Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2001-08-31 CVE-2001-0971 Directory Traversal vulnerability in ACI 4D Webserver 6.5.7
Directory traversal vulnerability in ACI 4d webserver allows remote attackers to read arbitrary files via a ..
network
low complexity
aci
5.0
2001-08-31 CVE-2001-0970 Unspecified vulnerability in Tdavid TD Forum 1.2
Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script.
network
low complexity
tdavid
7.5
2001-08-31 CVE-2001-0969 Unspecified vulnerability in Freebsd 4.3
ipfw in FreeBSD does not properly handle the use of "me" in its rules when point to point interfaces are used, which causes ipfw to allow connections from arbitrary remote hosts.
network
low complexity
freebsd
critical
10.0
2001-08-31 CVE-2001-0968 Unspecified vulnerability in Knox Software Arkeia 4.2/4.2.8.2
Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges.
network
low complexity
knox-software
critical
10.0
2001-08-31 CVE-2001-0967 Use of Password Hash With Insufficient Computational Effort vulnerability in Arkeia 4.2/4.2.82
Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.
network
low complexity
arkeia CWE-916
critical
9.8
2001-08-31 CVE-2001-0966 Unspecified vulnerability in Nudester.Org Nudester
Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a ..
network
low complexity
nudester-org
critical
10.0
2001-08-31 CVE-2001-0965 Denial of Service vulnerability in glFTPD LIST
glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.
network
low complexity
glftpd
5.0
2001-08-31 CVE-2001-0943 Unspecified vulnerability in Oracle Database Server 8.0.5/8.1.5
dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse programs.
local
low complexity
oracle
7.2
2001-08-31 CVE-2001-0711 Unspecified vulnerability in Cisco IOS 11/12.0
Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management Interface (ILMI) SNMP community string.
network
low complexity
cisco
5.0
2001-08-31 CVE-2000-1202 Unspecified vulnerability in IBM Http Server SSL Module Common 1.0
ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.
local
low complexity
ibm
7.2