Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2001-12-31 CVE-2001-1537 Cleartext Storage of Sensitive Information vulnerability in Symfony Twig
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
network
low complexity
symfony CWE-312
7.5
2001-12-31 CVE-2001-1536 Cleartext Storage of Sensitive Information vulnerability in Audiogalaxy
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.
network
low complexity
audiogalaxy CWE-312
7.5
2001-12-31 CVE-2001-1515 Improper Preservation of Permissions vulnerability in Microsoft Windows 2000
Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended.
network
low complexity
microsoft CWE-281
7.5
2001-12-31 CVE-2001-1496 Off-by-one Error vulnerability in Acme Thttpd
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
network
low complexity
acme CWE-193
critical
9.8
2001-12-31 CVE-2001-1494 Link Following vulnerability in multiple products
script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.
local
low complexity
kernel avaya CWE-59
5.5
2001-12-31 CVE-2001-1481 Cleartext Storage of Sensitive Information vulnerability in Xitami 2.4/2.5
Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.
network
low complexity
xitami CWE-312
critical
9.8
2001-12-06 CVE-2001-0830 Missing Release of Resource after Effective Lifetime vulnerability in 6Tunnel Project 6Tunnel 0.08
6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to and disconnecting from the server.
network
low complexity
6tunnel-project CWE-772
7.5
2001-12-04 CVE-2001-0950 Insufficient Entropy vulnerability in Valicert Enterprise Validation Authority 3.3/4.2.1
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.
network
low complexity
valicert CWE-331
7.5
2001-10-18 CVE-2001-0795 Improper Handling of Case Sensitivity vulnerability in Cmfperception Liteserve 1.25
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names.
network
low complexity
cmfperception CWE-178
7.5
2001-10-18 CVE-2001-0766 Improper Handling of Case Sensitivity vulnerability in Apache Http Server 1.3.14
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
network
low complexity
apache CWE-178
critical
9.8