Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2001-05-03 CVE-2001-0271 Unspecified vulnerability in Mailnews.Cgi
mailnews.cgi 1.3 and earlier allows remote attackers to execute arbitrary commands via a user name that contains shell metacharacters.
network
low complexity
mailnews-cgi
critical
10.0
2001-05-03 CVE-2001-0270 Denial Of Service vulnerability in Marconi Asx-1000 and Forethought
Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set.
network
low complexity
marconi
5.0
2001-05-03 CVE-2001-0269 Security Bypass vulnerability in SUN Sunos 5.8
pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password.
network
low complexity
sun
critical
10.0
2001-05-03 CVE-2001-0268 The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.
local
low complexity
netbsd openbsd
7.2
2001-05-03 CVE-2001-0267 Local Security vulnerability in HP MPE IX 5.5
NM debug in HP MPE/iX 6.5 and earlier does not properly handle breakpoints, which allows local users to gain privileges.
local
low complexity
hp
7.2
2001-05-03 CVE-2001-0266 Local Security vulnerability in HP-UX
Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges.
local
low complexity
hp
7.2
2001-05-03 CVE-2001-0236 Buffer Overflow vulnerability in SUN Solaris and Sunos
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.
network
low complexity
sun
critical
10.0
2001-05-03 CVE-2001-0234 SQL-Injection vulnerability in Sourceforge Newsdaemon 0.21B
NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.
network
low complexity
sourceforge
7.5
2001-05-03 CVE-2001-0229 Local Security vulnerability in SUN Chilisoft 3.5.2
Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts.
local
low complexity
sun
7.2
2001-05-03 CVE-2001-0228 Directory Traversal vulnerability in GoAhead WebServer
Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a ..
network
low complexity
goahead-software
5.0