerabilities
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0203.html
Reference: SUNBUG:4415570
Reference: XF:solaris-kcssunwiosolf-bo(6365)
Reference:
URL:http://xforce.iss.net/static/6365.php
Reference: BID:2605
Reference:
URL:http://www.securityfocus.com/bid/2605
Name: CVE-2001-0596
Description:
Netscape Communicator before 4.77 allows remote
attackers to execute arbitrary Javascript via a GIF
image whose comment contains the Javascript. Status:
Entry
Reference: BUGTRAQ:20010409 Netscape 4.76 gif
comment flaw
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98685237415117&w=2
Reference: DEBIAN:DSA-051
Reference:
URL:http://www.debian.org/security/2001/dsa-051
Reference: CONECTIVA:CLA-2001:393
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000393
Reference: REDHAT:RHSA-2001:046
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-046.html
Reference:
XF:netscape-javascript-access-data(6344)
Reference:
URL:http://xforce.iss.net/static/6344.php
Reference: BID:2637
Reference:
URL:http://www.securityfocus.com/bid/2637
Reference: IMMUNIX:IMNX-2001-70-014-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-014-01
Reference: OSVDB:5579
Reference: URL:http://www.osvdb.org/5579
Name: CVE-2001-0611
Description:
Becky! 2.00.05 and earlier can allow a remote attacker
to gain additional privileges via a buffer overflow
attack on long messages without newline characters.
Status: Entry
Reference: BUGTRAQ:20010514 Becky! 2.00.05 Buffer
Overflow
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0089.html
Reference: BID:2723
Reference:
URL:http://www.securityfocus.com/bid/2723
Reference: XF:becky-mail-message-bo(6531)
Reference:
URL:http://xforce.iss.net/static/6531.php
Name: CVE-2001-0612
Description:
McAfee Remote Desktop 3.0 and earlier allows remote
attackers to cause a denial of service (crash) via a
large number of packets to port 5045. Status:
Entry
Reference: BUGTRAQ:20010516 Remote Desktop DoS
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0158.html
Reference: XF:remote-desktop-dos(6547)
Reference:
URL:http://xforce.iss.net/static/6547.php
Reference: BID:2726
Reference:
URL:http://www.securityfocus.com/bid/2726
Reference: OSVDB:6288
Reference: URL:http://www.osvdb.org/6288
Name: CVE-2001-0613
Description:
Omnicron Technologies OmniHTTPD Professional 2.08 and
earlier allows a remote attacker to create a denial of
service via a long POST URL request. Status:
Entry
Reference: BUGTRAQ:20010515 OmniHTTPd Pro Denial
of Service Vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0131.html
Reference: XF:omnihttpd-post-dos(6540)
Reference:
URL:http://xforce.iss.net/static/6540.php
Reference: BID:2730
Reference:
URL:http://www.securityfocus.com/bid/2730
Name: CVE-2001-0615
Description:
Directory traversal vulnerability in Faust Informatics
Freestyle Chat server prior to 4.1 SR3 allows a remote
attacker to read arbitrary files via a specially crafted
URL which includes variations of a '..' (dot dot) attack
such as '...' or '....'. Status: Entry
Reference: BUGTRAQ:20010525 Advisory for
Freestyle Chat server
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0241.html
Reference: BID:2776
Reference:
URL:http://www.securityfocus.com/bid/2776
Reference:
XF:freestyle-chat-directory-traversal(6601)
Reference:
URL:http://xforce.iss.net/static/6601.php
Reference: OSVDB:1841
Reference: URL:http://www.osvdb.org/1841
Name: CVE-2001-0616
Description:
Faust Informatics Freestyle Chat server prior to 4.1 SR3
allows a remote attacker to create a denial of service
via a URL request which includes a MS-DOS device name
(e.g., GET /aux HTTP/1.0). Status: Entry
Reference: BUGTRAQ:20010525 Advisory for
Freestyle Chat server
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0241.html
Reference: BID:2777
Reference:
URL:http://www.securityfocus.com/bid/2777
Reference: XF:freestyle-chat-device-dos(6602)
Reference:
URL:http://xforce.iss.net/static/6602.php
Name: CVE-2001-0621
Description:
The FTP server on Cisco Content Service 11000 series
switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s
allows an attacker who is an FTP user to read and write
arbitrary files via GET or PUT commands. Status:
Entry
Reference: CISCO:20010517 Cisco Content Service
Switch 11000 Series FTP Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/arrowpoint-ftp-pub.shtml
Reference: CIAC:L-085
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-085.shtml
Reference: XF:cisco-css-ftp-commands(6557)
Reference:
URL:http://xforce.iss.net/static/6557.php
Reference: BID:2745
Reference:
URL:http://www.securityfocus.com/bid/2745
Reference: OSVDB:1834
Reference: URL:http://www.osvdb.org/1834
Name: CVE-2001-0622
Description:
The web management service on Cisco Content Service
series 11000 switches (CSS) before WebNS 4.01B29s or
WebNS 4.10B17s allows a remote attacker to gain
additional privileges by directly requesting the web
management URL instead of navigating through the
interface. Status: Entry
Reference: CISCO:20010531 Cisco Content Service
Switch 11000 Series Web Management Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/arrowpoint-webmgmt-vuln-pub.shtml
Reference: XF:cisco-css-web-management(6631)
Reference:
URL:http://xforce.iss.net/static/6631.php
Reference: BID:2806
Reference:
URL:http://www.securityfocus.com/bid/2806
Reference: OSVDB:1848
Reference: URL:http://www.osvdb.org/1848
Name: CVE-2001-0625
Description:
ftpdownload in Computer Associates InoculateIT 6.0
allows a local attacker to overwrite arbitrary files via
a symlink attack on /tmp/ftpdownload.log . Status:
Entry
Reference: BUGTRAQ:20010525 Security Bug in
InoculateIT for Linux (fwd)
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0245.html
Reference:
XF:inoculateit-ftpdownload-symlink(6607)
Reference:
URL:http://xforce.iss.net/static/6607.php
Reference: BID:2778
Reference:
URL:http://www.securityfocus.com/bid/2778
Reference: OSVDB:1843
Reference: URL:http://www.osvdb.org/1843
Name: CVE-2001-0626
Description:
O'Reilly Website Professional 2.5.4 and earlier allows
remote attackers to determine the physical path to the
root directory via a URL request containing a ":"
character. Status: Entry
Reference: BUGTRAQ:20010316 WebServer Pro All
Version Vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0236.html
Reference: BID:2488
Reference:
URL:http://www.securityfocus.com/bid/2488
Reference: XF:website-pro-dir-path(3839)
Reference:
URL:http://xforce.iss.net/static/3839.php
Name: CVE-2001-0627
Description:
vi as included with SCO OpenServer 5.0 - 5.0.6 allows a
local attacker to overwrite arbitrary files via a
symlink attack. Status: Entry
Reference: BUGTRAQ:20010522 [SRT2001-09] - vi and
crontab -e /tmp issues
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0220.html
Reference: CALDERA:CSSA-2001-SCO.17
Reference:
URL:ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.17/CSSA-2001-SCO.17.txt
Reference: CERT-VN:VU#747736
Reference:
URL:http://www.kb.cert.org/vuls/id/747736
Reference: BID:2752
Reference:
URL:http://www.securityfocus.com/bid/2752
Reference: XF:sco-openserver-vi-symlink(6588)
Reference:
URL:http://xforce.iss.net/static/6588.php
Name: CVE-2001-0628
Description:
Microsoft Word 2000 does not check AutoRecovery (.asd)
files for macros, which allows a local attacker to
execute arbitrary macros with the user ID of the Word
user. Status: Entry
Reference: MSKB:Q274228
Reference:
URL:http://support.microsoft.com/support/kb/articles/Q274/2/28.asp
Reference: BID:2760
Reference:
URL:http://www.securityfocus.com/bid/2760
Reference: XF:word-asd-macro-execution(6614)
Reference:
URL:http://xforce.iss.net/static/6614.php
Name: CVE-2001-0629
Description:
HP Event Correlation Service (ecsd) as included with
OpenView Network Node Manager 6.1 allows a remote
attacker to gain addition privileges via a buffer
overflow attack in the '-restore_config' command line
parameter. Status: Entry
Reference: BUGTRAQ:20010523 HP OpenView NNM v6.1
buffer overflow
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0226.html
Reference: HP:HPSBUX0107-158
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0107-158
Reference: BID:2761
Reference:
URL:http://www.securityfocus.com/bid/2761
Reference: XF:openview-nnm-ecsd-bo(6582)
Reference:
URL:http://xforce.iss.net/static/6582.php
Name: CVE-2001-0630
Description:
Directory traversal vulnerability in MIMAnet viewsrc.cgi
2.0 allows a remote attacker to read arbitrary files via
a '..' (dot dot) attack in the 'loc' variable.
Status: Entry
Reference: BUGTRAQ:20010523 Vulnerability in
viewsrc.cgi
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0231.html
Reference: BID:2762
Reference:
URL:http://www.securityfocus.com/bid/2762
Reference: XF:viewsrc-cgi-view-files(6583)
Reference:
URL:http://xforce.iss.net/static/6583.php
Reference: OSVDB:5565
Reference: URL:http://www.osvdb.org/5565
Name: CVE-2001-0631
Description:
Centrinity First Class Internet Services 5.50 allows for
the circumventing of the default 'spam' filters via the
presence of '<@>' in the 'From:' field, which allows
remote attackers to send spoofed email with the identity
of local users. Status: Entry
Reference: BUGTRAQ:20010221 FirstClass
Internetgateway "stupidity"
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0376.html
Reference: BUGTRAQ:20010226 Re: [Fwd: FirstClass
Internetgateway "stupidity"]
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0440.html
Reference:
XF:centrinity-firstclass-email-spoofing(6192)
Reference:
URL:http://xforce.iss.net/static/6192.php
Reference: BID:2423
Reference:
URL:http://www.securityfocus.com/bid/2423
Name: CVE-2001-0634
Description:
Sun Chili!Soft ASP has weak permissions on various
configuration files, which allows a local attacker to
gain additional privileges and create a denial of
service. Status: Entry
Reference: BUGTRAQ:20010220 Advisory: Chili!Soft
ASP Multiple Vulnerabilities
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0378.html
Reference: BUGTRAQ:20010226 Re: Advisory:
Chili!Soft ASP Multiple Vulnerabilities
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0443.html
Reference: XF:chilisoft-asp-license-dos(6176)
Reference:
URL:http://xforce.iss.net/static/6176.php
Reference: BID:2409
Reference:
URL:http://www.securityfocus.com/bid/2409
Name: CVE-2001-0635
Description:
Red Hat Linux 7.1 sets insecure permissions on swap
files created during installation, which can allow a
local attacker to gain additional privileges by reading
sensitive information from the swap file, such as
passwords. Status: Entry
Reference: REDHAT:RHSA-2001:058
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-058.html
Reference: XF:mount-swap-world-readable(6493)
Reference:
URL:http://xforce.iss.net/static/6493.php
Reference: OSVDB:5564
Reference: URL:http://www.osvdb.org/5564
Name: CVE-2001-0641
Description:
Buffer overflow in man program in various distributions
of Linux allows local user to execute arbitrary code as
group man via a long -S option. Status: Entry
Reference: BUGTRAQ:20010513 RH 7.0:/usr/bin/man
exploit: gid man + more
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0087.html
Reference: BUGTRAQ:20010612 man 1.5h10 + man
1.5i-4 exploits
Reference:
URL:http://www.securityfocus.com/archive/1/190136
Reference: REDHAT:RHSA-2001:069
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-069.html
Reference: SUSE:SuSE-SA:2001:019
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_019_man_txt.html
Reference: XF:man-s-bo(6530)
Reference:
URL:http://xforce.iss.net/static/6530.php
Reference: BID:2711
Reference:
URL:http://www.securityfocus.com/bid/2711
Name: CVE-2001-0643
Description:
Internet Explorer 5.5 does not display the Class ID
(CLSID) when it is at the end of the file name, which
could allow attackers to trick the user into executing
dangerous programs by making it appear that the document
is of a safe file type. Status: Entry
Reference: BUGTRAQ:20010416 Double clicking on
innocent looking files may be dangerous
Reference:
URL:http://www.securityfocus.com/archive/1/176909
Reference:
MISC:http://www.guninski.com/clsidext.html
Reference:
MISC:http://vil.nai.com/vil/virusSummary.asp?virus_k=99048
Reference:
MISC:http://www.sarc.com/avcenter/venc/data/vbs.postcard@mm.html
Reference: BID:2612
Reference:
URL:http://www.securityfocus.com/bid/2612
Reference: OSVDB:7858
Reference: URL:http://www.osvdb.org/7858
Reference: XF:ie-clsid-execute-files(6426)
Reference:
URL:http://xforce.iss.net/static/6426.php
Name: CVE-2001-0644
Description:
Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 stores
passwords in plaintext in the "Rumpus User Database"
file in the prefs folder, which could allow attackers to
gain privileges on the server. Status: Entry
Reference: BUGTRAQ:20010515 Rumpus FTP DoS
Reference:
URL:http://www.securityfocus.com/archive/1/184751
Reference: BID:2718
Reference:
URL:http://www.securityfocus.com/bid/2718
Reference: XF:rumpus-plaintext-passwords(6543)
Reference:
URL:http://xforce.iss.net/static/6543.php
Name: CVE-2001-0646
Description:
Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a
remote attacker to perform a denial of service (hang) by
creating a directory name of a specific length.
Status: Entry
Reference: BUGTRAQ:20010515 Rumpus FTP DoS
Reference:
URL:http://www.securityfocus.com/archive/1/184751
Reference: BID:2716
Reference:
URL:http://www.securityfocus.com/bid/2716
Reference: XF:rumpus-long-directory-dos(6542)
Reference:
URL:http://xforce.iss.net/static/6542.php
Name: CVE-2001-0648
Description:
Directory traversal vulnerability in PHProjekt 2.1 and
earlier allows a remote attacker to conduct unauthorized
activities via a dot dot (..) attack on the file module.
Status: Entry
Reference: BUGTRAQ:20010508 security hole in os
groupware suite PHProjekt
Reference:
URL:http://www.securityfocus.com/archive/1/184215
Reference: BID:2702
Reference:
URL:http://www.securityfocus.com/bid/2702
Reference:
XF:phprojekt-dot-directory-traversal(6522)
Reference:
URL:http://xforce.iss.net/static/6522.php
Name: CVE-2001-0650
Description:
Cisco devices IOS 12.0 and earlier allow a remote
attacker to cause a crash, or bad route updates, via
malformed BGP updates with unrecognized transitive
attribute. Status: Entry
Reference: CISCO:20010510 Cisco IOS BGP Attribute
Corruption Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/ios-bgp-attr-corruption-pub.shtml
Reference: CERT-VN:VU#106392
Reference:
URL:http://www.kb.cert.org/vuls/id/106392
Reference: CIAC:L-082
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/l-082.shtml
Reference: XF:cisco-ios-bgp-dos(6566)
Reference:
URL:http://xforce.iss.net/static/6566.php
Reference: BID:2733
Reference:
URL:http://www.securityfocus.com/bid/2733
Reference: OSVDB:1830
Reference: URL:http://www.osvdb.org/1830
Name: CVE-2001-0652
Description:
Heap overflow in xlock in Solaris 2.6 through 8 allows
local users to gain root privileges via a long (1)
XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental
variable. Status: Entry
Reference: BUGTRAQ:20010810 NSFOCUS SA2001-05 :
Solaris Xlock Heap Overflow Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99745571104126&w=2
Reference: SUNBUG:4483090
Reference: XF:solaris-xlock-bo(6967)
Reference:
URL:http://xforce.iss.net/static/6967.php
Reference: BID:3160
Reference:
URL:http://www.securityfocus.com/bid/3160
Reference: OVAL:oval:org.mitre.oval:def:10
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10
Reference: OVAL:oval:org.mitre.oval:def:131
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:131
Name: CVE-2001-0653
Description:
Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows
local users to modify process memory and possibly gain
privileges via a large value in the 'category' part of
debugger (-d) command line arguments, which is
interpreted as a negative number. Status: Entry
Reference: BUGTRAQ:20010821 *ALERT* UPDATED BID
3163 (URGENCY 6.58): Sendmail Debugger Arbitrary Code
Execution Vulnerability (fwd)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99841063100516&w=2
Reference:
CONFIRM:http://www.sendmail.org/8.11.html
Reference: CALDERA:CSSA-2001-032.0
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-032.0.txt
Reference: CALDERA:CSSA-2001-SCO.31
Reference: CONECTIVA:CLA-2001:412
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000412
Reference: HP:HPSBTL0112-007
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0112-007
Reference: IMMUNIX:IMNX-2001-70-032-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-032-01
Reference: MANDRAKE:MDKSA-2001:075
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-075.php3
Reference: NETBSD:NetBSD-SA2001-017
Reference:
URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-017.txt.asc
Reference: REDHAT:RHSA-2001:106
Reference:
URL:http://rhn.redhat.com/errata/RHSA-2001-106.html
Reference: SUSE:SuSE-SA:2001:028
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_028_sendmail_txt.html
Reference: CIAC:L-133
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-133.shtml
Reference: BID:3163
Reference:
URL:http://www.securityfocus.com/bid/3163
Reference:
XF:sendmail-debug-signed-int-overflow(7016)
Reference:
URL:http://xforce.iss.net/static/7016.php
Name: CVE-2001-0658
Description:
Cross-site scripting (CSS) vulnerability in Microsoft
Internet Security and Acceleration (ISA) Server 2000
allows remote attackers to cause other clients to
execute certain script or read cookies via malicious
script in an invalid URL that is not properly quoted in
an error message. Status: Entry
Reference: MS:MS01-045
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-045.asp
Reference: XF:isa-cross-site-scripting(6991)
Reference:
URL:http://xforce.iss.net/static/6991.php
Reference: BID:3198
Reference:
URL:http://www.securityfocus.com/bid/3198
Name: CVE-2001-0659
Description:
Buffer overflow in IrDA driver providing infrared data
exchange on Windows 2000 allows attackers who are
physically close to the machine to cause a denial of
service (reboot) via a malformed IrDA packet. Status:
Entry
Reference: BUGTRAQ:20010821 IrDA semiremote
vulnerability
Reference:
URL:http://online.securityfocus.com/archive/1/209385
Reference: MS:MS01-046
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-046.asp
Reference: XF:win2k-irda-dos(7008)
Reference:
URL:http://xforce.iss.net/static/7008.php
Reference: BID:3215
Reference:
URL:http://www.securityfocus.com/bid/3215
Name: CVE-2001-0660
Description:
Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4
and earlier, allows remote attackers to identify valid
user email addresses by directly accessing a back-end
function that processes the global address list (GAL).
