Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2001-07-11 CVE-2001-1146 Unspecified vulnerability in LEE Herron Allcommerce 1.2.3
AllCommerce with debugging enabled in EnGarde Secure Linux 1.0.1 creates temporary files with predictable names, which allows local users to modify files via a symlink attack.
local
high complexity
lee-herron
1.2
2001-07-11 CVE-2001-1144 Directory Traversal vulnerability in Mcafee Asap Virusscan 1.0
Directory traversal vulnerability in McAfee ASaP VirusScan agent 1.0 allows remote attackers to read arbitrary files via a ..
network
low complexity
mcafee
5.0
2001-07-11 CVE-2001-1143 Denial of Service vulnerability in IBM DB2 Universal Database 7.0
IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.
network
low complexity
ibm
5.0
2001-07-11 CVE-2001-1120 Unspecified vulnerability in Allaire Coldfusion Server
Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates.
network
low complexity
allaire
6.4
2001-07-11 CVE-2001-1038 Denial of Service vulnerability in Cisco SN 5420 Storage Router
Cisco SN 5420 Storage Router 1.1(3) and earlier allows remote attackers to cause a denial of service (reboot) via a series of connections to TCP port 8023.
network
low complexity
cisco
5.0
2001-07-10 CVE-2001-1322 Unspecified vulnerability in Xinetd
xinetd 2.1.8 and earlier runs with a default umask of 0, which could allow local users to read or modify files that are created by an application that runs under xinetd but does not set its own safe umask.
local
low complexity
xinetd
3.6
2001-07-10 CVE-2001-1180 Unspecified vulnerability in Freebsd
FreeBSD 4.3 does not properly clear shared signal handlers when executing a process, which allows local users to gain privileges by calling rfork with a shared signal handler, having the child process execute a setuid program, and sending a signal to the child.
local
low complexity
freebsd
7.2
2001-07-10 CVE-2001-1141 The Pseudo-Random Number Generator (PRNG) in SSLeay and OpenSSL before 0.9.6b allows attackers to use the output of small PRNG requests to determine the internal state information, which could be used by attackers to predict future pseudo-random numbers.
network
low complexity
openssl ssleay
5.0
2001-07-09 CVE-2001-1245 Unspecified vulnerability in Opera Software Opera web Browser 5.0
Opera 5.0 for Linux does not properly handle malformed HTTP headers, which allows remote attackers to cause a denial of service, possibly with a header whose value is the same as a MIME header name.
network
low complexity
opera-software
5.0
2001-07-09 CVE-2001-1158 Unspecified vulnerability in Checkpoint Firewall-1 4.1/4.1Build41439
Check Point VPN-1/FireWall-1 4.1 base.def contains a default macro, accept_fw1_rdp, which can allow remote attackers to bypass intended restrictions with forged RDP (internal protocol) headers to UDP port 259 of arbitrary hosts.
network
low complexity
checkpoint
7.5