Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2001-05-03 CVE-2001-0167 Buffer Overflow vulnerability in AT&T; WinVNC Client
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.
network
high complexity
att
7.6
2001-05-03 CVE-2001-0165 Unspecified vulnerability in SUN Solaris and Sunos
Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.
local
low complexity
sun
7.2
2001-05-03 CVE-2001-0154 Unspecified vulnerability in Microsoft Internet Explorer
HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.
network
low complexity
microsoft
7.5
2001-05-03 CVE-2001-0153 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Visual Basic and Visual Studio
Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.
network
low complexity
microsoft CWE-119
7.5
2001-05-03 CVE-2001-0152 Unspecified vulnerability in Microsoft Plus
The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password information to a file, which allows local users to recover the passwords and read the compressed folders.
local
low complexity
microsoft
2.1
2001-05-03 CVE-2001-0147 Unspecified vulnerability in Microsoft Windows 2000
Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records.
network
low complexity
microsoft
critical
10.0
2001-05-03 CVE-2001-0145 Unspecified vulnerability in Microsoft Outlook and Outlook Express
Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.
network
low complexity
microsoft
7.5
2001-04-21 CVE-2001-1442 Buffer Overflow vulnerability in innfeed Command-Line
Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privileges via a long -c command line argument.
local
low complexity
isc
4.6
2001-04-17 CVE-2001-1400 Denial-Of-Service vulnerability in kernel
Unknown vulnerabilities in the UDP port allocation for Linux kernel before 2.2.19 could allow local users to cause a denial of service (deadlock).
local
low complexity
linux
2.1
2001-04-17 CVE-2001-1399 Local Security vulnerability in kernel
Certain operations in Linux kernel before 2.2.19 on the x86 architecture copy the wrong number of bytes, which might allow attackers to modify memory, aka "User access asm bug on x86."
local
low complexity
linux
2.1