Status: Entry
Reference: MS:MS01-047
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-047.asp
Reference: MSKB:Q307195
Reference:
URL:http://support.microsoft.com/support/kb/articles/Q307/1/95.ASP
Reference: XF:exchange-owa-obtain-addresses(7089)
Reference:
URL:http://xforce.iss.net/static/7089.php
Reference: BID:3301
Reference:
URL:http://www.securityfocus.com/bid/3301
Name: CVE-2001-0662
Description:
RPC endpoint mapper in Windows NT 4.0 allows remote
attackers to cause a denial of service (loss of RPC
services) via a malformed request. Status: Entry
Reference: MS:MS01-048
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-048.asp
Reference: XF:winnt-rpc-endpoint-dos(7105)
Reference:
URL:http://xforce.iss.net/static/7105.php
Reference: CIAC:L-142
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-142.shtml
Reference: BID:3313
Reference:
URL:http://www.securityfocus.com/bid/3313
Name: CVE-2001-0663
Description:
Terminal Server in Windows NT and Windows 2000 allows
remote attackers to cause a denial of service via a
sequence of invalid Remote Desktop Protocol (RDP)
packets. Status: Entry
Reference: MS:MS01-052
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-052.asp
Reference: XF:win-rdp-packet-dos(7302)
Reference:
URL:http://xforce.iss.net/static/7302.php
Reference: BID:3445
Reference:
URL:http://www.securityfocus.com/bid/3445
Name: CVE-2001-0664
Description:
Internet Explorer 5.5 and 5.01 allows remote attackers
to bypass security restrictions via malformed URLs that
contain dotless IP addresses, which causes Internet
Explorer to process the page in the Intranet Zone, which
may have fewer security restrictions, aka the "Zone
Spoofing vulnerability." Status: Entry
Reference: BUGTRAQ:20011011 Serious security Flaw
in Microsoft Internet Explorer - Zone Spoofing
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100281551611595&w=2
Reference: MS:MS01-051
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-051.asp
Reference: MISC:http://morph3us.org/blog/?p=31
Reference: BID:3420
Reference:
URL:http://www.securityfocus.com/bid/3420
Reference: OSVDB:1971
Reference: URL:http://www.osvdb.org/1971
Reference: XF:ie-incorrect-security-zone(7258)
Reference:
URL:http://xforce.iss.net/static/7258.php
Name: CVE-2001-0665
Description:
Internet Explorer 6 and earlier allows remote attackers
to cause certain HTTP requests to be automatically
executed and appear to come from the user, which could
allow attackers to gain privileges or execute operations
within web-based services, aka the "HTTP Request
Encoding vulnerability." Status: Entry
Reference: MS:MS01-051
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-051.asp
Reference: XF:ie-url-http-requests(7259)
Reference:
URL:http://xforce.iss.net/static/7259.php
Reference: BID:3421
Reference:
URL:http://www.securityfocus.com/bid/3421
Reference: OSVDB:1972
Reference: URL:http://www.osvdb.org/1972
Name: CVE-2001-0666
Description:
Outlook Web Access (OWA) in Microsoft Exchange 2000
allows an authenticated user to cause a denial of
service (CPU consumption) via a malformed OWA request
for a deeply nested folder within the user's mailbox.
Status: Entry
Reference: MS:MS01-049
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-049.asp
Reference:
XF:exchange-owa-folder-request-dos(7168)
Reference:
URL:http://xforce.iss.net/static/7168.php
Reference: BID:3368
Reference:
URL:http://www.securityfocus.com/bid/3368
Name: CVE-2001-0667
Description:
Internet Explorer 6 and earlier, when used with the
Telnet client in Services for Unix (SFU) 2.0, allows
remote attackers to execute commands by spawning Telnet
with a log file option on the command line and writing
arbitrary code into an executable file which is later
executed, aka a new variant of the Telnet Invocation
vulnerability as described in CVE-2001-0150. Status:
Entry
Reference: MS:MS01-051
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-051.asp
Reference: CIAC:M-024
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-024.shtml
Reference: CERT-VN:VU#952611
Reference:
URL:http://www.kb.cert.org/vuls/id/952611
Reference:
XF:ie-telnet-command-execution-variant(7260)
Reference:
URL:http://xforce.iss.net/static/7260.php
Name: CVE-2001-0668
Description:
Buffer overflow in line printer daemon (rlpdaemon) in
HP-UX 10.01 through 11.11 allows remote attackers to
execute arbitrary commands. Status: Entry
Reference: ISS:20010827 Remote Buffer Overflow
Vulnerability in HP-UX Line Printer Daemon
Reference:
URL:http://xforce.iss.net/alerts/advise93.php
Reference: HP:HPSBUX0108-163
Reference:
URL:http://archives.neohapsis.com/archives/hp/2001-q3/0047.html
Reference: CIAC:L-134
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-134.shtml
Reference: CERT-VN:VU#966075
Reference:
URL:http://www.kb.cert.org/vuls/id/966075
Reference: CERT:CA-2001-30
Reference:
URL:http://www.cert.org/advisories/CA-2001-30.html
Reference: XF:hpux-rlpd-bo(6811)
Reference:
URL:http://xforce.iss.net/static/6811.php
Reference: BID:3240
Reference:
URL:http://www.securityfocus.com/bid/3240
Name: CVE-2001-0670
Description:
Buffer overflow in BSD line printer daemon (in.lpd or
lpd) in various BSD-based operating systems allows
remote attackers to execute arbitrary code via an
incomplete print job followed by a request to display
the printer queue. Status: Entry
Reference: ISS:20010829 Remote Buffer Overflow
Vulnerability in BSD Line Printer Daemon
Reference:
URL:http://xforce.iss.net/alerts/advise94.php
Reference: CERT:CA-2001-30
Reference:
URL:http://www.cert.org/advisories/CA-2001-30.html
Reference: OPENBSD:20010829
Reference:
URL:http://www.openbsd.com/errata28.html
Reference: CALDERA:CSSA-2001-SCO.20
Reference:
URL:ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.20/CSSA-2001-SCO.20.txt
Reference: NETBSD:NetBSD-SA2001-018
Reference:
URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-018.txt.asc
Reference: REDHAT:RHSA-2001:147
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-147.html
Reference: CERT-VN:VU#274043
Reference:
URL:http://www.kb.cert.org/vuls/id/274043
Reference: XF:bsd-lpd-bo(7046)
Reference:
URL:http://xforce.iss.net/static/7046.php
Reference: BID:3252
Reference:
URL:http://www.securityfocus.com/bid/3252
Name: CVE-2001-0675
Description:
Rit Research Labs The Bat! 1.51 for Windows allows a
remote attacker to cause a denial of service by sending
an email to a user's account containing a carrage return
<CR> that is not followed by a line feed <LF>.
Status: Entry
Reference: BUGTRAQ:20010418 SECURITY.NNOV: The
Bat! <cr> bug
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0345.html
Reference: BUGTRAQ:20010421 Re: SECURITY.NNOV:
The Bat! <cr> bug
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0381.html
Reference: BUGTRAQ:20010423 Re: SECURITY.NNOV:
The Bat! <cr> bug
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0410.html
Reference: XF:thebat-pop3-dos(6423)
Reference:
URL:http://xforce.iss.net/static/6423.php
Reference: BID:2636
Reference:
URL:http://www.securityfocus.com/bid/2636
Name: CVE-2001-0676
Description:
Directory traversal vulnerability in Rit Research Labs
The Bat! 1.48f and earlier allows a remote attacker to
create arbitrary files via a "dot dot" attack in the
filename for an attachment. Status: Entry
Reference: BUGTRAQ:20010104 SECURITY.NNOV
advisory - The Bat! directory traversal (public release)
Reference:
URL:http://www.securityfocus.com/archive/1/154359
Reference:
XF:thebat-attachment-directory-traversal(5871)
Reference:
URL:http://xforce.iss.net/static/5871.php
Name: CVE-2001-0677
Description:
Eudora 5.0.2 allows a remote attacker to read arbitrary
files via an email with the path of the target file in
the "Attachment Converted" MIME header, which sends the
file when the email is forwarded to the attacker by the
user. Status: Entry
Reference: BUGTRAQ:20010418 Eudora file leakage
problem (still)
Reference:
URL:http://www.securityfocus.com/archive/1/177369
Reference: XF:eudora-plain-text-attachment(6431)
Reference:
URL:http://xforce.iss.net/static/6431.php
Reference: BID:2616
Reference:
URL:http://www.securityfocus.com/bid/2616
Reference: OSVDB:3085
Reference: URL:http://www.osvdb.org/3085
Name: CVE-2001-0680
Description:
Directory traversal vulnerability in ftpd in QPC QVT/Net
4.0 and AVT/Term 5.0 allows a remote attacker to
traverse directories on the web server via a "dot dot"
attack in a LIST (ls) command. Status: Entry
Reference: BUGTRAQ:20010413 QPC FTPd Directory
Traversal and BoF Vulnerabilities
Reference:
URL:http://www.securityfocus.com/archive/1/176712
Reference: BUGTRAQ:20010925 Vulnerabilities in
QVT/Term
Reference:
URL:http://online.securityfocus.com/archive/1/216555
Reference: XF:qpc-ftpd-directory-traversal(6375)
Reference:
URL:http://xforce.iss.net/static/6375.php
Reference: BID:2618
Reference:
URL:http://www.securityfocus.com/bid/2618
Reference: OSVDB:1794
Reference: URL:http://www.osvdb.org/1794
Reference: OSVDB:4050
Reference: URL:http://www.osvdb.org/4050
Name: CVE-2001-0682
Description:
ZoneAlarm and ZoneAlarm Pro allows a local attacker to
cause a denial of service by running a trojan to
initialize a ZoneAlarm mutex object which prevents
ZoneAlarm from starting. Status: Entry
Reference: NTBUGTRAQ:20001230 [DiamondCS
Advisory] ZoneAlarm and ZoneAlarm Pro can be blocked
from loading by setting a Mutex in memory
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=97818917222992&w=2
Reference: XF:zonealarm-mutex-dos(5821)
Reference:
URL:http://xforce.iss.net/static/5821.php
Name: CVE-2001-0685
Description:
Thibault Godouet FCron prior to 1.1.1 allows a local
user to corrupt another user's crontab file via a
symlink attack on the fcrontab temporary file.
Status: Entry
Reference: BUGTRAQ:20010228 fcron 0.9.5 is
vulnerable to a symlink attack
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98339581702282&w=2
Reference:
CONFIRM:http://fcron.free.fr/CHANGES.html
Reference: BID:2835
Reference:
URL:http://www.securityfocus.com/bid/2835
Reference: XF:fcron-tmpfile-symlink(7127)
Reference:
URL:http://xforce.iss.net/static/7127.php
Name: CVE-2001-0686
Description:
Buffer overflow in mail included with SunOS 5.8 for x86
allows a local user to gain privileges via a long HOME
environment variable. Status: Entry
Reference: BUGTRAQ:20010604 $HOME buffer overflow
in SunOS 5.8 x86
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0000.html
Reference: SUNBUG:4465086
Reference: BID:2819
Reference:
URL:http://www.securityfocus.com/bid/2819
Reference: XF:solaris-mail-home-bo(6638)
Reference:
URL:http://xforce.iss.net/static/6638.php
Name: CVE-2001-0690
Description:
Format string vulnerability in exim (3.22-10 in Red Hat,
3.12 in Debian and 3.16 in Conectiva) in batched SMTP
mode allows a remote attacker to execute arbitrary code
via format strings in SMTP mail headers. Status:
Entry
Reference: BUGTRAQ:20010606 lil' exim format bug
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0041.html
Reference: DEBIAN:DSA-058
Reference:
URL:http://www.debian.org/security/2001/dsa-058
Reference: CONECTIVA:CLA-2001:402
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000402
Reference: REDHAT:RHSA-2001:078
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-078.html
Reference: XF:exim-syntax-format-string(6671)
Reference:
URL:http://xforce.iss.net/static/6671.php
Reference: BID:2828
Reference:
URL:http://www.securityfocus.com/bid/2828
Name: CVE-2001-0692
Description:
SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and
4.6 allows a remote attacker to bypass firewall
filtering via a base64 MIME encoded email attachment
whose boundary name ends in two dashes. Status:
Entry
Reference: BUGTRAQ:20010608 WatchGuard SMTP Proxy
issue
Reference:
URL:http://www.securityfocus.com/archive/1/189783
Reference: BUGTRAQ:20010628 RE: WatchGuard SMTP
Proxy issue
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99379787421319&w=2
Reference: XF:firebox-smtp-bypass-filter(6682)
Reference:
URL:http://xforce.iss.net/static/6682.php
Reference: BID:2855
Reference:
URL:http://www.securityfocus.com/bid/2855
Name: CVE-2001-0696
Description:
NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker
to cause a denial of service (crash) via a CD command to
a directory with an MS-DOS device name such as con.
Status: Entry
Reference: BUGTRAQ:20010619 SurgeFTP
vulnerabilities
Reference:
URL:http://www.securityfocus.com/archive/1/191916
Reference:
MISC:http://netwinsite.com/surgeftp/manual/updates.htm
Reference: BID:2891
Reference:
URL:http://www.securityfocus.com/bid/2891
Reference: XF:surgeftp-concon-dos(6712)
Reference:
URL:http://xforce.iss.net/static/6712.php
Name: CVE-2001-0697
Description:
NetWin SurgeFTP prior to 1.1h allows a remote attacker
to cause a denial of service (crash) via an 'ls ..'
command. Status: Entry
Reference: BUGTRAQ:20010228 SurgeFTP Denial of
Service
Reference:
URL:http://www.securityfocus.com/archive/1/165816
Reference: WIN2KSEC:20010301 SurgeFTP 1.0b Denial
of Service
Reference:
URL:http://www.secadministrator.com/Articles/Index.cfm?ArticleID=20200
Reference:
CONFIRM:http://netwinsite.com/surgeftp/manual/updates.htm
Reference: XF:surgeftp-listing-dos(6168)
Reference:
URL:http://xforce.iss.net/static/6168.php
Reference: BID:2442
Reference:
URL:http://www.securityfocus.com/bid/2442
Name: CVE-2001-0698
Description:
Directory traversal vulnerability in NetWin SurgeFTP
2.0a and 1.0b allows a remote attacker to list arbitrary
files and directories via the 'nlist ...' command.
