Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2001-07-02 CVE-2001-0430 Unspecified vulnerability in Debian Linux
Vulnerability in exuberant-ctags before 3.2.4-0.1 insecurely creates temporary files.
local
low complexity
debian
3.6
2001-07-02 CVE-2001-0429 Unspecified vulnerability in Cisco Catos
Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service.
network
low complexity
cisco
5.0
2001-07-02 CVE-2001-0428 Unspecified vulnerability in Cisco VPN 3000 Concentrator Series Software
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option.
network
low complexity
cisco
5.0
2001-07-02 CVE-2001-0426 Unspecified vulnerability in SUN Solaris and Sunos
Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.
local
low complexity
sun
7.2
2001-07-02 CVE-2001-0424 BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.
local
low complexity
timecop freebsd
7.2
2001-07-02 CVE-2001-0423 Buffer Overflow vulnerability in SUN Solaris 7.0
Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.
local
low complexity
sun
7.2
2001-07-02 CVE-2001-0422 Buffer Overflow vulnerability in SUN Solaris and Sunos
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
local
low complexity
sun
7.2
2001-07-02 CVE-2001-0421 Unspecified vulnerability in SUN Solaris and Sunos
FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.
network
low complexity
sun
6.4
2001-07-02 CVE-2001-0419 Unspecified vulnerability in Oracle Application Server 4.0.8.2
Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.
network
low complexity
oracle
7.5
2001-07-02 CVE-2001-0418 Unspecified vulnerability in NCM Content Management System
content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.
network
low complexity
ncm
5.0