Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2001-08-31 CVE-2001-1005 Unspecified vulnerability in Starfish Truesync Desktop 2.0B
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registry key to decrypt the password and gain privileges.
network
low complexity
starfish
7.5
2001-08-31 CVE-2001-1004 Cross-Site Scripting vulnerability in Gnutella Client
Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name contains the script tags.
network
low complexity
gnutella
5.0
2001-08-31 CVE-2001-1003 Local Security vulnerability in Webct Respondus 1.1.2
Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can read the WEBCT.SVR file to decrypt the passwords and gain additional privileges.
local
low complexity
webct
4.6
2001-08-31 CVE-2001-1002 Remote Command Execution vulnerability in Redhat Linux 6.2/7.0/7.1
The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains malicious commands.
network
low complexity
redhat
7.5
2001-08-31 CVE-2001-0995 Unspecified vulnerability in PHPprojekt
PHProjekt before 2.4a allows remote attackers to perform actions as other PHProjekt users by modifying the ID number in an HTTP request to PHProjekt CGI programs.
network
low complexity
phpprojekt
7.5
2001-08-31 CVE-2001-0983 Local Security vulnerability in Ultraedit-32
UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read the file to decrypt the passwords and gain privileges.
local
low complexity
ultraedit
4.6
2001-08-31 CVE-2001-0981 Unspecified vulnerability in HP Cifs-9000 Server A.01.05/A.01.06/A.01.07
HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user.
network
low complexity
hp
critical
10.0
2001-08-31 CVE-2001-0976 Local Security vulnerability in Process Resource Manager C.01.07/C.01.08.02/C.01.08.2
Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables.
local
low complexity
hp
7.2
2001-08-31 CVE-2001-0973 Symbolic Link File Disclosure vulnerability in BSCW
BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space.
network
low complexity
fraunhofer-fit
6.4
2001-08-31 CVE-2001-0972 Unspecified vulnerability in Surf-Net ASP Forum 2.20
Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e.
network
low complexity
surf-net
critical
10.0