Status: Entry
Reference: BUGTRAQ:20010619 SurgeFTP
vulnerabilities
Reference:
URL:http://www.securityfocus.com/archive/1/191916
Reference:
CONFIRM:http://www.netwinsite.com/surgeftp/manual/updates.htm
Reference: BID:2892
Reference:
URL:http://www.securityfocus.com/bid/2892
Reference:
XF:surgeftp-nlist-directory-traversal(6711)
Reference:
URL:http://xforce.iss.net/static/6711.php
Name: CVE-2001-0699
Description:
Buffer overflow in cb_reset in the System Service
Processor (SSP) package of SunOS 5.8 allows a local user
to execute arbitrary code via a long argument.
Status: Entry
Reference: BUGTRAQ:20010620 Solaris
/opt/SUNWssp/bin/cb_reset Vulnerability
Reference:
URL:http://www.securityfocus.com/archive/1/192299
Reference: SUNBUG:4469366
Reference: BID:2893
Reference:
URL:http://www.securityfocus.com/bid/2893
Reference: XF:sun-cbreset-bo(6726)
Reference:
URL:http://xforce.iss.net/static/6726.php
Name: CVE-2001-0700
Description:
Buffer overflow in w3m 0.2.1 and earlier allows a remote
attacker to execute arbitrary code via a long base64
encoded MIME header. Status: Entry
Reference: BUGTRAQ:20010621 [SNS Advisory No.32]
w3m malformed MIME header Buffer Overflow Vulnerability
Reference:
URL:http://www.securityfocus.com/archive/1/192371
Reference:
CONFIRM:http://mi.med.tohoku.ac.jp/~satodai/w3m-dev-en/200106.month/537.html
Reference: CONECTIVA:CLA-2001:434
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000434
Reference: DEBIAN:DSA-064
Reference:
URL:http://www.debian.org/security/2001/dsa-064
Reference: DEBIAN:DSA-081
Reference:
URL:http://www.debian.org/security/2001/dsa-081
Reference: XF:w3m-mime-header-bo(6725)
Reference:
URL:http://xforce.iss.net/static/6725.php
Reference: BID:2895
Reference:
URL:http://www.securityfocus.com/bid/2895
Name: CVE-2001-0701
Description:
Buffer overflow in ptexec in the Sun Validation Test
Suite 4.3 and earlier allows a local user to gain
privileges via a long -o argument. Status: Entry
Reference: BUGTRAQ:20010621 Solaris
/opt/SUNWvts/bin/ptexec Vulnerability
Reference:
URL:http://www.securityfocus.com/archive/1/192667
Reference: SUNBUG:4469370
Reference: BID:2898
Reference:
URL:http://www.securityfocus.com/bid/2898
Reference: XF:sunvts-ptexec-bo(6736)
Reference:
URL:http://xforce.iss.net/static/6736.php
Name: CVE-2001-0706
Description:
Maximum Rumpus FTP Server 2.0.3 dev and before allows an
attacker to cause a denial of service (crash) via a
mkdir command that specifies a large number of
sub-folders. Status: Entry
Reference: BUGTRAQ:20010612 Rumpus FTP DoS vol. 2
Reference:
URL:http://www.securityfocus.com/archive/1/190932
Reference: XF:rumpus-ftp-directory-dos(6699)
Reference:
URL:http://xforce.iss.net/static/6699.php
Reference: BID:2864
Reference:
URL:http://www.securityfocus.com/bid/2864
Name: CVE-2001-0710
Description:
NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier
allows a remote attacker to cause a denial of service by
sending a large number of IP fragments to the machine,
exhausting the mbuf pool. Status: Entry
Reference: FREEBSD:FreeBSD-SA-01:52
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:52.fragment.asc
Reference: NETBSD:NetBSD-SA2001-006
Reference:
URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-006.txt.asc
Reference: XF:bsd-ip-fragments-dos(6636)
Reference:
URL:http://xforce.iss.net/static/6636.php
Reference: BID:2799
Reference:
URL:http://www.securityfocus.com/bid/2799
Name: CVE-2001-0716
Description:
Citrix MetaFrame 1.8 Server with Service Pack 3, and XP
Server Service Pack 1 and earlier, allows remote
attackers to cause a denial of service (crash) via a
large number of incomplete connections to the server.
Status: Entry
Reference: ISS:20011016 Citrix MetaFrame Remote
Denial of Service Vulnerability
Reference:
URL:http://xforce.iss.net/alerts/advise99.php
Reference:
XF:metaframe-multiple-sessions-dos(7068)
Reference:
URL:http://xforce.iss.net/static/7068.php
Reference: BID:3440
Reference:
URL:http://www.securityfocus.com/bid/3440
Name: CVE-2001-0717
Description:
Format string vulnerability in ToolTalk database server
rpc.ttdbserverd allows remote attackers to execute
arbitrary commands via format string specifiers that are
passed to the syslog function. Status: Entry
Reference: ISS:20011002 Multi-Vendor Format
String Vulnerability in ToolTalk Service
Reference:
URL:http://xforce.iss.net/alerts/advise98.php
Reference: CERT:CA-2001-27
Reference:
URL:http://www.cert.org/advisories/CA-2001-27.html
Reference: CIAC:M-002
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-002.shtml
Reference: CALDERA:CSSA-2001-SCO.28
Reference:
URL:ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.28/CSSA-2001-SCO.28.txt
Reference: COMPAQ:SSRT0767U
Reference:
URL:http://ftp.support.compaq.com/patches/.new/html/SSRT0767U.shtml
Reference: HP:HPSBUX0110-168
Reference:
URL:http://online.securityfocus.com/advisories/3584
Reference: SUN:00212
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/212
Reference: BID:3382
Reference:
URL:http://www.securityfocus.com/bid/3382
Reference: SECTRACK:1002479
Reference:
URL:http://securitytracker.com/id?1002479
Reference:
XF:tooltalk-ttdbserverd-format-string(7069)
Reference:
URL:http://xforce.iss.net/static/7069.php
Name: CVE-2001-0718
Description:
Vulnerability in (1) Microsoft Excel 2002 and earlier
and (2) Microsoft PowerPoint 2002 and earlier allows
attackers to bypass macro restrictions and execute
arbitrary commands by modifying the data stream in the
document. Status: Entry
Reference: BUGTRAQ:20011005 Symantec Security
Response SecBul-10042001, Revision1, Malformed Microsoft
Excel or PowerPoint documents bypass Microsoft macro
security features
Reference:
URL:http://online.securityfocus.com/archive/1/218802
Reference: MS:MS01-050
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-050.asp
Reference: CERT:CA-2001-28
Reference:
URL:http://www.cert.org/advisories/CA-2001-28.html
Reference: CERT-VN:VU#287067
Reference:
URL:http://www.kb.cert.org/vuls/id/287067
Reference: BID:3402
Reference:
URL:http://www.securityfocus.com/bid/3402
Reference: XF:ms-malformed-document-macro(7223)
Reference:
URL:http://xforce.iss.net/static/7223.php
Name: CVE-2001-0719
Description:
Buffer overflow in Microsoft Windows Media Player 6.4
allows remote attackers to execute arbitrary code via a
malformed Advanced Streaming Format (ASF) file.
Status: Entry
Reference: BUGTRAQ:20010807 MS Windows Media
Player ASF Marker Buffer Overflow
Reference:
URL:http://online.securityfocus.com/archive/1/202470
Reference: MS:MS01-056
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-056.asp
Reference: XF:mediaplayer-asf-marker-bo(6962)
Reference:
URL:http://www.iss.net/security_center/static/6962.php
Reference: BID:3156
Reference:
URL:http://www.securityfocus.com/bid/3156
Reference: OSVDB:5558
Reference: URL:http://www.osvdb.org/5558
Reference: OVAL:oval:org.mitre.oval:def:287
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:287
Name: CVE-2001-0720
Description:
Internet Explorer 5.1 for Macintosh on Mac OS X allows
remote attackers to execute arbitrary commands by
causing a BinHex or MacBinary file type to be
downloaded, which causes the files to be executed if
automatic decoding is enabled. Status: Entry
Reference: MS:MS01-053
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-053.asp
Reference: CIAC:M-013
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-013.shtml
Reference:
XF:ie-mac-downloaded-file-execution(7336)
Reference:
URL:http://xforce.iss.net/static/7336.php
Reference: BID:3471
Reference:
URL:http://www.securityfocus.com/bid/3471
Name: CVE-2001-0722
Description:
Internet Explorer 5.5 and 6.0 allows remote attackers to
read and modify user cookies via Javascript in an about:
URL, aka the "First Cookie Handling Vulnerability."
Status: Entry
Reference: BUGTRAQ:20011108 Microsoft IE cookies
readable via about: URLS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100527618108521&w=2
Reference: BUGTRAQ:20011019 Minor IE
vulnerability: about: URLs
Reference:
URL:http://www.securityfocus.com/archive/1/221612
Reference: MS:MS01-055
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-055.asp
Reference: CIAC:M-016
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-016.shtml
Reference: BID:3513
Reference:
URL:http://www.securityfocus.com/bid/3513
Reference: OSVDB:1982
Reference: URL:http://www.osvdb.org/1982
Reference: XF:ie-about-cookie-information(7486)
Reference:
URL:http://xforce.iss.net/static/7486.php
Name: CVE-2001-0723
Description:
Internet Explorer 5.5 and 6.0 allows remote attackers to
read and modify user cookies via Javascript, aka the
"Second Cookie Handling Vulnerability." Status:
Entry
Reference: MS:MS01-055
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-055.asp
Reference: BID:3546
Reference:
URL:http://www.securityfocus.com/bid/3546
Name: CVE-2001-0724
Description:
Internet Explorer 5.5 allows remote attackers to bypass
security restrictions via malformed URLs that contain
dotless IP addresses, which causes Internet Explorer to
process the page in the Intranet Zone, which may have
fewer security restrictions, aka the "Zone Spoofing
Vulnerability variant" of CVE-2001-0664. Status:
Entry
Reference: MS:MS01-055
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-055.asp
Reference: OSVDB:5556
Reference: URL:http://www.osvdb.org/5556
Reference:
XF:ie-incorrect-security-zone-variant(8471)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/8471
Name: CVE-2001-0726
Description:
Outlook Web Access (OWA) in Microsoft Exchange 5.5
Server, when used with Internet Explorer, does not
properly detect certain inline script, which can allow
remote attackers to perform arbitrary actions on a
user's Exchange mailbox via an HTML e-mail message.
Status: Entry
Reference: MS:MS01-057
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-057.asp
Reference:
XF:exchange-owa-embedded-script-execution(7663)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7663
Reference: BID:3650
Reference:
URL:http://www.securityfocus.com/bid/3650
Reference: OSVDB:5557
Reference: URL:http://www.osvdb.org/5557
Name: CVE-2001-0727
Description:
Internet Explorer 6.0 allows remote attackers to execute
arbitrary code by modifying the Content-Disposition and
Content-Type header fields in a way that causes Internet
Explorer to believe that the file is safe to open
without prompting the user, aka the "File Execution
Vulnerability." Status: Entry
Reference: BUGTRAQ:20011214 MSIE may download and
run progams automatically
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100835204509262&w=2
Reference: BUGTRAQ:20011216 Re: MSIE may download
and run progams automatically - NOT SO FAST
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100861273114437&w=2
Reference: MS:MS01-058
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-058.asp
Reference: CERT:CA-2001-36
Reference:
URL:http://www.cert.org/advisories/CA-2001-36.html
Reference: CERT-VN:VU#443699
Reference:
URL:http://www.kb.cert.org/vuls/id/443699
Reference: CIAC:M-027
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-027.shtml
Reference: BID:3578
Reference:
URL:http://www.securityfocus.com/bid/3578
Reference: OSVDB:3033
Reference: URL:http://www.osvdb.org/3033
Reference: OVAL:oval:org.mitre.oval:def:921
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:921
Reference: XF:ie-file-download-execution(7703)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7703
Name: CVE-2001-0728
Description:
Buffer overflow in Compaq Management Agents before 5.2,
included in Compaq Web-enabled Management Software,
allows local users to gain privileges. Status:
Entry
Reference: COMPAQ:SSRT0758
Reference:
URL:http://www.compaq.com/products/servers/management/mgtsw-advisory2.html
Reference: CERT-VN:VU#275979
Reference:
URL:http://www.kb.cert.org/vuls/id/275979
Reference: XF:compaq-wbm-bo(7189)
Reference:
URL:http://xforce.iss.net/static/7189.php
Reference: BID:3376
Reference:
URL:http://www.securityfocus.com/bid/3376
Name: CVE-2001-0730
Description:
split-logfile in Apache 1.3.20 allows remote attackers
to overwrite arbitrary files that end in the .log
extension via an HTTP request with a / (slash) in the
Host: header. Status: Entry
Reference:
CONFIRM:http://www.apacheweek.com/issues/01-09-28#security
Reference: MANDRAKE:MDKSA-2001:077
Reference:
URL:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:077
Reference: CONECTIVA:CLA-2001:430
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000430
Reference: ENGARDE:ESA-20011019-01
Reference:
URL:http://www.linuxsecurity.com/advisories/other_advisory-1649.html
Reference: REDHAT:RHSA-2001:126
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-126.html
Reference: REDHAT:RHSA-2001:164
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-164.html
Reference: XF:apache-log-file-overwrite(7419)
Reference:
URL:http://xforce.iss.net/static/7419.php
Name: CVE-2001-0731
Description:
Apache 1.3.20 with Multiviews enabled allows remote
attackers to view directory contents and bypass the
index page via a URL containing the "M=D" query string.
