Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2001-07-21 CVE-2001-0497 Incorrect Default Permissions vulnerability in ISC Bind
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.
local
low complexity
isc CWE-276
7.8
2001-07-16 CVE-2001-1238 Improper Handling of Case Sensitivity vulnerability in Microsoft Windows 2000
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.
local
low complexity
microsoft CWE-178
7.8
2001-07-12 CVE-2001-1291 Improper Restriction of Excessive Authentication Attempts vulnerability in 3Com Superstack II PS HUB 40 Firmware
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.
network
low complexity
3com CWE-307
critical
9.8
2001-07-02 CVE-2001-1042 Link Following vulnerability in Transsoft Broker FTP Server 5.9.5.0
Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.
network
low complexity
transsoft CWE-59
7.5
2001-07-02 CVE-2001-0395 Improper Restriction of Excessive Authentication Attempts vulnerability in Lightwavemo Consoleserver 3200 Firmware
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.
network
low complexity
lightwavemo CWE-307
critical
9.8
2001-07-01 CVE-2001-1386 Link Following vulnerability in Texasimperialsoftware Wftpd 3.00
WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension.
network
low complexity
texasimperialsoftware CWE-59
7.5
2001-07-01 CVE-2001-1043 Link Following vulnerability in Argosoft FTP Server 1.2.2.2
ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.
network
low complexity
argosoft CWE-59
7.5
2001-06-27 CVE-2001-0334 Incorrect Calculation of Buffer Size vulnerability in Microsoft Internet Information Server
FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.
network
low complexity
microsoft CWE-131
7.5
2001-06-18 CVE-2001-0249 Incorrect Calculation of Buffer Size vulnerability in multiple products
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
network
low complexity
hp oracle sgi CWE-131
critical
9.8
2001-06-18 CVE-2001-0248 Incorrect Calculation of Buffer Size vulnerability in multiple products
Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.
network
low complexity
sgi hp CWE-131
critical
9.8