Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2001-06-18 CVE-2001-0374 Security Bypass vulnerability in Web-Enabled Management
The HTTP server in Compaq web-enabled management software for (1) Foundation Agents, (2) Survey, (3) Power Manager, (4) Availability Agents, (5) Intelligent Cluster Administrator, and (6) Insight Manager can be used as a generic proxy server, which allows remote attackers to bypass access restrictions via the management port, 2301.
network
low complexity
compaq
7.5
2001-06-18 CVE-2001-0373 Unspecified vulnerability in Microsoft Windows 2000 and Windows NT
The default configuration of the Dr.
local
low complexity
microsoft
2.1
2001-06-18 CVE-2001-0372 Unspecified vulnerability in Akopia Interchange 4.5.3
Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.
network
low complexity
akopia
critical
10.0
2001-06-18 CVE-2001-0371 Unspecified vulnerability in Freebsd
Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted information.
local
high complexity
freebsd
6.2
2001-06-18 CVE-2001-0265 Unspecified vulnerability in PGP 5
ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file.
local
low complexity
pgp
2.1
2001-06-18 CVE-2001-0264 Unspecified vulnerability in Gene6 G6 FTP Server 2.0
Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.
network
low complexity
gene6
5.0
2001-06-18 CVE-2001-0263 Unspecified vulnerability in Gene6 G6 FTP Server 2.0
Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.
network
low complexity
gene6
7.5
2001-06-18 CVE-2001-0249 Incorrect Calculation of Buffer Size vulnerability in multiple products
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
network
low complexity
hp oracle sgi CWE-131
critical
9.8
2001-06-18 CVE-2001-0248 Incorrect Calculation of Buffer Size vulnerability in multiple products
Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.
network
low complexity
sgi hp CWE-131
critical
9.8
2001-06-18 CVE-2001-0247 Buffer Overflow vulnerability in Multiple Vendor BSD ftpd glob()
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.
network
low complexity
mit sgi freebsd netbsd openbsd
critical
10.0