Status: Entry
Reference: BUGTRAQ:20010709 How Google indexed a
file with no external link
Reference:
URL:http://www.securityfocus.com/archive/1/20010709214744.A28765@brasscannon.net
Reference:
CONFIRM:http://www.apacheweek.com/issues/01-10-05#security
Reference: MANDRAKE:MDKSA-2001:077
Reference:
URL:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:077
Reference: REDHAT:RHSA-2001:126
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-126.html
Reference: REDHAT:RHSA-2001:164
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-164.html
Reference: BID:3009
Reference:
URL:http://www.securityfocus.com/bid/3009
Reference:
XF:apache-multiviews-directory-listing(8275)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/8275
Reference: SGI:20020301-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20020301-01-P
Name: CVE-2001-0733
Description:
The #sinclude directive in Embedded Perl (ePerl) 2.2.14
and earlier allows a remote attacker to execute
arbitrary code by modifying the 'sinclude' file to point
to another file that contains a #include directive that
references a file that contains the code. Status:
Entry
Reference: BUGTRAQ:20010621 bugtraq submission
Reference:
URL:http://www.securityfocus.com/archive/1/192711
Reference: BID:2912
Reference:
URL:http://www.securityfocus.com/bid/2912
Reference: XF:eperl-embedded-code-execution(6743)
Reference:
URL:http://xforce.iss.net/static/6743.php
Name: CVE-2001-0738
Description:
LogLine function in klogd in sysklogd 1.3 in various
Linux distributions allows an attacker to cause a denial
of service (hang) by causing null bytes to be placed in
log messages. Status: Entry
Reference: BUGTRAQ:20010614 sysklogd update --
Immunix OS 6.2, 7.0-beta, 7.0
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99258618906506&w=2
Reference: CERT-VN:VU#249579
Reference:
URL:http://www.kb.cert.org/vuls/id/249579
Reference: IMMUNIX:IMNX-2001-70-026-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-026-01
Reference: XF:klogd-null-byte-dos(7098)
Reference:
URL:http://xforce.iss.net/static/7098.php
Name: CVE-2001-0739
Description:
Guardian Digital WebTool in EnGarde Secure Linux 1.0.1
allows restarted services to inherit some environmental
variables, which could allow local users to gain root
privileges. Status: Entry
Reference: REDHAT:RHSA-2001:126
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-126.html
Reference: ENGARDE:ESA-20010529-02
Reference:
URL:http://www.linuxsecurity.com/advisories/other_advisory-1404.html
Reference:
XF:linux-webtool-inherit-privileges(7404)
Reference:
URL:http://xforce.iss.net/static/7404.php
Name: CVE-2001-0740
Description:
3COM OfficeConnect 812 and 840 ADSL Router 4.2, running
OCR812 router software 1.1.9 and earlier, allows remote
attackers to cause a denial of service via a long string
containing a large number of "%s" strings, possibly
triggering a format string vulnerability. Status:
Entry
Reference: BUGTRAQ:20010515 3COM OfficeConnect
DSL router vulneratibilities
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0115.html
Reference: BUGTRAQ:20010921 3Com OfficeConnect
812/840 Router DoS exploit code
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100119572524232&w=2
Reference: BUGTRAQ:20010924 Regarding: 3Com
OfficeConnect 812/840 Router DoS exploit code
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100137290421828&w=2
Reference: XF:3com-officeconnect-http-dos(6573)
Reference:
URL:http://xforce.iss.net/static/6573.php
Reference: BID:2721
Reference:
URL:http://www.securityfocus.com/bid/2721
Name: CVE-2001-0741
Description:
Cisco Hot Standby Routing Protocol (HSRP) allows local
attackers to cause a denial of service by spoofing HSRP
packets. Status: Entry
Reference: BUGTRAQ:20010503 Cisco HSRP
Weakness/DoS
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0035.html
Reference:
MISC:http://www.cisco.com/networkers/nw00/pres/2402.pdf
Reference: XF:cisco-hsrp-dos(6497)
Reference:
URL:http://xforce.iss.net/static/6497.php
Reference: BID:2684
Reference:
URL:http://www.securityfocus.com/bid/2684
Name: CVE-2001-0745
Description:
Netscape 4.7x allows remote attackers to obtain
sensitive information such as the user's login, mailbox
location and installation path via Javascript that
accesses the mailbox: URL in the document.referrer
property. Status: Entry
Reference: BUGTRAQ:20010605 SECURITY.NNOV:
Netscape 4.7x Messanger user information retrival
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0014.html
Reference: XF:netscape-user-info-retrieval(7417)
Reference:
URL:http://xforce.iss.net/static/7417.php
Reference: OSVDB:5543
Reference: URL:http://www.osvdb.org/5543
Name: CVE-2001-0748
Description:
Acme.Serve 1.7, as used in Cisco Secure ACS Unix and
possibly other products, allows remote attackers to read
arbitrary files by prepending several / (slash)
characters to the URI. Status: Entry
Reference: BUGTRAQ:20010531 Acme.Server v1.7 of
13nov96 Directory Browsing
Reference:
URL:http://www.securityfocus.com/archive/1/188141
Reference:
XF:acme-serve-directory-traversal(6634)
Reference:
URL:http://www.iss.net/security_center/static/6634.php
Reference: CISCO:20020702 Cisco Secure ACS Unix
Acme.server Information Disclosure Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/acmeweb-acsunix-dirtravers-vuln-pub.shtml
Reference: BID:2809
Reference:
URL:http://www.securityfocus.com/bid/2809
Reference: OSVDB:5544
Reference: URL:http://www.osvdb.org/5544
Name: CVE-2001-0749
Description:
Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote
attackers to read arbitrary files via a webserver root
directory set to system root. Status: Entry
Reference: BUGTRAQ:20010524 IPC@Chip Security
Reference:
URL:http://www.securityfocus.com/archive/1/186418
Reference: BID:2775
Reference:
URL:http://www.securityfocus.com/bid/2775
Reference: XF:ipcchip-web-root-system(8922)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/8922
Name: CVE-2001-0750
Description:
Cisco IOS 12.1(2)T, 12.1(3)T allow remote attackers to
cause a denial of service (reload) via a connection to
TCP ports 3100-3999, 5100-5999, 7100-7999 and
10100-10999. Status: Entry
Reference: CISCO:20010524 IOS Reload after
Scanning Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/ios-tcp-scanner-reload-pub.shtml
Reference: XF:cisco-ios-tcp-dos(6589)
Reference:
URL:http://xforce.iss.net/static/6589.php
Reference: BID:2804
Reference:
URL:http://www.securityfocus.com/bid/2804
Reference: OSVDB:800
Reference: URL:http://www.osvdb.org/800
Name: CVE-2001-0751
Description:
Cisco switches and routers running CBOS 2.3.8 and
earlier use predictable TCP Initial Sequence Numbers
(ISN), which allows remote attackers to spoof or hijack
TCP connections. Status: Entry
Reference: CISCO:20010522 More Multiple
Vulnerabilities in CBOS
Reference:
URL:http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html
Reference: XF:tcp-seq-predict(139)
Reference:
URL:http://xforce.iss.net/static/139.php
Name: CVE-2001-0752
Description:
Cisco CBOS 2.3.8 and earlier allows remote attackers to
cause a denial of service via an ICMP ECHO REQUEST
(ping) with the IP Record Route option set. Status:
Entry
Reference: CISCO:20010522 More Multiple
Vulnerabilities in CBOS
Reference:
URL:http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html
Reference: XF:cisco-cbos-record-dos(7298)
Reference:
URL:http://xforce.iss.net/static/7298.php
Reference: OSVDB:5573
Reference: URL:http://www.osvdb.org/5573
Name: CVE-2001-0754
Description:
Cisco CBOS 2.3.8 and earlier allows remote attackers to
cause a denial of service via a series of large ICMP
ECHO REPLY (ping) packets, which cause it to enter
ROMMON mode and stop forwarding packets. Status:
Entry
Reference: CISCO:20010522 More Multiple
Vulnerabilities in CBOS
Reference:
URL:http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html
Reference: XF:cisco-cbos-multiple-echo(7299)
Reference:
URL:http://xforce.iss.net/static/7299.php
Name: CVE-2001-0757
Description:
Cisco 6400 Access Concentrator Node Route Processor 2
(NRP2) 12.1DC card does not properly disable access when
a password has not been set for vtys, which allows
remote attackers to obtain access via telnet. Status:
Entry
Reference: CISCO:20010614 Cisco 6400 NRP2 Telnet
Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/6400-nrp2-telnet-vuln-pub.shtml
Reference: BID:2874
Reference:
URL:http://www.securityfocus.com/bid/2874
Reference: XF:cisco-nrp2-telnet-access(6691)
Reference:
URL:http://xforce.iss.net/static/6691.php
Reference: CERT-VN:VU#516659
Reference:
URL:http://www.kb.cert.org/vuls/id/516659
Reference: CIAC:L-097
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-097.shtml
Reference: OSVDB:804
Reference: URL:http://www.osvdb.org/804
Name: CVE-2001-0760
Description:
Citrix Nfuse 1.51 allows remote attackers to obtain the
absolute path of the web root via a malformed request to
launch.asp that does not provide the session field.
Status: Entry
Reference: BUGTRAQ:20010630 Nfuse reveals full
path
Reference:
URL:http://www.securityfocus.com/archive/1/194449
Reference: BUGTRAQ:20010702 Re: Nfuse reveals
full path
Reference:
URL:http://www.securityfocus.com/archive/1/194522
Reference: BID:2956
Reference:
URL:http://www.securityfocus.com/bid/2956
Reference: XF:citrix-nfuse-path-disclosure(6786)
Reference:
URL:http://xforce.iss.net/static/6786.php
Name: CVE-2001-0763
Description:
Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and
earlier may allow remote attackers to execute arbitrary
code via a long ident response, which is not properly
handled by the svc_logprint function. Status:
Entry
Reference: BUGTRAQ:20010608 potential buffer
overflow in xinetd-2.1.8.9pre11-1
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0064.html
Reference: CONECTIVA:CLA-2001:404
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000404
Reference: DEBIAN:DSA-063
Reference:
URL:http://www.debian.org/security/2001/dsa-063
Reference: SUSE:SA:2001:022
Reference: IMMUNIX:IMNX-2001-70-024-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-024-01
Reference: ENGARDE:ESA-20010621-01
Reference:
URL:http://www.linuxsecurity.com/advisories/other_advisory-1469.html
Reference: CIAC:L-104
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-104.shtml
Reference: REDHAT:RHSA-2001:075
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-075.html
Reference: FREEBSD:FreeBSD-SA-01:47
Reference: XF:xinetd-identd-bo(6670)
Reference:
URL:http://xforce.iss.net/static/6670.php
Reference: BID:2840
Reference:
URL:http://www.securityfocus.com/bid/2840
Name: CVE-2001-0764
Description:
Buffer overflow in ntping in scotty 2.1.0 allows local
users to execute arbitrary code via a long hostname as a
command line argument. Status: Entry
Reference: VULN-DEV:20010609 suid scotty / ntping
overflow
Reference:
URL:http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0579.html
Reference: VULN-DEV:20010615 Re: suid scotty
(ntping) overflow (fwd)
Reference:
URL:http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0627.html
Reference: BUGTRAQ:20010621 suid scotty (ntping)
overflow (fwd)
Reference:
URL:http://www.securityfocus.com/archive/1/192664
Reference: SUSE:SuSE-SA:2001:023
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_023_scotty_txt.html
Reference: XF:scotty-ntping-bo(6735)
Reference:
URL:http://xforce.iss.net/static/6735.php
Reference: BID:2911
Reference:
URL:http://www.securityfocus.com/bid/2911
Name: CVE-2001-0765
Description:
BisonFTP V4R1 allows local users to access directories
outside of their home directory by uploading .bdl files,
which can then be linked to other directories.
Status: Entry
Reference: BUGTRAQ:20010702 BisonFTP Server V4R1
*.bdl upload Directory Traversal
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0025.html
Reference:
CONFIRM:http://www.bisonftp.com/ServRev.htm
Reference: BID:2963
Reference:
URL:http://www.securityfocus.com/bid/2963
Reference:
XF:bisonftp-bdl-directory-traversal(6782)
Reference:
URL:http://xforce.iss.net/static/6782.php
Reference: OSVDB:1888
Reference: URL:http://www.osvdb.org/1888
Name: CVE-2001-0769
Description:
Memory leak in GuildFTPd Server 0.97 allows remote
attackers to cause a denial of service via a request
containing a null character. Status: Entry
Reference: BUGTRAQ:20010527 def-2001-27:
GuildFTPD Buffer Overflow and Memory Leak DoS
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0254.html
Reference: XF:guildftpd-null-memory-leak(6613)
Reference:
URL:http://xforce.iss.net/static/6613.php
Name: CVE-2001-0770
Description:
Buffer overflow in GuildFTPd Server 0.97 allows remote
attacker to execute arbitrary code via a long SITE
command. Status: Entry
Reference: BUGTRAQ:20010527 def-2001-27:
GuildFTPD Buffer Overflow and Memory Leak DoS
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0254.html
Reference: XF:guildftpd-site-bo(6612)
Reference:
URL:http://xforce.iss.net/static/6612.php
Reference:
CONFIRM:http://www.nitrolic.com/help/history.htm
Name: CVE-2001-0773
Description:
Cayman 3220-H DSL Router 1.0 allows remote attacker to
cause a denial of service (crash) via a series of SYN or
TCP connect requests. Status: Entry
Reference: BUGTRAQ:20010709 Cayman-DSL Model
3220-H DOS with nmap
Reference:
URL:http://www.securityfocus.com/archive/1/195644
Reference: BID:3001
Reference:
URL:http://www.securityfocus.com/bid/3001
Reference: XF:cayman-dsl-portscan-dos(6825)
Reference:
URL:http://xforce.iss.net/static/6825.php
Reference: CERT-VN:VU#312761
Reference:
URL:http://www.kb.cert.org/vuls/id/312761
Name: CVE-2001-0774
Description:
Tripwire 1.3.1, 2.2.1 and 2.3.0 allows local users to
overwrite arbitrary files and possible gain privileges
via a symbolic link attack on temporary files.
Status: Entry
Reference: BUGTRAQ:20010709 Tripwire temporary
files
Reference:
URL:http://www.securityfocus.com/archive/1/195617
Reference: BID:3003
Reference:
URL:http://www.securityfocus.com/bid/3003
Reference: XF:tripwire-tmpfile-symlink(6820)
Reference:
URL:http://xforce.iss.net/static/6820.php
Reference: CERT-VN:VU#349019
Reference:
URL:http://www.kb.cert.org/vuls/id/349019
Reference: MANDRAKE:MDKSA-2001:064
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-064.php3
Reference: OSVDB:1895
Reference: URL:http://www.osvdb.org/1895
Name: CVE-2001-0779
Description:
Buffer overflow in rpc.yppasswdd (yppasswd server) in
Solaris 2.6, 7 and 8 allows remote attackers to gain
root access via a long username. Status: Entry
Reference: BUGTRAQ:20010528 solaris 2.6, 7
yppasswd vulnerability
Reference:
URL:http://www.securityfocus.com/archive/1/187086
Reference: BUGTRAQ:20011004 Patches for Solaris
rpc.yppasswdd available
Reference:
URL:http://www.securityfocus.com/archive/1/200110041632.JAA28125@dim.ucsd.edu
Reference: SUNBUG:4456994
Reference: CERT-VN:VU#327281
Reference:
URL:http://www.kb.cert.org/vuls/id/327281
Reference: SUN:00209
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/209
Reference: CIAC:M-008
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-008.shtml
Reference: XF:solaris-yppasswd-bo(6629)
Reference:
URL:http://xforce.iss.net/static/6629.php
Reference: BID:2763
Reference:
URL:http://www.securityfocus.com/bid/2763
Reference: OVAL:oval:org.mitre.oval:def:102
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:102
Reference: OVAL:oval:org.mitre.oval:def:56
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:56
Name: CVE-2001-0784
Description:
Directory traversal vulnerability in Icecast 1.3.10 and
earlier allows remote attackers to read arbitrary files
via a modified .. (dot dot) attack using encoded URL
characters. Status: Entry
Reference: BUGTRAQ:20010626 Advisory
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0353.html
Reference: REDHAT:RHSA-2001:105
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-105.html
Reference: REDHAT:RHSA-2002:063
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2002-063.html
Reference: BID:2932
Reference:
URL:http://www.securityfocus.com/bid/2932
Reference:
XF:icecast-dot-directory-traversal(6752)
Reference:
URL:http://xforce.iss.net/static/6752.php
Reference: DEBIAN:DSA-089
Reference:
URL:http://www.debian.org/security/2001/dsa-089
Reference: OSVDB:1883
Reference: URL:http://www.osvdb.org/1883
Name: CVE-2001-0787
Description:
LPRng in Red Hat Linux 7.0 and 7.1 does not properly
drop memberships in supplemental groups when lowering
privileges, which could allow a local user to elevate
privileges. Status: Entry
Reference: REDHAT:RHSA-2001:077
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-077.html
Reference: CIAC:L-096
Reference:
URL:http://www.ciac.org/ciac/bulletins/l-096.shtml
Reference: BID:2865
Reference:
URL:http://www.securityfocus.com/bid/2865
Reference: XF:lprng-supplementary-groups(6703)
Reference:
URL:http://xforce.iss.net/static/6703.php
Name: CVE-2001-0792
Description:
Format string vulnerability in XChat 1.2.x allows remote
attackers to execute arbitrary code via a malformed
nickname. Status: Entry
Reference:
MISC:http://www.securiteam.com/exploits/5AP0Q2A4AQ.html
Reference: XF:xchat-nickname-format-string(7416)
Reference:
URL:http://xforce.iss.net/static/7416.php
Name: CVE-2001-0796
Description:
SGI IRIX 6.5 through 6.5.12f and possibly earlier
versions, and FreeBSD 3.0, allows remote attackers to
cause a denial of service via a malformed IGMP multicast
packet with a small response delay. Status: Entry
Reference: SGI:20011001-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20011001-01-P
Reference:
CONFIRM:http://www.freebsd.org/cgi/query-pr.cgi?pr=8990
Reference: XF:irix-igmp-dos(7332)
Reference:
URL:http://xforce.iss.net/static/7332.php
Reference: BID:3463
Reference:
URL:http://www.securityfocus.com/bid/3463
Name: CVE-2001-0797
Description:
Buffer overflow in login in various System V based
operating systems allows remote attackers to execute
arbitrary commands via a large number of arguments
through services such as telnet and rlogin. Status:
Entry
Reference: ISS:20011212 Buffer Overflow in
/bin/login
Reference:
URL:http://xforce.iss.net/alerts/advise105.php
Reference: BUGTRAQ:20011219 Linux distributions
and /bin/login overflow
Reference:
URL:http://www.securityfocus.com/archive/1/246487
Reference: CERT:CA-2001-34
Reference:
URL:http://www.cert.org/advisories/CA-2001-34.html
Reference: CERT-VN:VU#569272
Reference:
URL:http://www.kb.cert.org/vuls/id/569272
Reference: CALDERA:CSSA-2001-SCO.40
Reference:
URL:ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.40/CSSA-2001-SCO.40.txt
Reference: SUN:00213
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/213
Reference: AIXAPAR:IY26221
Reference:
URL:http://www-1.ibm.com/support/search.wss?rs=0&q=IY26221&apar=only
Reference: SGI:20011201-01-I
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20011201-01-I
Reference: SUNBUG:4516885
Reference: BUGTRAQ:20011214 Sun Solaris login bug
patches out
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100844757228307&w=2
Reference: BID:3681
Reference:
URL:http://www.securityfocus.com/bid/3681
Reference: OVAL:oval:org.mitre.oval:def:2025
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2025
Reference: XF:telnet-tab-bo(7284)
Reference:
URL:http://xforce.iss.net/static/7284.php
Name: CVE-2001-0801
Description:
lpstat in IRIX 6.5.13f and earlier allows local users to
gain root privileges by specifying a Trojan Horse
nettype shared library. Status: Entry
Reference:
MISC:http://www.lsd-pl.net/files/get?IRIX/irx_lpstat2
Reference: SGI:20011003-02-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20011003-02-P
Reference: XF:irix-lpstat-net-type-library(7639)
Reference:
URL:http://xforce.iss.net/static/7639.php
Name: CVE-2001-0803
Description:
Buffer overflow in the client connection routine of
libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd)
allows remote attackers to execute arbitrary commands.
