Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2001-03-12 CVE-2001-0140 arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
local
high complexity
immunix mandrakesoft redhat
1.2
2001-03-12 CVE-2001-0139 inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
local
high complexity
caldera immunix debian mandrakesoft redhat
1.2
2001-03-12 CVE-2001-0138 privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.
local
high complexity
immunix debian mandrakesoft redhat
1.2
2001-03-12 CVE-2001-0137 Unspecified vulnerability in Microsoft Windows Media Player 7
Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file named skin.wmz, then referencing that skin in the codebase parameter to an applet tag, aka the Windows Media Player Skins File Download" vulnerability.
network
high complexity
microsoft
5.1
2001-03-12 CVE-2001-0135 Unspecified vulnerability in Ultrascripts Ultraboard 2.11
The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.
local
low complexity
ultrascripts
2.1
2001-03-12 CVE-2001-0134 Buffer Overflow vulnerability in Compaq Web Admin
Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.
network
low complexity
compaq digital
critical
10.0
2001-03-12 CVE-2001-0133 Unspecified vulnerability in Trend Micro Interscan Viruswall 3.0.1
The web administration interface for Interscan VirusWall 3.6.x and earlier does not use encryption, which could allow remote attackers to obtain the administrator password to sniff the administrator password via the setpasswd.cgi program or other HTTP GET requests that contain base64 encoded usernames and passwords.
network
low complexity
trend-micro
critical
10.0
2001-03-12 CVE-2001-0132 Unspecified vulnerability in Trend Micro Interscan Viruswall 3.0.1
Interscan VirusWall 3.6.x and earlier follows symbolic links when uninstalling the product, which allows local users to overwrite arbitrary files via a symlink attack.
local
high complexity
trend-micro
1.2
2001-03-12 CVE-2001-0131 htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
local
high complexity
apache immunix redhat
1.2
2001-03-12 CVE-2001-0130 Denial-Of-Service vulnerability in Domino R5 Server
Buffer overflow in HTML parser of the Lotus R5 Domino Server before 5.06, and Domino Client before 5.05, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed font size specifier.
network
low complexity
lotus
critical
10.0