CVE-2001-0086
CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter. Date published :...
CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter. Date published :...
GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program. Date published : 2001-02-02...
Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets. Date published : 2001-02-02 http://archives.neohapsis.com/archives/bugtraq/2000-12/0271.html
Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file. Date published : 2001-02-02 http://archives.neohapsis.com/archives/bugtraq/2000-12/0174.html
register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed. Date published : 2001-02-02...
Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter. Date published : 2001-02-02 http://www.securityfocus.com/bid/2156 http://www.securityfocus.com/archive/1/153212
Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter. Date published : 2001-02-02 http://www.securityfocus.com/bid/2155 http://www.securityfocus.com/archive/1/153007
Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory. Date published : 2001-02-02 http://www.securityfocus.com/bid/2154 http://www.securityfocus.com/archive/1/153188
Buffer overflow in 1st Up Mail Server 4.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long MAIL FROM command. Date published : 2001-02-02 http://www.securityfocus.com/bid/2152 http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0143.html
Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter. Date published : 2001-02-02 http://archives.neohapsis.com/archives/bugtraq/2000-12/0241.html https://exchange.xforce.ibmcloud.com/vulnerabilities/5784
The installation of J-Pilot creates the .jpilot directory with the user’s umask, which could allow local attackers to read other users’ PalmOS backup information if their umasks are not securely set. Date published :...
Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command. Date published : 2001-02-02 http://archives.neohapsis.com/archives/bugtraq/2000-12/0189.html https://exchange.xforce.ibmcloud.com/vulnerabilities/5775
Webconfig, IMAP, and other services in MDaemon 3.5.0 and earlier allows remote attackers to cause a denial of service via a long URL terminated by a "rn" string. Date published : 2001-02-02 http://www.securityfocus.com/bid/2134 http://archives.neohapsis.com/archives/bugtraq/2000-12/0315.html
IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query. Date published : 2001-02-02 http://www.securityfocus.com/bid/2067 http://www.securityfocus.com/archive/1/149207