Status: Entry
Reference: ISS:20011112 Multi-Vendor Buffer
Overflow Vulnerability in CDE Subprocess Control Service
Reference:
URL:http://xforce.iss.net/alerts/advise101.php
Reference: CALDERA:CSSA-2001-SCO.30
Reference:
URL:ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.30/
Reference: COMPAQ:SSRT541
Reference:
URL:http://ftp.support.compaq.com/patches/.new/html/SSRT-541.shtml
Reference: HP:HPSBUX0111-175
Reference:
URL:http://www.securityfocus.com/advisories/3651
Reference: SGI:20011107-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20011107-01-P
Reference: SUN:00214
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/214
Reference: CERT:CA-2001-31
Reference:
URL:http://www.cert.org/advisories/CA-2001-31.html
Reference: CERT:CA-2002-01
Reference:
URL:http://www.cert.org/advisories/CA-2002-01.html
Reference: CERT-VN:VU#172583
Reference:
URL:http://www.kb.cert.org/vuls/id/172583
Reference: BID:3517
Reference:
URL:http://www.securityfocus.com/bid/3517
Reference: OVAL:oval:org.mitre.oval:def:70
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:70
Reference: OVAL:oval:org.mitre.oval:def:74
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:74
Reference: XF:cde-dtspcd-bo(7396)
Reference:
URL:http://xforce.iss.net/static/7396.php
Name: CVE-2001-0804
Description:
Directory traversal vulnerability in story.pl in
Interactive Story 1.3 allows a remote attacker to read
arbitrary files via a .. (dot dot) attack on the "next"
parameter. Status: Entry
Reference: BUGTRAQ:20010715 Interactive Story
File Disclosure Vulnerability
Reference:
URL:http://www.securityfocus.com/archive/1/4.3.2.7.2.20010715184257.00b20100@compumodel.com
Reference:
CONFIRM:http://www.valeriemates.com/story_download.html
Reference:
XF:interactive-story-next-directory-traversal(6843)
Reference:
URL:http://xforce.iss.net/static/6843.php
Reference: BID:3028
Reference:
URL:http://www.securityfocus.com/bid/3028
Reference: OSVDB:683
Reference: URL:http://www.osvdb.org/683
Name: CVE-2001-0805
Description:
Directory traversal vulnerability in ttawebtop.cgi in
Tarantella Enterprise 3.00 and 3.01 allows remote
attackers to read arbitrary files via a .. (dot dot) in
the pg parameter. Status: Entry
Reference: BUGTRAQ:20010618 SCO Tarantella Remote
file read via ttawebtop.cgi
Reference:
URL:http://www.securityfocus.com/archive/1/3B2E37D0.81D9ED9D@snosoft.com
Reference: BUGTRAQ:20010619 Re: SCO Tarantella
Remote file read via ttawebtop.cgi
Reference:
URL:http://www.securityfocus.com/archive/1/20010619150935.A5226@tarantella.com
Reference:
XF:tarantella-ttawebtop-read-files(6723)
Reference:
URL:http://xforce.iss.net/static/6723.php
Reference: BID:2890
Reference:
URL:http://www.securityfocus.com/bid/2890
Name: CVE-2001-0806
Description:
Apple MacOS X 10.0 and 10.1 allow a local user to read
and write to a user's desktop folder via insecure
default permissions for the Desktop when it is created
in some languages. Status: Entry
Reference: BUGTRAQ:20010626 MacOSX 10.0.X
Permissions uncorrectly set
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99358249631139&w=2
Reference: BUGTRAQ:20011007 OS X 10.1 and
localized desktop folder still vulnerable
Reference:
URL:http://online.securityfocus.com/archive/1/219166
Reference: BUGTRAQ:20010704 Re: MacOSX 10.0.X
Permissions uncorrectly set - I got it
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99436289015729&w=2
Reference: BID:2930
Reference:
URL:http://www.securityfocus.com/bid/2930
Reference:
XF:macos-desktop-insecure-permissions(6750)
Reference:
URL:http://xforce.iss.net/static/6750.php
Reference: OSVDB:1882
Reference: URL:http://www.osvdb.org/1882
Name: CVE-2001-0815
Description:
Buffer overflow in PerlIS.dll in Activestate ActivePerl
5.6.1.629 and earlier allows remote attackers to exute
arbitrary code via an HTTP request for a long filename
that ends in a .pl extension. Status: Entry
Reference: BUGTRAQ:20011115 NSFOCUS SA2001-07 :
ActivePerl PerlIS.dll Remote Buffer Overflow
Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100583978302585&w=2
Reference:
CONFIRM:http://bugs.activestate.com/show_bug.cgi?id=18062
Reference: BID:3526
Reference:
URL:http://www.securityfocus.com/bid/3526
Reference: XF:activeperl-perlis-filename-bo(7539)
Reference:
URL:http://xforce.iss.net/static/7539.php
Reference: OSVDB:678
Reference: URL:http://www.osvdb.org/678
Name: CVE-2001-0816
Description:
OpenSSH before 2.9.9, when running sftp using
sftp-server and using restricted keypairs, allows remote
authenticated users to bypass authorized_keys2 command=
restrictions using sftp commands. Status: Entry
Reference: BUGTRAQ:20010918 OpenSSH: sftp &
bypassing keypair auth restrictions
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0153.html
Reference: CONECTIVA:CLSA-2001:431
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000431
Reference: IMMUNIX:IMNX-2001-70-034-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-034-01
Reference: REDHAT:RHSA-2001:154
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-154.html
Reference:
XF:openssh-sftp-bypass-restrictions(7634)
Reference:
URL:http://xforce.iss.net/static/7634.php
Reference: OSVDB:5536
Reference: URL:http://www.osvdb.org/5536
Name: CVE-2001-0819
Description:
A buffer overflow in Linux fetchmail before 5.8.6 allows
remote attackers to execute arbitrary code via a large
'To:' field in an email header. Status: Entry
Reference: DEBIAN:DSA-060
Reference:
URL:http://www.debian.org/security/2001/dsa-060
Reference: ENGARDE:ESA-20010620-01
Reference:
URL:http://www.linuxsecurity.com/advisories/other_advisory-1451.html
Reference: MANDRAKE:MDKSA-2001:063
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-063.php3?dis=7.1
Reference: CALDERA:CSSA-2001-022.1
Reference:
URL:http://www.caldera.com/support/security/advisories/CSSA-2001-022.1.txt
Reference: CONECTIVA:CLA-2001:403
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000403
Reference: FREEBSD:FreeBSD-SA-01:43
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:43.fetchmail.asc
Reference: IMMUNIX:IMNX-2001-70-025-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-025-01
Reference: REDHAT:RHSA-2001:103
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-103.html
Reference: BID:2877
Reference:
URL:http://www.securityfocus.com/bid/2877
Reference: XF:fetchmail-long-header-bo(6704)
Reference:
URL:http://xforce.iss.net/static/6704.php
Reference: SUSE:SuSE-SA:2001:026
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_026_fetchmail_txt.html
Name: CVE-2001-0822
Description:
FPF kernel module 1.0 allows a remote attacker to cause
a denial of service via fragmented packets. Status:
Entry
Reference: BUGTRAQ:20010602 fpf module and packet
fragmentation:local/remote DoS.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99167206319643&w=2
Reference: CONFIRM:http://www.pkcrew.org/news.php
Reference: XF:linux-fpf-kernel-dos(6659)
Reference:
URL:http://xforce.iss.net/static/6659.php
Reference: BID:2816
Reference:
URL:http://www.securityfocus.com/bid/2816
Name: CVE-2001-0823
Description:
The pmpost program in Performance Co-Pilot (PCP) before
2.2.1-3 allows a local user to gain privileges via a
symlink attack on the NOTICES file in the PCP log
directory (PCP_LOG_DIR). Status: Entry
Reference: BUGTRAQ:20010618 pmpost - another nice
symlink follower
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99290754901708&w=2
Reference: BUGTRAQ:20010619 Re: pmpost - another
nice symlink follower
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0245.html
Reference: SGI:20010601-01-A
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20010601-01-A
Reference: XF:irix-pcp-pmpost-symlink(6724)
Reference:
URL:http://xforce.iss.net/static/6724.php
Reference: BID:2887
Reference:
URL:http://www.securityfocus.com/bid/2887
Name: CVE-2001-0825
Description:
Buffer overflow in internal string handling routines of
xinetd before 2.1.8.8 allows remote attackers to execute
arbitrary commands via a length argument of zero or
less, which disables the length check. Status:
Entry
Reference: SUSE:SuSE-SA:2001:022
Reference: CONECTIVA:CLA-2001:406
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000406
Reference: REDHAT:RHSA-2001:092
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-092.html
Reference: IMMUNIX:IMNX-2001-70-029-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-029-01
Reference: BID:2971
Reference:
URL:http://www.securityfocus.com/bid/2971
Reference: XF:xinetd-zero-length-bo(6804)
Reference:
URL:http://xforce.iss.net/static/6804.php
Name: CVE-2001-0828
Description:
A cross-site scripting vulnerability in Caucho
Technology Resin before 1.2.4 allows a malicious
webmaster to embed Javascript in a hyperlink that ends
in a .jsp extension, which causes an error message that
does not properly quote the Javascript. Status:
Entry
Reference: BUGTRAQ:20010702 Multiple Vendor Java
Servlet Container Cross-Site Scripting Vulnerability
Reference:
URL:http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00021.html
Reference:
CONFIRM:http://www.caucho.com/products/resin/changes.xtp
Reference: BID:2981
Reference:
URL:http://www.securityfocus.com/bid/2981
Reference:
XF:java-servlet-crosssite-scripting(6793)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6793
Reference: CERT-VN:VU#981651
Reference:
URL:http://www.kb.cert.org/vuls/id/981651
Reference: OSVDB:1890
Reference: URL:http://www.osvdb.org/1890
Name: CVE-2001-0830
Description:
6tunnel 0.08 and earlier does not properly close sockets
that were initiated by a client, which allows remote
attackers to cause a denial of service (resource
exhaustion) by repeatedly connecting to and
disconnecting from the server. Status: Entry
Reference: BUGTRAQ:20011023 Remote DoS in 6tunnel
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100386451702966&w=2
Reference:
CONFIRM:ftp://213.146.38.146/pub/wojtekka/6tunnel-0.09.tar.gz
Reference: XF:6tunnel-open-socket-dos(7337)
Reference:
URL:http://xforce.iss.net/static/7337.php
Reference: BID:3467
Reference:
URL:http://www.securityfocus.com/bid/3467
Name: CVE-2001-0833
Description:
Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1
allows local users to execute arbitrary code via a long
ORACLE_HOME environment variable, aka the "Oracle Trace
Collection Security Vulnerability." Status: Entry
Reference: BUGTRAQ:20010802 vulnerability in
otrcrep binary in Oracle 8.0.5.
Reference:
URL:http://online.securityfocus.com/archive/1/201295
Reference: BUGTRAQ:20011023 FW: ASI Oracle
Security Alert: 3 new security alerts
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100386756715645&w=2
Reference: BUGTRAQ:20011024 Oracle Trace
Collection Security Vulnerability
Reference:
URL:http://online.securityfocus.com/archive/1/222612
Reference: VULNWATCH:20011024 Oracle Trace
Collection Security Vulnerability
Reference:
CONFIRM:http://otn.oracle.com/deploy/security/pdf/otrcrep.pdf
Reference: CIAC:M-011
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-011.shtml
Reference: XF:oracle-binary-symlink(6940)
Reference:
URL:http://xforce.iss.net/static/6940.php
Reference: BID:3139
Reference:
URL:http://www.securityfocus.com/bid/3139
Name: CVE-2001-0834
Description:
htsearch CGI program in htdig (ht://Dig) 3.1.5 and
earlier allows remote attackers to use the -c option to
specify an alternate configuration file, which could be
used to (1) cause a denial of service (CPU consumption)
by specifying a large file such as /dev/zero, or (2)
read arbitrary files by uploading an alternate
configuration file that specifies the target file.
Status: Entry
Reference:
MISC:http://sourceforge.net/tracker/index.php?func=detail&aid=458013&group_id=4593&atid=104593
Reference: BUGTRAQ:20011007 Re: Bug found in
ht://Dig htsearch CGI
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100260195401753&w=2
Reference: CONECTIVA:CLA-2001:429
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000429
Reference: SUSE:SuSE-SA:2001:035
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_035_htdig_txt.html
Reference: DEBIAN:DSA-080
Reference:
URL:http://www.debian.org/security/2001/dsa-080
Reference: REDHAT:RHSA-2001:139
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-139.html
Reference: CALDERA:CSSA-2001-035.0
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-035.0.txt
Reference: MANDRAKE:MDKSA-2001:083
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-083.php3
Reference: BID:3410
Reference:
URL:http://www.securityfocus.com/bid/3410
Reference: XF:htdig-htsearch-infinite-loop(7262)
Reference:
URL:http://xforce.iss.net/static/7262.php
Reference: XF:htdig-htsearch-retrieve-files(7263)
Reference:
URL:http://xforce.iss.net/static/7263.php
Name: CVE-2001-0836
Description:
Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows
remote attackers to execute arbitrary code via a long
HTTP GET request. Status: Entry
Reference: BUGTRAQ:20011018 def-2001-30
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100342151132277&w=2
Reference: BUGTRAQ:20011024 Oracle9iAS Web Cache
Overflow Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100395487007578&w=2
Reference:
CONFIRM:http://otn.oracle.com/deploy/security/pdf/webcache.pdf
Reference: CERT:CA-2001-29
Reference:
URL:http://www.cert.org/advisories/CA-2001-29.html
Reference: CERT-VN:VU#649979
Reference:
URL:http://www.kb.cert.org/vuls/id/649979
Reference: XF:oracle-appserver-http-bo(7306)
Reference:
URL:http://xforce.iss.net/static/7306.php
Reference: OSVDB:5534
Reference: URL:http://www.osvdb.org/5534
Name: CVE-2001-0837
Description:
DeltaThree Pc-To-Phone 3.0.3 places sensitive data in
world-readable locations in the installation directory,
which allows local users to read the information in (1)
temp.html, (2) the log folder, and (3) the PhoneBook
folder. Status: Entry
Reference: BUGTRAQ:20011025 Pc-to-Phone
vulnerability - broken by design
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100403691432052&w=2
Reference:
XF:pc2phone-temp-account-readable(7393)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7393
Reference: BID:3475
Reference:
URL:http://www.securityfocus.com/bid/3475
Name: CVE-2001-0843
Description:
Squid proxy server 2.4 and earlier allows remote
attackers to cause a denial of service (crash) via a
mkdir-only FTP PUT request. Status: Entry
Reference: BUGTRAQ:20010921 squid DoS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100109679010256&w=2
Reference: REDHAT:RHSA-2001:113
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-113.html
Reference: SUSE:SuSE-SA:2001:037
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_037_squid_txt.html
Reference: MANDRAKE:MDKSA-2001:088
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-088.php3
Reference: DEBIAN:DSA-077
Reference:
URL:http://www.debian.org/security/2001/dsa-077
Reference: XF:squid-mkdir-put-dos(7157)
Reference:
URL:http://xforce.iss.net/static/7157.php
Reference: BID:3354
Reference:
URL:http://www.securityfocus.com/bid/3354
Reference: CONECTIVA:CLA-2001:426
Reference:
URL:http://archives.neohapsis.com/archives/linux/conectiva/2001-q3/0020.html
Name: CVE-2001-0846
Description:
Lotus Domino 5.x allows remote attackers to read files
or execute arbitrary code by requesting the ReplicaID of
the Web Administrator template file (webadmin.ntf).
Status: Entry
Reference: BUGTRAQ:20011030 Lotus Domino Web
Administrator Template ReplicaID Access (#NISR29102001A)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100448721830960&w=2
Reference: XF:lotus-domino-replicaid-access(7424)
Reference:
URL:http://xforce.iss.net/static/7424.php
Reference: BID:3491
Reference:
URL:http://www.iss.net/security_center/static/7424.php
Reference: OSVDB:1979
Reference: URL:http://www.osvdb.org/1979
Name: CVE-2001-0850
Description:
A configuration error in the libdb1 package in OpenLinux
3.1 uses insecure versions of the snprintf and vsnprintf
functions, which could allow local or remote users to
exploit those functions with a buffer overflow.
