Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2001-03-26 CVE-2001-0170 glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.
local
low complexity
immunix conectiva debian redhat
2.1
2001-03-26 CVE-2001-0169 When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
local
low complexity
mandrakesoft redhat trustix turbolinux
2.1
2001-03-26 CVE-2001-0166 Unspecified vulnerability in Macromedia Shockwave Flash Plugin 6.0/7.0/8.0
Macromedia Shockwave Flash plugin version 8 and earlier allows remote attackers to cause a denial of service via malformed tag length specifiers in a SWF file.
network
high complexity
macromedia
7.6
2001-03-13 CVE-2001-1230 Unspecified vulnerability in Icecast
Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.
network
low complexity
icecast
7.5
2001-03-13 CVE-2001-0122 Unspecified vulnerability in IBM Http Server and Websphere Application Server
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
network
low complexity
ibm
5.0
2001-03-12 CVE-2001-1229 Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.
network
low complexity
icecast libshout
7.5
2001-03-12 CVE-2001-0144 CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.
network
low complexity
openbsd ssh
critical
10.0
2001-03-12 CVE-2001-0143 vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.
local
high complexity
immunix redhat
1.2
2001-03-12 CVE-2001-0142 squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations. 1.2
2001-03-12 CVE-2001-0141 Unspecified vulnerability in Gert Doering Mgetty 1.1.22
mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
local
high complexity
gert-doering
1.2