Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2002-03-15 CVE-2002-0083 Off-by-one Error vulnerability in multiple products
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
9.8
2002-03-15 CVE-2002-0059 Double Free vulnerability in Zlib
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary code via a block of malformed compression data.
network
low complexity
zlib CWE-415
critical
9.8
2001-12-31 CVE-2001-1559 NULL Pointer Dereference vulnerability in Openbsd 2.9/3.0
The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigger a null dereference.
local
low complexity
openbsd CWE-476
5.5
2001-12-31 CVE-2001-1546 Inadequate Encryption Strength vulnerability in Mckesson Pathways Homecare 6.5
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file.
local
low complexity
mckesson CWE-326
7.8
2001-12-31 CVE-2001-1537 Cleartext Storage of Sensitive Information vulnerability in Symfony Twig
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
network
low complexity
symfony CWE-312
7.5
2001-12-31 CVE-2001-1536 Cleartext Storage of Sensitive Information vulnerability in Audiogalaxy
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.
network
low complexity
audiogalaxy CWE-312
7.5
2001-12-31 CVE-2001-1515 Improper Preservation of Permissions vulnerability in Microsoft Windows 2000
Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended.
network
low complexity
microsoft CWE-281
7.5
2001-12-31 CVE-2001-1496 Off-by-one Error vulnerability in Acme Thttpd
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
network
low complexity
acme CWE-193
critical
9.8
2001-12-31 CVE-2001-1494 Link Following vulnerability in multiple products
script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.
local
low complexity
kernel avaya CWE-59
5.5
2001-12-31 CVE-2001-1481 Cleartext Storage of Sensitive Information vulnerability in Xitami 2.4/2.5
Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.
network
low complexity
xitami CWE-312
critical
9.8