Status: Entry
Reference: CALDERA:CSSA-2001-037.0
Reference:
URL:http://www.caldera.com/support/security/advisories/CSSA-2001-037.0.txt
Reference: XF:openlinux-libdb-bo(7427)
Reference:
URL:http://xforce.iss.net/static/7427.php
Name: CVE-2001-0851
Description:
Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled
allows remote attackers to bypass firewall rules by
brute force guessing the cookie. Status: Entry
Reference: ENGARDE:ESA-20011106-01
Reference:
URL:http://www.linuxsecurity.com/advisories/other_advisory-1683.html
Reference: CALDERA:CSSA-2001-38.0
Reference:
URL:http://www.caldera.com/support/security/advisories/CSSA-2001-038.0.txt
Reference: SUSE:SuSE-SA:2001:039
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_039_kernel2_txt.html
Reference: XF:linux-syncookie-bypass-filter(7461)
Reference:
URL:http://xforce.iss.net/static/7461.php
Reference: REDHAT:RHSA-2001:142
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-142.html
Reference: CONECTIVA:CLA-2001:432
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000432
Reference: MANDRAKE:MDKSA-2001:082
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-082.php3
Name: CVE-2001-0852
Description:
TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote
attackers to cause a denial of service via a long Host:
header. Status: Entry
Reference: BUGTRAQ:20011105 RH Linux Tux HTTPD
DoS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100498100112191&w=2
Reference: VULNWATCH:20011102 [RH Linux7.2] Tux
HTTPD Denial of Service
Reference:
CONFIRM:http://marc.theaimsgroup.com/?l=tux-list&m=100584714702328&w=2
Reference: REDHAT:RHSA-2001:142
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-142.html
Reference: XF:tux-http-host-dos(7464)
Reference:
URL:http://xforce.iss.net/static/7464.php
Reference: BID:3506
Reference:
URL:http://www.securityfocus.com/bid/3506
Name: CVE-2001-0857
Description:
Cross-site scripting vulnerability in status.php3 in Imp
Webmail 2.2.6 and earlier allows remote attackers to
gain access to the e-mail of other users by hijacking
session cookies via the message parameter. Status:
Entry
Reference: BUGTRAQ:20011109 Imp Webmail session
hijacking vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100535679608486&w=2
Reference: BUGTRAQ:20011110 IMP 2.2.7 (SECURITY)
released
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100540578822469&w=2
Reference: CONECTIVA:CLA-2001:437
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000437
Reference: CALDERA:CSSA-2001-039.0
Reference:
URL:http://www.caldera.com/support/security/advisories/CSSA-2001-039.0.txt
Reference: BID:3525
Reference:
URL:http://www.securityfocus.com/bid/3525
Reference: OSVDB:668
Reference: URL:http://www.osvdb.org/668
Reference: XF:imp-css-steal-cookies(7496)
Reference:
URL:http://xforce.iss.net/static/7496.php
Name: CVE-2001-0859
Description:
2.4.3-12 kernel in Red Hat Linux 7.1 Korean installation
program sets the setting default umask for init to 000,
which installs files with world-writeable permissions.
Status: Entry
Reference: REDHAT:RHSA-2001:148
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-148.html
Reference: HP:HPSBTL0112-006
Reference:
URL:http://online.securityfocus.com/advisories/3725
Reference: XF:linux-korean-default-umask(7549)
Reference:
URL:http://xforce.iss.net/static/7549.php
Reference: BID:3527
Reference:
URL:http://www.securityfocus.com/bid/3527
Name: CVE-2001-0860
Description:
Terminal Services Manager MMC in Windows 2000 and XP
trusts the Client Address (IP address) that is provided
by the client instead of obtaining it from the packet
headers, which allows clients to spoof their public IP
address, e.g. through a Network Address Translation
(NAT). Status: Entry
Reference: BUGTRAQ:20011114 Xato Advisory:
Win2k/XP Terminal Services IP Spoofing
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100578220002083&w=2
Reference: XF:win-terminal-spoof-address(7538)
Reference:
URL:http://xforce.iss.net/static/7538.php
Reference: BID:3541
Reference:
URL:http://www.securityfocus.com/bid/3541
Name: CVE-2001-0861
Description:
Cisco 12000 with IOS 12.0 and line cards based on Engine
2 and earlier allows remote attackers to cause a denial
of service (CPU consumption) by flooding the router with
traffic that generates a large number of ICMP
Unreachable replies. Status: Entry
Reference: CISCO:20011114 ICMP Unreachable
Vulnerability in Cisco 12000 Series Internet Router
Reference:
URL:http://www.cisco.com/warp/public/707/GSR-unreachables-pub.shtml
Reference: CIAC:M-018
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-018.shtml
Reference: XF:cisco-icmp-unreachable-dos(7536)
Reference:
URL:http://xforce.iss.net/static/7536.php
Reference: BID:3534
Reference:
URL:http://www.securityfocus.com/bid/3534
Reference: OSVDB:794
Reference: URL:http://www.osvdb.org/794
Name: CVE-2001-0862
Description:
Cisco 12000 with IOS 12.0 and line cards based on Engine
2 does not block non-initial packet fragments, which
allows remote attackers to bypass the ACL. Status:
Entry
Reference: CISCO:20011114 Multiple
Vulnerabilities in Access Control List Implementation
for Cisco 12000 Series Internet Router
Reference:
URL:http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml
Reference: CIAC:M-018
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-018.shtml
Reference: XF:cisco-acl-noninital-dos(7550)
Reference:
URL:http://xforce.iss.net/static/7550.php
Reference: BID:3535
Reference:
URL:http://www.securityfocus.com/bid/3535
Reference: OSVDB:1985
Reference: URL:http://www.osvdb.org/1985
Name: CVE-2001-0863
Description:
Cisco 12000 with IOS 12.0 and line cards based on Engine
2 does not handle the "fragment" keyword in a compiled
ACL (Turbo ACL) for packets that are sent to the router,
which allows remote attackers to cause a denial of
service via a flood of fragments. Status: Entry
Reference: CISCO:20011114 Multiple
Vulnerabilities in Access Control List Implementation
for Cisco 12000 Series Internet Router
Reference:
URL:http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml
Reference: CIAC:M-018
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-018.shtml
Reference: XF:cisco-acl-outgoing-fragment(7551)
Reference:
URL:http://xforce.iss.net/static/7551.php
Reference: BID:3539
Reference:
URL:http://www.securityfocus.com/bid/3539
Reference: OSVDB:1987
Reference: URL:http://www.osvdb.org/1987
Name: CVE-2001-0864
Description:
Cisco 12000 with IOS 12.0 and line cards based on Engine
2 does not properly handle the implicit "deny ip any
any" rule in an outgoing ACL when the ACL contains
exactly 448 entries, which can allow some outgoing
packets to bypass access restrictions. Status:
Entry
Reference: CISCO:20011114 Multiple
Vulnerabilities in Access Control List Implementation
for Cisco 12000 Series Internet Router
Reference:
URL:http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml
Reference: CIAC:M-018
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-018.shtml
Reference: XF:cisco-acl-deny-ip(7553)
Reference:
URL:http://xforce.iss.net/static/7553.php
Reference: BID:3536
Reference:
URL:http://www.securityfocus.com/bid/3536
Reference: OSVDB:1986
Reference: URL:http://www.osvdb.org/1986
Name: CVE-2001-0865
Description:
Cisco 12000 with IOS 12.0 and line cards based on Engine
2 does not support the "fragment" keyword in an outgoing
ACL, which could allow fragmented packets in violation
of the intended access. Status: Entry
Reference: CISCO:20011114 Multiple
Vulnerabilities in Access Control List Implementation
for Cisco 12000 Series Internet Router
Reference:
URL:http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml
Reference: CIAC:M-018
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-018.shtml
Reference: BID:3540
Reference:
URL:http://www.securityfocus.com/bid/3540
Reference: XF:cisco-turbo-acl-dos(7552)
Reference:
URL:http://xforce.iss.net/static/7552.php
Reference: OSVDB:1988
Reference: URL:http://www.osvdb.org/1988
Name: CVE-2001-0866
Description:
Cisco 12000 with IOS 12.0 and lines card based on Engine
2 does not properly handle an outbound ACL when an input
ACL is not configured on all the interfaces of a multi
port line card, which could allow remote attackers to
bypass the intended access controls. Status:
Entry
Reference: CISCO:20011114 Multiple
Vulnerabilities in Access Control List Implementation
for Cisco 12000 Series Internet Router
Reference:
URL:http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml
Reference: CIAC:M-018
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-018.shtml
Reference: XF:cisco-input-acl-configured(7554)
Reference:
URL:http://www.iss.net/security_center/static/7554.php
Reference: BID:3537
Reference:
URL:http://www.securityfocus.com/bid/3537
Reference: OSVDB:1984
Reference: URL:http://www.osvdb.org/1984
Name: CVE-2001-0867
Description:
Cisco 12000 with IOS 12.0 and line cards based on Engine
2 does not properly filter does not properly filter
packet fragments even when the "fragment" keyword is
used in an ACL, which allows remote attackers to bypass
the intended access controls. Status: Entry
Reference: CISCO:20011114 Multiple
Vulnerabilities in Access Control List Implementation
for Cisco 12000 Series Internet Router
Reference:
URL:http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml
Reference: CIAC:M-018
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-018.shtml
Reference: XF:cisco-acl-fragment-bypass(7555)
Reference:
URL:http://xforce.iss.net/static/7555.php
Reference: BID:3538
Reference:
URL:http://www.securityfocus.com/bid/3538
Reference: OSVDB:1989
Reference: URL:http://www.osvdb.org/1989
Name: CVE-2001-0869
Description:
Format string vulnerability in the default logging
callback function _sasl_syslog in common.c in Cyrus SASL
library (cyrus-sasl) may allow remote attackers to
execute arbitrary commands. Status: Entry
Reference: BUGTRAQ:20011101 Formatting string bug
on cyrus-sasl library
Reference: CALDERA:CSSA-2001-040.0
Reference:
URL:http://www.caldera.com/support/security/advisories/CSSA-2001-040.0.txt
Reference: CONECTIVA:CLA-2001:444
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000444
Reference: FREEBSD:FreeBSD-SA-02:15
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:15.cyrus-sasl.asc
Reference: MANDRAKE:MDKSA-2002:018
Reference:
URL:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:018
Reference: REDHAT:RHSA-2001:150
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-150.html
Reference: REDHAT:RHSA-2001:151
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-151.html
Reference: SUSE:SuSE-SA:2001:042
Reference:
URL:http://lwn.net/alerts/SuSE/SuSE-SA%3A2001%3A042.php3
Reference: BID:3498
Reference:
URL:http://www.securityfocus.com/bid/3498
Reference: XF:cyrus-sasl-format-string(7443)
Reference:
URL:http://xforce.iss.net/static/7443.php
Name: CVE-2001-0872
Description:
OpenSSH 3.0.1 and earlier with UseLogin enabled does not
properly cleanse critical environment variables such as
LD_PRELOAD, which allows local users to gain root
privileges. Status: Entry
Reference: BUGTRAQ:20011204 [Fwd: OpenSSH 3.0.2
fixes UseLogin vulnerability]
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100749779131514&w=2
Reference: VULN-DEV:20011205 OpenSSH UseLogin
proof of concept exploit
Reference:
CONFIRM:http://marc.theaimsgroup.com/?l=openssh-unix-dev&m=100747128105913&w=2
Reference: CALDERA:CSSA-2001-042.1
Reference:
URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-042.1.txt
Reference: DEBIAN:DSA-091
Reference:
URL:http://www.debian.org/security/2001/dsa-091
Reference: FREEBSD:FreeBSD-SA-01:63
Reference: HP:HPSBUX0112-005
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0112-005
Reference: MANDRAKE:MDKSA-2001:092
Reference:
URL:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:092
Reference: REDHAT:RHSA-2001:161
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-161.html
Reference: SUSE:SuSE-SA:2001:045
Reference:
URL:http://lists.suse.com/archives/suse-security-announce/2001-Dec/0001.html
Reference: BUGTRAQ:20011220 TSL-2001-0030 -
openssh (updated)
Reference: TURBO:TLSA2002001
Reference: CONECTIVA:CLA-2001:446
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000446
Reference: CIAC:M-026
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-026.shtml
Reference: CERT-VN:VU#157447
Reference:
URL:http://www.kb.cert.org/vuls/id/157447
Reference: BID:3614
Reference:
URL:http://www.securityfocus.com/bid/3614
Reference: OSVDB:688
Reference: URL:http://www.osvdb.org/688
Reference: XF:openssh-uselogin-execute-code(7647)
Reference:
URL:http://xforce.iss.net/static/7647.php
Name: CVE-2001-0873
Description:
uuxqt in Taylor UUCP package does not properly remove
dangerous long options, which allows local users to gain
privileges by calling uux and specifying an alternate
configuration file with the --config option. Status:
Entry
Reference: BUGTRAQ:20010908 Multiple vendor
'Taylor UUCP' problems.
Reference:
URL:http://www.securityfocus.com/archive/1/212892
Reference: BUGTRAQ:20011130 Redhat 7.0 local root
(via uucp) (attempt 2)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100715446131820
Reference: CALDERA:CSSA-2001-033.0
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-033.0.txt
Reference: CONECTIVA:CLA-2001:425
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000425
Reference: DEBIAN:DSA-079
Reference:
URL:http://www.debian.org/security/2001/dsa-079
Reference: SUSE:SuSE-SA:2001:38
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_038_uucp_txt.html
Reference: BID:3312
Reference:
URL:http://www.securityfocus.com/bid/3312
Reference: XF:uucp-argument-gain-privileges(7099)
Reference:
URL:http://xforce.iss.net/static/7099.php
Reference: REDHAT:RHSA-2001:165
Reference:
URL:http://rhn.redhat.com/errata/RHSA-2001-165.html
Name: CVE-2001-0874
Description:
Internet Explorer 5.5 and 6.0 allow remote attackers to
read certain files via HTML that passes information from
a frame in the client's domain to a frame in the web
site's domain, a variant of the "Frame Domain
Verification" vulnerability. Status: Entry
Reference: MS:MS01-058
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-058.asp
Reference: CIAC:M-027
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-027.shtml
Reference:
XF:ie-frame-verification-variant2(7702)
Reference:
URL:http://xforce.iss.net/static/7702.php
Reference: BID:3693
Reference:
URL:http://www.securityfocus.com/bid/3693
Name: CVE-2001-0875
Description:
Internet Explorer 5.5 and 6.0 allows remote attackers to
cause the File Download dialogue box to misrepresent the
name of the file in the dialogue in a way that could
fool users into thinking that the file type is safe to
download. Status: Entry
Reference: BUGTRAQ:20011126 File extensions
spoofable in MSIE download dialog
Reference:
URL:http://www.securityfocus.com/archive/1/245594
Reference: MS:MS01-058
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-058.asp
Reference: XF:ie-file-download-ext-spoof(7636)
Reference:
URL:http://xforce.iss.net/static/7636.php
Reference: BID:3597
Reference:
URL:http://www.securityfocus.com/bid/3597
Reference: OVAL:oval:org.mitre.oval:def:1014
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1014
Name: CVE-2001-0876
Description:
Buffer overflow in Universal Plug and Play (UPnP) on
Windows 98, 98SE, ME, and XP allows remote attackers to
execute arbitrary code via a NOTIFY directive with a
long Location URL. Status: Entry
Reference: BUGTRAQ:20011220 Multiple Remote
Windows XP/ME/98 Vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100887440810532&w=2
Reference: NTBUGTRAQ:20011220 Multiple Remote
Windows XP/ME/98 Vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=100887271006313&w=2
Reference: MS:MS01-059
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-059.asp
Reference: CERT:CA-2001-37
Reference:
URL:http://www.cert.org/advisories/CA-2001-37.html
Reference: CERT-VN:VU#951555
Reference:
URL:http://www.kb.cert.org/vuls/id/951555
Reference: CIAC:M-030
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-030.shtml
Reference: BID:3723
Reference:
URL:http://www.securityfocus.com/bid/3723
Reference: XF:win-upnp-notify-bo(7721)
Reference:
URL:http://xforce.iss.net/static/7721.php
Name: CVE-2001-0877
Description:
Universal Plug and Play (UPnP) on Windows 98, 98SE, ME,
and XP allows remote attackers to cause a denial of
service via (1) a spoofed SSDP advertisement that causes
the client to connect to a service on another machine
that generates a large amount of traffic (e.g.,
chargen), or (2) via a spoofed SSDP announcement to
broadcast or multicast addresses, which could cause all
UPnP clients to send traffic to a single target system.
