Monthly Archive: February 2001

CVE-2001-0086

CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter. Date published :...

CVE-2001-0084

GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program. Date published : 2001-02-02...

CVE-2001-0076

register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed. Date published : 2001-02-02...

CVE-2001-0067

The installation of J-Pilot creates the .jpilot directory with the user’s umask, which could allow local attackers to read other users’ PalmOS backup information if their umasks are not securely set. Date published :...