Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2001-06-11 CVE-2001-1256 Symbolic Link vulnerability in HP Hp-Ux 11.00/11.04/11.11
kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.
local
high complexity
hp
1.2
2001-06-08 CVE-2001-1359 Authentication Failure Hijacking vulnerability in Volution Client
Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server.
network
low complexity
caldera
critical
10.0
2001-06-06 CVE-2001-1263 Denial of Service vulnerability in Pragma Systems Interaccess 4.0Build5
telnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large number of characters to port 23, possibly due to a buffer overflow.
network
low complexity
pragma-systems
5.0
2001-06-05 CVE-2001-1345 Unspecified vulnerability in Jetico Bestcrypt
bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program.
local
low complexity
jetico
4.6
2001-06-02 CVE-2001-1047 Denial Of Service vulnerability in OpenBSD Dup2 VFS Race Condition
Race condition in OpenBSD VFS allows local users to cause a denial of service (kernel panic) by (1) creating a pipe in one thread and causing another thread to set one of the file descriptors to NULL via a close, or (2) calling dup2 on a file descriptor in one process, then setting the descriptor to NULL via a close in another process that is created via rfork.
local
high complexity
openbsd
1.2
2001-06-02 CVE-2001-1046 Buffer Overflow vulnerability in Qualcomm Qpopper 4.0/4.0.1/4.0.2
Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain privileges via a long username.
network
low complexity
qualcomm
critical
10.0
2001-06-02 CVE-2001-0323 Denial-Of-Service vulnerability in Oracle Solaris
The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host.
network
low complexity
6.4
2001-06-02 CVE-2001-0322 Unspecified vulnerability in Microsoft Internet Explorer, Outlook and Outlook Express
MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.
network
low complexity
microsoft
5.0
2001-06-02 CVE-2001-0318 Unspecified vulnerability in Proftpd Project Proftpd 1.2.0Rc2
Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd).
network
low complexity
proftpd-project
7.5
2001-06-02 CVE-2001-0315 Remote Security vulnerability in mIRC
The locking feature in mIRC 5.7 allows local users to bypass the password mechanism by modifying the LockOptions registry key.
network
low complexity
khaled-mardam-bey
7.5