Status: Entry
Reference: BUGTRAQ:20011220 Multiple Remote
Windows XP/ME/98 Vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100887440810532&w=2
Reference: NTBUGTRAQ:20011220 Multiple Remote
Windows XP/ME/98 Vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=100887271006313&w=2
Reference: BUGTRAQ:20020109 UPNP Denial of
Service
Reference:
URL:http://www.securityfocus.com/archive/1/249238
Reference: MS:MS01-059
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms01-059.asp
Reference: CERT:CA-2001-37
Reference:
URL:http://www.cert.org/advisories/CA-2001-37.html
Reference: CERT-VN:VU#411059
Reference:
URL:http://www.kb.cert.org/vuls/id/411059
Reference: CIAC:M-030
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-030.shtml
Reference: BID:3724
Reference:
URL:http://www.securityfocus.com/bid/3724
Reference: XF:win-upnp-udp-dos(7722)
Reference:
URL:http://xforce.iss.net/static/7722.php
Name: CVE-2001-0879
Description:
Format string vulnerability in the C runtime functions
in SQL Server 7.0 and 2000 allows attackers to cause a
denial of service. Status: Entry
Reference: ATSTAKE:A122001-1
Reference:
URL:http://www.atstake.com/research/advisories/2001/a122001-1.txt
Reference: BUGTRAQ:20011221 @stake advisory:
Multiple overflow and format string vulnerabilities in
in Microsoft SQL Server
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100891252317406&w=2
Reference: MS:MS01-060
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS01-060.asp
Reference: XF:mssql-c-runtime-format-string(7725)
Reference:
URL:http://xforce.iss.net/static/7725.php
Reference: BID:3732
Reference:
URL:http://www.securityfocus.com/bid/3732
Reference: OVAL:oval:org.mitre.oval:def:253
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:253
Name: CVE-2001-0884
Description:
Cross-site scripting vulnerability in Mailman email
archiver before 2.08 allows attackers to obtain
sensitive information or authentication credentials via
a malicious link that is accessed by other web users.
Status: Entry
Reference: BUGTRAQ:20011128 Cgisecurity.com
Advisory #7: Mailman Email Archive Cross Site Scripting
Reference:
URL:http://www.securityfocus.com/archive/1/242839
Reference: CONECTIVA:CLA-2001:445
Reference:
URL:http://www.securityfocus.com/advisories/3721
Reference: REDHAT:RHSA-2001:168
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-168.html
Reference: REDHAT:RHSA-2001:169
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-169.html
Reference: REDHAT:RHSA-2001:170
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-170.html
Reference: BID:3602
Reference:
URL:http://www.securityfocus.com/bid/3602
Reference: XF:mailman-java-css(7617)
Reference:
URL:http://xforce.iss.net/static/7617.php
Name: CVE-2001-0886
Description:
Buffer overflow in glob function of glibc allows
attackers to cause a denial of service (crash) and
possibly execute arbitrary code via a glob pattern that
ends in a brace "{" character. Status: Entry
Reference:
MISC:http://sources.redhat.com/ml/bug-glibc/2001-11/msg00109.html
Reference: BUGTRAQ:20011217 [Global InterSec
2001121001] glibc globbing issues.
Reference:
URL:http://www.securityfocus.com/archive/1/245956
Reference: CONECTIVA:CLA-2002:447
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000447
Reference: DEBIAN:DSA-103
Reference:
URL:http://www.debian.org/security/2002/dsa-103
Reference: ENGARDE:ESA-20011217-01
Reference:
URL:http://www.linuxsecurity.com/advisories/other_advisory-1752.html
Reference: HP:HPSBTL0112-008
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0112-008
Reference: IMMUNIX:IMNX-2001-70-037-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-037-01
Reference: MANDRAKE:MDKSA-2001:095
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-095.php3
Reference: REDHAT:RHSA-2001:160
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-160.html
Reference: SUSE:SuSE-SA:2001:046
Reference: BUGTRAQ:20011220 TSLSA-2001-0029 -
glibc
Reference: CIAC:M-029
Reference:
URL:http://www.ciac.org/ciac/bulletins/m-029.shtml
Reference: BID:3707
Reference:
URL:http://www.securityfocus.com/bid/3707
Reference: XF:glibc-glob-bo(7705)
Reference:
URL:http://xforce.iss.net/static/7705.php
Name: CVE-2001-0887
Description:
xSANE 0.81 and earlier allows local users to modify
files of other xSANE users via a symlink attack on
temporary files. Status: Entry
Reference: FREEBSD:FreeBSD-SA-01:68
Reference:
URL:http://www.securityfocus.com/advisories/3734
Reference: REDHAT:RHSA-2001:171
Reference:
URL:http://rhn.redhat.com/errata/RHSA-2001-171.html
Reference: REDHAT:RHSA-2001:172
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-172.html
Reference: BID:3700
Reference:
URL:http://www.securityfocus.com/bid/3700
Reference: XF:xsane-temp-symlink(7714)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7714
Name: CVE-2001-0888
Description:
Atmel Firmware 1.3 Wireless Access Point (WAP) allows
remote attackers to cause a denial of service via a SNMP
request with (1) a community string other than "public"
or (2) an unknown OID, which causes the WAP to deny
subsequent SNMP requests. Status: Entry
Reference: BUGTRAQ:20011221 VIGILANTe advisory
2001003 : Atmel SNMP Non Public Community String DoS
Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100895903202798&w=2
Reference: XF:atmel-snmp-community-dos(7734)
Reference:
URL:http://xforce.iss.net/static/7734.php
Reference: BID:3734
Reference:
URL:http://www.securityfocus.com/bid/3734
Name: CVE-2001-0889
Description:
Exim 3.22 and earlier, in some configurations, does not
properly verify the local part of an address when
redirecting the address to a pipe, which could allow
remote attackers to execute arbitrary commands via shell
metacharacters. Status: Entry
Reference: BUGTRAQ:20011219 [ph10@cus.cam.ac.uk:
[Exim] Potential security problem]
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100877978506387&w=2
Reference: DEBIAN:DSA-097
Reference:
URL:http://www.debian.org/security/2002/dsa-097
Reference: REDHAT:RHSA-2001:176
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-176.html
Reference: CERT-VN:VU#283723
Reference:
URL:http://www.kb.cert.org/vuls/id/283723
Reference: BID:3728
Reference:
URL:http://www.securityfocus.com/bid/3728
Reference: XF:exim-pipe-hostname-commands(7738)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7738
Name: CVE-2001-0891
Description:
Format string vulnerability in NQS daemon (nqsdaemon) in
NQE 3.3.0.16 for CRAY UNICOS and SGI IRIX allows a local
user to gain root privileges by using qsub to submit a
batch job whose name contains formatting characters.
Status: Entry
Reference: BUGTRAQ:20011127 UNICOS LOCAL HOLE ALL
VERSIONS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100695627423924&w=2
Reference: SGI:20020101-01-I
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20020101-01-I
Reference: BID:3590
Reference:
URL:http://www.securityfocus.com/bid/3590
Reference: OSVDB:3275
Reference: URL:http://www.osvdb.org/3275
Reference: XF:unicos-nqsd-format-string(7618)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7618
Name: CVE-2001-0894
Description:
Vulnerability in Postfix SMTP server before
20010228-pl07, when configured to email the postmaster
when SMTP errors cause the session to terminate, allows
remote attackers to cause a denial of service (memory
exhaustion) by generating a large number of SMTP errors,
which forces the SMTP session log to grow too large.
Status: Entry
Reference: BUGTRAQ:20011115 Postfix session log
memory exhaustion bugfix
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100584160110303&w=2
Reference: CONECTIVA:CLA-2001:439
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000439
Reference: DEBIAN:DSA-093
Reference:
URL:http://www.debian.org/security/2001/dsa-093
Reference: MANDRAKE:MDKSA-2001:089
Reference:
URL:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:089
Reference: REDHAT:RHSA-2001:156
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-156.html
Reference: BID:3544
Reference:
URL:http://www.securityfocus.com/bid/3544
Reference: XF:postfix-smtp-log-dos(7568)
Reference:
URL:http://xforce.iss.net/static/7568.php
Name: CVE-2001-0895
Description:
Multiple Cisco networking products allow remote
attackers to cause a denial of service on the local
network via a series of ARP packets sent to the router's
interface that contains a different MAC address for the
router, which eventually causes the router to overwrite
the MAC address in its ARP table. Status: Entry
Reference: CISCO:20011115 Cisco IOS ARP Table
Overwrite Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/IOS-arp-overwrite-vuln-pub.shtml
Reference: CERT-VN:VU#399355
Reference:
URL:http://www.kb.cert.org/vuls/id/399355
Reference: BID:3547
Reference:
URL:http://www.securityfocus.com/bid/3547
Reference: OSVDB:807
Reference: URL:http://www.osvdb.org/807
Reference: XF:cisco-arp-overwrite-table(7547)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7547
Name: CVE-2001-0896
Description:
Inetd in OpenServer 5.0.5 allows remote attackers to
cause a denial of service (crash) via a port scan, e.g.
with nmap -PO. Status: Entry
Reference: CALDERA:CSSA-2001-SCO.33
Reference:
URL:ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.33/CSSA-2001-SCO.33.txt
Reference: BUGTRAQ:20020201 RE: DoS bug on Tru64
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101284101228656&w=2
Reference: BUGTRAQ:20020205 nmap vs. inetd on
Caldera (ex-SCO) OpenServer, Re: DoS bug on Tru64
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101303877215098&w=2
Reference: XF:openserver-nmap-po-option(7571)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7571
Name: CVE-2001-0899
Description:
Network Tools 0.2 for PHP-Nuke allows remote attackers
to execute commands on the server via shell
metacharacters in the $hostinput variable. Status:
Entry
Reference: BUGTRAQ:20011116 Network Tool 0.2
Addon for PHPNuke vulnerable to remote command execution
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100593523104176&w=2
Reference:
CONFIRM:http://phpnukerz.org/modules.php?name=Downloads&d_op=viewsdownload&sid=32
Reference:
XF:phpnuke-nettools-command-execution(7578)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7578
Name: CVE-2001-0900
Description:
Directory traversal vulnerability in modules.php in
Gallery before 1.2.3 allows remote attackers to read
arbitrary files via a .. (dot dot) in the include
parameter. Status: Entry
Reference: BUGTRAQ:20011118 Gallery Addon for
PhpNuke remote file viewing vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100619599000590&w=2
Reference:
CONFIRM:http://www.menalto.com/projects/gallery/article.php?sid=33&mode=&order=
Reference: BID:3554
Reference:
URL:http://www.securityfocus.com/bid/3554
Reference: OSVDB:677
Reference: URL:http://www.osvdb.org/677
Reference:
XF:phpnuke-gallery-directory-traversal(7580)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7580
Name: CVE-2001-0901
Description:
Hypermail allows remote attackers to execute arbitrary
commands on a server supporting SSI via an attachment
with a .shtml extension, which is archived on the server
and can then be executed by requesting the URL for the
attachment. Status: Entry
Reference: BUGTRAQ:20011119 Hypermail SSI
Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100626603407639&w=2
Reference:
CONFIRM:http://www.hypermail.org/dist/hypermail-2.1.4.tar.gz
Reference:
XF:hypermail-ssi-execute-commands(7576)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7576
Name: CVE-2001-0902
Description:
Microsoft IIS 5.0 allows remote attackers to spoof web
log entries via an HTTP request that includes
hex-encoded newline or form-feed characters. Status:
Entry
Reference: BUGTRAQ:20011120 IIS logging issue
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100626531103946&w=2
Reference: NTBUGTRAQ:20011120 IIS logging issue
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=100627497122247&w=2
Reference: XF:iis-fake-log-entry(7613)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7613
Reference: BID:6795
Reference:
URL:http://www.securityfocus.com/bid/6795
Name: CVE-2001-0905
Description:
Race condition in signal handling of procmail 3.20 and
earlier, when running setuid, allows local users to
cause a denial of service or gain root privileges by
sending a signal while a signal handling routine is
already running. Status: Entry
Reference: DEBIAN:DSA-083
Reference:
URL:http://www.debian.org/security/2001/dsa-083
Reference: REDHAT:RHSA-2001:093
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-093.html
Reference: MANDRAKE:MDKSA-2001:085
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-085.php3
Reference: FREEBSD:FreeBSD-SA-01:60
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:60.procmail.asc
Reference: CONECTIVA:CLA-2001:433
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000433
Reference: BID:3071
Reference:
URL:http://www.securityfocus.com/bid/3071
Reference: XF:procmail-signal-handling-race(6872)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6872
Name: CVE-2001-0906
Description:
teTeX filter before 1.0.7 allows local users to gain
privileges via a symlink attack on temporary files that
are produced when printing .dvi files using lpr.
Status: Entry
Reference: BUGTRAQ:20010622 LPRng + tetex tmpfile
race - uid lp exploit
Reference:
URL:http://www.securityfocus.com/archive/1/192647
Reference: REDHAT:RHSA-2001:102
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-102.html
Reference: MANDRAKE:MDKSA-2001:086
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-086.php3
Reference: IMMUNIX:IMNX-2001-70-030-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-030-01
Reference: BID:2974
Reference:
URL:http://www.securityfocus.com/bid/2974
Reference: XF:tetex-lprng-tmp-race(6785)
Reference:
URL:http://xforce.iss.net/static/6785.php
Name: CVE-2001-0907
Description:
Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through
2.4.10, allows local users to cause a denial of service
via a series of deeply nested symlinks, which causes the
kernel to spend extra time when trying to access the
link. Status: Entry
Reference: BUGTRAQ:20011018 Flaws in recent Linux
kernels
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100343090106914&w=2
Reference: MANDRAKE:MDKSA-2001:082
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-082.php3
Reference: SUSE:SuSE-SA:2001:036
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_036_kernel_txt.html
Reference: IMMUNIX:IMNX-2001-70-035-01
Reference:
URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-035-01
Reference: CALDERA:CSSA-2001-036.0
Reference:
URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-036.0.txt
Reference: MANDRAKE:MDKSA-2001:079
Reference:
URL:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:079
Reference: ENGARDE:ESA-20011019-02
Reference:
URL:http://www.linuxsecurity.com/advisories/other_advisory-1650.html
Reference: BUGTRAQ:20011019 TSLSA-2001-0028
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100350685431610&w=2
Reference: XF:linux-multiple-symlink-dos(7312)
Reference:
URL:http://www.iss.net/security_center/static/7312.php
Reference: BID:3444
Reference:
URL:http://www.securityfocus.com/bid/3444
Name: CVE-2001-0909
Description:
Buffer overflow in helpctr.exe program in Microsoft Help
Center for Windows XP allows remote attackers to execute
arbitrary code via a long hcp: URL. Status: Entry
Reference: BUGTRAQ:20011121 Buffer overflow in
Windows XP "helpctr.exe"
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100638955422011&w=2
Reference: XF:winxp-helpctr-bo(7605)
Reference:
URL:http://xforce.iss.net/static/7605.php
Reference: BID:6802
Reference:
URL:http://www.securityfocus.com/bid/6802
Name: CVE-2001-0912
Description:
Packaging error for expect 8.3.3 in Mandrake Linux 8.1
causes expect to search for its libraries in the
/home/snailtalk directory before other directories,
which could allow a local user to gain root privileges.
