Логотип exploitDog
source:"redhat"
Консоль
Логотип exploitDog

exploitDog

source:"redhat"

Количество 41 119

Количество 41 119

redhat логотип

CVE-2001-0408

почти 25 лет назад

vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when another user opens a file containing malicious VIM control codes.

EPSS: Низкий
redhat логотип

CVE-2001-0406

почти 25 лет назад

Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.

EPSS: Низкий
redhat логотип

CVE-2001-0405

почти 25 лет назад

ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.

EPSS: Средний
redhat логотип

CVE-2001-0381

почти 25 лет назад

The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters the encrypted private key file and captures a single message signed with the signature key.

EPSS: Низкий
redhat логотип

CVE-2001-0328

почти 25 лет назад

TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN.

CVSS2: 2.6
EPSS: Средний
redhat логотип

CVE-2001-0317

около 25 лет назад

Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.

EPSS: Низкий
redhat логотип

CVE-2001-0316

около 25 лет назад

Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.

EPSS: Низкий
redhat логотип

CVE-2001-0309

около 25 лет назад

inetd in Red Hat 6.2 does not properly close sockets for internal services such as chargen, daytime, echo, etc., which allows remote attackers to cause a denial of service via a series of connections to the internal services.

EPSS: Низкий
redhat логотип

CVE-2001-0301

почти 25 лет назад

Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings.

EPSS: Низкий
redhat логотип

CVE-2001-0289

почти 25 лет назад

Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory.

EPSS: Низкий
redhat логотип

CVE-2001-0279

почти 25 лет назад

Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.

EPSS: Низкий
redhat логотип

CVE-2001-0233

около 25 лет назад

Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.

EPSS: Средний
redhat логотип

CVE-2001-0197

около 25 лет назад

Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.

EPSS: Низкий
redhat логотип

CVE-2001-0191

около 25 лет назад

gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.

EPSS: Низкий
redhat логотип

CVE-2001-0170

около 25 лет назад

glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.

EPSS: Низкий
redhat логотип

CVE-2001-0169

около 25 лет назад

When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.

EPSS: Низкий
redhat логотип

CVE-2001-0141

около 25 лет назад

mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations.

EPSS: Низкий
redhat логотип

CVE-2001-0131

около 25 лет назад

htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.

CVSS3: 2.9
EPSS: Низкий
redhat логотип

CVE-2001-0128

около 25 лет назад

Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.

EPSS: Низкий
redhat логотип

CVE-2001-0117

около 25 лет назад

sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2001-0408

vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when another user opens a file containing malicious VIM control codes.

1%
Низкий
почти 25 лет назад
redhat логотип
CVE-2001-0406

Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.

0%
Низкий
почти 25 лет назад
redhat логотип
CVE-2001-0405

ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.

14%
Средний
почти 25 лет назад
redhat логотип
CVE-2001-0381

The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters the encrypted private key file and captures a single message signed with the signature key.

0%
Низкий
почти 25 лет назад
redhat логотип
CVE-2001-0328

TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN.

CVSS2: 2.6
29%
Средний
почти 25 лет назад
redhat логотип
CVE-2001-0317

Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.

0%
Низкий
около 25 лет назад
redhat логотип
CVE-2001-0316

Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.

0%
Низкий
около 25 лет назад
redhat логотип
CVE-2001-0309

inetd in Red Hat 6.2 does not properly close sockets for internal services such as chargen, daytime, echo, etc., which allows remote attackers to cause a denial of service via a series of connections to the internal services.

1%
Низкий
около 25 лет назад
redhat логотип
CVE-2001-0301

Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings.

5%
Низкий
почти 25 лет назад
redhat логотип
CVE-2001-0289

Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory.

0%
Низкий
почти 25 лет назад
redhat логотип
CVE-2001-0279

Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.

0%
Низкий
почти 25 лет назад
redhat логотип
CVE-2001-0233

Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.

15%
Средний
около 25 лет назад
redhat логотип
CVE-2001-0197

Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.

10%
Низкий
около 25 лет назад
redhat логотип
CVE-2001-0191

gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.

1%
Низкий
около 25 лет назад
redhat логотип
CVE-2001-0170

glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.

1%
Низкий
около 25 лет назад
redhat логотип
CVE-2001-0169

When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.

0%
Низкий
около 25 лет назад
redhat логотип
CVE-2001-0141

mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations.

0%
Низкий
около 25 лет назад
redhat логотип
CVE-2001-0131

htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.

CVSS3: 2.9
0%
Низкий
около 25 лет назад
redhat логотип
CVE-2001-0128

Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.

0%
Низкий
около 25 лет назад
redhat логотип
CVE-2001-0117

sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.

0%
Низкий
около 25 лет назад

Уязвимостей на страницу