Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2001-12-06 | CVE-2001-0830 | Missing Release of Resource after Effective Lifetime vulnerability in 6Tunnel Project 6Tunnel 0.08 6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to and disconnecting from the server. | 7.5 |
2001-12-04 | CVE-2001-0950 | Insufficient Entropy vulnerability in Valicert Enterprise Validation Authority 3.3/4.2.1 ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing. | 7.5 |
2001-10-18 | CVE-2001-0795 | Improper Handling of Case Sensitivity vulnerability in Cmfperception Liteserve 1.25 Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names. | 7.5 |
2001-10-18 | CVE-2001-0766 | Improper Handling of Case Sensitivity vulnerability in Apache Http Server 1.3.14 Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters. | 9.8 |
2001-10-05 | CVE-2001-1125 | Download of Code Without Integrity Check vulnerability in Symantec Liveupdate 1.0/1.4/1.5 Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site. | 9.8 |
2001-08-31 | CVE-2001-1452 | Origin Validation Error vulnerability in Microsoft Windows 2000 and Windows NT By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses. | 7.5 |
2001-08-31 | CVE-2001-0967 | Use of Password Hash With Insufficient Computational Effort vulnerability in Arkeia 4.2/4.2.82 Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing. | 9.8 |
2001-08-31 | CVE-2000-1198 | Improper Locking vulnerability in Qualcomm Qpopper 2.53/3.0 qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes. | 5.5 |
2001-08-29 | CVE-2001-0682 | Improper Locking vulnerability in multiple products ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting. | 5.5 |
2001-08-23 | CVE-2001-1155 | Incorrect Authorization vulnerability in Freebsd 4.1.1/4.2/4.3 TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spoofing. | 9.8 |