Status: Entry
Reference: MANDRAKE:MDKSA-2001:087
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-087.php3?dis=8.1
Reference: XF:linux-expect-unauth-root(7604)
Reference:
URL:http://xforce.iss.net/static/7604.php
Name: CVE-2001-0914
Description:
Linux kernel before 2.4.11pre3 in multiple Linux
distributions allows local users to cause a denial of
service (crash) by starting the core vmlinux kernel,
possibly related to poor error checking during ELF
loading. Status: Entry
Reference: BUGTRAQ:20011121 SuSE 7.3 : Kernel
2.4.10-4GB Bug
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100638584813349&w=2
Reference: BUGTRAQ:20011122 Re: SuSE 7.3 : Kernel
2.4.10-4GB Bug
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100654787226869&w=2L:2
Reference: XF:linux-vmlinux-dos(7591)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7591
Reference: BID:3570
Reference:
URL:http://www.securityfocus.com/bid/3570
Name: CVE-2001-0917
Description:
Jakarta Tomcat 4.0.1 allows remote attackers to reveal
physical path information by requesting a long URL with
a .JSP extension. Status: Entry
Reference: BUGTRAQ:20011122 Hi
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100654722925155&w=2
Reference:
CONFIRM:http://marc.theaimsgroup.com/?l=tomcat-dev&m=100658457507305&w=2
Reference: XF:tomcat-reveal-install-path(7599)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7599
Name: CVE-2001-0918
Description:
Vulnerabilities in CGI scripts in susehelp in SuSE 7.2
and 7.3 allow remote attackers to execute arbitrary
commands by not opening files securely. Status:
Entry
Reference: SUSE:SuSE-SA:2001:041
Reference:
URL:http://www.novell.com/linux/security/advisories/2001_041_susehelp_txt.html
Reference:
XF:susehelp-cgi-command-execution(7583)
Reference:
URL:http://xforce.iss.net/static/7583.php
Reference: BID:3576
Reference:
URL:http://www.securityfocus.com/bid/3576
Name: CVE-2001-0920
Description:
Format string vulnerability in auto nice daemon (AND)
1.0.4 and earlier allows a local user to possibly
execute arbitrary code via a process name containing a
format string. Status: Entry
Reference: BUGTRAQ:20011126 [CERT-intexxia] Auto
Nice Daemon Format String Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100680319004162&w=2
Reference: CONFIRM:http://and.sourceforge.net/
Reference: XF:and-format-string(7606)
Reference:
URL:http://xforce.iss.net/static/7606.php
Reference: BID:3580
Reference:
URL:http://www.securityfocus.com/bid/3580
Name: CVE-2001-0921
Description:
Netscape 4.79 and earlier for MacOS allows an attacker
with access to the browser to obtain passwords from form
fields by printing the document into which the password
has been typed, which is printed in cleartext.
Status: Entry
Reference: BUGTRAQ:20011121 Mac Netscape password
fields
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100638816318705&w=2
Reference:
XF:macos-netscape-print-passwords(7593)
Reference:
URL:http://xforce.iss.net/static/7593.php
Reference: BID:3565
Reference:
URL:http://www.securityfocus.com/bid/3565
Reference: OSVDB:5524
Reference: URL:http://www.osvdb.org/5524
Name: CVE-2001-0929
Description:
Cisco IOS Firewall Feature set, aka Context Based Access
Control (CBAC) or Cisco Secure Integrated Software, for
IOS 11.2P through 12.2T does not properly check the IP
protocol type, which could allow remote attackers to
bypass access control lists. Status: Entry
Reference: CISCO:20011128 A Vulnerability in IOS
Firewall Feature Set
Reference:
URL:http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml
Reference: CERT-VN:VU#362483
Reference:
URL:http://www.kb.cert.org/vuls/id/362483
Reference: BID:3588
Reference:
URL:http://www.securityfocus.com/bid/3588
Reference: OSVDB:808
Reference: URL:http://www.osvdb.org/808
Reference: XF:ios-cbac-bypass-acl(7614)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7614
Name: CVE-2001-0936
Description:
Buffer overflow in Frox transparent FTP proxy 0.6.6 and
earlier, with the local caching method selected, allows
remote FTP servers to run arbitrary code via a long
response to an MDTM request. Status: Entry
Reference: BUGTRAQ:20011130 Alert: Vulnerability
in frox transparent ftp proxy.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100713367307799&w=2
Reference:
CONFIRM:http://frox.sourceforge.net/security.txt
Reference: XF:frox-ftp-proxy-bo(7632)
Reference:
URL:http://xforce.iss.net/static/7632.php
Reference: BID:3606
Reference:
URL:http://www.securityfocus.com/bid/3606
Name: CVE-2001-0939
Description:
Lotus Domino 5.08 and earlier allows remote attackers to
cause a denial of service (crash) via a SunRPC NULL
command to port 443. Status: Entry
Reference: BUGTRAQ:20011130 Denial of Service in
Lotus Domino 5.08 and earlier HTTP Server
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100715316426817&w=2
Reference:
CONFIRM:http://www-1.ibm.com/support/manager.wss?rs=0&rt=0&org=sims&doc=4C8E450DBF2E7F1885256B200079FA88
Reference: BID:3607
Reference:
URL:http://www.securityfocus.com/bid/3607
Reference: XF:lotus-domino-nhttp-dos(7631)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7631
Reference: OSVDB:1998
Reference: URL:http://www.osvdb.org/1998
Name: CVE-2001-0940
Description:
Buffer overflow in the GUI authentication code of Check
Point VPN-1/FireWall-1 Management Server 4.0 and 4.1
allows remote attackers to execute arbitrary code via a
long user name. Status: Entry
Reference: WIN2KSEC:20010921 Check Point
FireWall-1 GUI Buffer Overflow
Reference:
URL:http://archives.neohapsis.com/archives/win2ksecadvice/2001-q3/0151.html
Reference: BUGTRAQ:20011128 Firewall-1 remote
SYSTEM shell buffer overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100698954308436&w=2
Reference: BUGTRAQ:20010919 Check Point
FireWall-1 GUI Log Viewer vulnerability (vuldb 3336)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100094268017271&w=2
Reference: BUGTRAQ:20011130 Fw: Firewall-1 remote
SYSTEM shell buffer overflow
Reference:
URL:http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00291.html
Reference: CHECKPOINT:20010919 GUI Buffer
Overflow
Reference:
URL:http://www.checkpoint.com/techsupport/alerts/buffer_overflow.html
Reference: BID:3336
Reference:
URL:http://www.securityfocus.com/bid/3336
Reference: XF:fw1-log-viewer-bo(7145)
Reference:
URL:http://xforce.iss.net/static/7145.php
Reference: OSVDB:1951
Reference: URL:http://www.osvdb.org/1951
Name: CVE-2001-0946
Description:
apmscript in Apmd in Red Hat 7.2 "Enigma" allows local
users to create or change the modification dates of
arbitrary files via a symlink attack on the LOW_POWER
temporary file, which could be used to cause a denial of
service, e.g. by creating /etc/nologin and disabling
logins. Status: Entry
Reference: BUGTRAQ:20011204 Symlink attack with
apmd of RH 7.2
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100743394701962&w=2
Reference:
MISC:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=56389
Reference: XF:apmd-apmscript-symlink(8268)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/8268
Reference: OSVDB:5493
Reference: URL:http://www.osvdb.org/5493
Name: CVE-2001-0951
Description:
Windows 2000 allows remote attackers to cause a denial
of service (CPU consumption) by flooding Internet Key
Exchange (IKE) UDP port 500 with packets that contain a
large number of dot characters. Status: Entry
Reference: BUGTRAQ:20011207 UDP DoS attack in
Win2k via IKE
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100774842520403&w=2
Reference: BUGTRAQ:20011211 UDP DoS attack in
Win2k via IKE
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100813081913496&w=2
Reference: XF:win2k-ike-dos(7667)
Reference:
URL:http://xforce.iss.net/static/7667.php
Reference: BID:3652
Reference:
URL:http://www.securityfocus.com/bid/3652
Name: CVE-2001-0954
Description:
Lotus Domino 5.0.5 and 5.0.8, and possibly other
versions, allows remote attackers to cause a denial of
service (block access to databases that have not been
previously accessed) via a URL that includes the . (dot)
directory. Status: Entry
Reference: BUGTRAQ:20011207 Lotus Domino Web
server vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100780146532131&w=2L:1
Reference:
CONFIRM:http://www-1.ibm.com/support/manager.wss?rs=1&rt=0&org=sims&doc=255CC03D83CFF50C85256B1E005E349B
Reference: XF:lotus-domino-database-dos(7684)
Reference:
URL:http://xforce.iss.net/static/7684.php
Reference: BID:3656
Reference:
URL:http://www.securityfocus.com/bid/3656
Reference: OSVDB:2000
Reference: URL:http://www.osvdb.org/2000
Name: CVE-2001-0959
Description:
Computer Associates ARCserve for NT 6.61 SP2a and
ARCserve 2000 7.0 creates a hidden share named
ARCSERVE$, which allows remote attackers to obtain
sensitive information and overwrite critical files.
Status: Entry
Reference: BUGTRAQ:20010915 ARCserve 6.61 Share
Access Vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0137.html
Reference:
MISC:http://support.ca.com/Download/patches/asitnt/QO00945.html
Reference: BID:3342
Reference:
URL:http://www.securityfocus.com/bid/3342
Reference: XF:arcserve-aremote-plaintext(7122)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7122
Reference: OSVDB:5483
Reference: URL:http://www.osvdb.org/5483
Name: CVE-2001-0960
Description:
Computer Associates ARCserve for NT 6.61 SP2a and
ARCserve 2000 7.0 stores the backup agent user name and
password in cleartext in the aremote.dmp file in the
ARCSERVE$ hidden share, which allows local and remote
attackers to gain privileges. Status: Entry
Reference: BUGTRAQ:20010915 ARCserve 6.61 Share
Access Vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0137.html
Reference:
MISC:http://support.ca.com/Download/patches/asitnt/QO00945.html
Reference: XF:arcserve-aremote-plaintext(7122)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7122
Reference: BID:3343
Reference:
URL:http://www.securityfocus.com/bid/3343
Name: CVE-2001-0961
Description:
Buffer overflow in tab expansion capability of the most
program allows local or remote attackers to execute
arbitrary code via a malformed file that is viewed with
most. Status: Entry
Reference: DEBIAN:DSA-076
Reference:
URL:http://www.debian.org/security/2001/dsa-076
Reference: XF:most-file-create-bo(7149)
Reference:
URL:http://xforce.iss.net/static/7149.php
Reference: BID:3347
Reference:
URL:http://www.securityfocus.com/bid/3347
Name: CVE-2001-0962
Description:
IBM WebSphere Application Server 3.02 through 3.53 uses
predictable session IDs for cookies, which allows remote
attackers to gain privileges of WebSphere users via
brute force guessing. Status: Entry
Reference: BUGTRAQ:20010919 Websphere
cookie/sessionid predictable
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0234.html
Reference: BUGTRAQ:20010928 Re: Websphere
cookie/sessionid predictable
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0234.html
Reference:
CONFIRM:http://www14.software.ibm.com/webapp/download/postconfig.jsp?id=4000805&pf=Multi-Platform&v=3.0.2&e=Standard+%26+Advanced+Editions&cat=&s=p
Reference: XF:ibm-websphere-seq-predict(7153)
Reference:
URL:http://xforce.iss.net/static/7153.php
Reference: OSVDB:5492
Reference: URL:http://www.osvdb.org/5492
Name: CVE-2001-0963
Description:
Directory traversal vulnerability in SpoonFTP 1.1 allows
local and sometimes remote attackers to access files
outside of the FTP root via a ... (modified dot dot) in
the CD (CWD) command. Status: Entry
Reference: BUGTRAQ:20010920 Vulnerability in
SpoonFTP
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0171.html
Reference:
CONFIRM:http://www.pi-soft.com/spoonftp/index.shtml
Reference:
XF:spoonftp-dot-directory-traversal(7147)
Reference:
URL:http://xforce.iss.net/static/7147.php
Reference: BID:3351
Reference:
URL:http://www.securityfocus.com/bid/3351
Reference: OSVDB:1953
Reference: URL:http://www.osvdb.org/1953
Name: CVE-2001-0965
Description:
glFTPD 1.23 allows remote attackers to cause a denial of
service (CPU consumption) via a LIST command with an
argument that contains a large number of * (asterisk)
characters. Status: Entry
Reference: BUGTRAQ:20010817 [ASGUARD-LABS] glFTPD
v1.23 DOS Attack
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0239.html
Reference: CONFIRM:http://www.glftpd.org/
Reference: BID:3201
Reference:
URL:http://www.securityfocus.com/bid/3201
Reference: XF:glftpd-list-dos(7001)
Reference:
URL:http://www.iss.net/security_center/static/7001.php
Name: CVE-2001-0969
Description:
ipfw in FreeBSD does not properly handle the use of "me"
in its rules when point to point interfaces are used,
which causes ipfw to allow connections from arbitrary
remote hosts. Status: Entry
Reference: FREEBSD:FreeBSD-SA-01:53
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:53.ipfw.asc
Reference: XF:ipfw-me-unauthorized-access(7002)
Reference:
URL:http://xforce.iss.net/static/7002.php
Reference: BID:3206
Reference:
URL:http://www.securityfocus.com/bid/3206
Reference: OSVDB:1937
Reference: URL:http://www.osvdb.org/1937
Name: CVE-2001-0973
Description:
BSCW groupware system 3.3 through 4.0.2 beta allows
remote attackers to read or modify arbitrary files by
uploading and extracting a tar file with a symlink into
the data-bag space. Status: Entry
Reference: BUGTRAQ:20010822 BSCW symlink
vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0328.html
Reference:
CONFIRM:http://bscw.gmd.de/Bulletins/BSCW-SB-2001-08.extract.txt
Reference: CERT-VN:VU#465971
Reference:
URL:http://www.kb.cert.org/vuls/id/465971
Reference: BID:3227
Reference:
URL:http://www.securityfocus.com/bid/3227
Reference: XF:bscw-extracted-file-symlink(7029)
Reference:
URL:http://www.iss.net/security_center/static/7029.php
Name: CVE-2001-0977
Description:
slapd in OpenLDAP 1.x before 1.2.12, and 2.x before
2.0.8, allows remote attackers to cause a denial of
service (crash) via an invalid Basic Encoding Rules
(BER) length field. Status: Entry
Reference: CERT:CA-2001-18
Reference:
URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CERT-VN:VU#935800
Reference:
URL:http://www.kb.cert.org/vuls/id/935800
Reference: DEBIAN:DSA-068
Reference:
URL:http://www.debian.org/security/2001/dsa-068
Reference: REDHAT:RHSA-2001:098
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2001-098.html
Reference: CONECTIVA:CLA-2001:417
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000417
Reference: MANDRAKE:MDKSA-2001:069
Reference:
URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-069.php3
Reference: BID:3049
Reference:
URL:http://www.securityfocus.com/bid/3049
Reference: XF:openldap-ldap-protos-dos(6904)
Reference:
URL:http://xforce.iss.net/static/6904.php
Reference: OSVDB:1905
Reference: URL:http://www.osvdb.org/1905
Name: CVE-2001-0978
Description:
login in HP-UX 10.26 does not record failed login
attempts in /var/adm/btmp, which could allow attackers
to conduct brute force password guessing attacks without
being detected or observed using the lastb program.
Status: Entry
Reference: HPBUG:PHCO_17719
Reference:
URL:http://archives.neohapsis.com/archives/hp/2001-q3/0052.html
Reference: HPBUG:PHCO_24454
Reference: BID:3289
Reference:
URL:http://www.securityfocus.com/bid/3289
Reference: XF:hpux-login-btmp(8632)
Reference:
URL:http://www.iss.net/security_center/static/8632.php
Name: CVE-2001-0980
Description:
docview before 1.0-15 allows remote attackers to execute
arbitrary commands via shell metacharacters that are
processed when converting a man page to a web page.
Status: Entry
Reference: CALDERA:CSSA-2001-026.0
Reference:
URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-026.0.txt
Reference:
XF:docview-httpd-command-execution(6854)
Reference:
URL:http://xforce.iss.net/static/6854.php
Reference: BID:3052
Reference:
URL:http://www.securityfocus.com/bid/3052
Name: CVE-2001-0981
Description:
HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the
"unix password sync" option enabled calls the passwd
program without specifying the username of the user
making the request, which could cause the server to
change the password of a different user. Status:
Entry
Reference: HP:HPSBUX0108-164
Reference:
URL:http://archives.neohapsis.com/archives/hp/2001-q3/0048.html
Reference: XF:hp-cifs-change-passwords(7051)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7051
Name: CVE-2001-0982
Description:
Directory traversal vulnerability in IBM Tivoli WebSEAL
Policy Director 3.01 through 3.7.1 allows remote
attackers to read arbitrary files or directories via
encoded .. (dot dot) sequences containing "%2e" strings.
Status: Entry
Reference: BUGTRAQ:20010723
iXsecurity.20010618.policy_director.a
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0497.html
Reference: AIXAPAR:IY18152
Reference:
URL:http://www-1.ibm.com/support/search.wss?rs=0&q=IY18152&apar=only
Reference:
CONFIRM:ftp://ftp.tivoli.com/support/patches/patches_3.7.1/3.7.1-POL-0003/3.7.1-POL-0003.README
Reference:
XF:tivoli-secureway-dot-directory-traversal(6884)
Reference:
URL:http://xforce.iss.net/static/6884.php
Reference: BID:3080
Reference:
URL:http://www.securityfocu |