Vulnerabilities > Caldera

DATE CVE VULNERABILITY TITLE RISK
2001-07-18 CVE-2001-1030 Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
network
low complexity
caldera immunix mandrakesoft squid redhat trustix
7.5
2001-07-17 CVE-2001-0980 Unspecified vulnerability in Caldera Openlinux Server and Openlinux Workstation
docview before 1.0-15 allows remote attackers to execute arbitrary commands via shell metacharacters that are processed when converting a man page to a web page.
network
low complexity
caldera
7.5
2001-06-27 CVE-2001-1164 Local Security vulnerability in Caldera Unixware 7.0
Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.
local
low complexity
caldera
7.2
2001-06-08 CVE-2001-1359 Authentication Failure Hijacking vulnerability in Volution Client
Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server.
network
low complexity
caldera
critical
10.0
2001-03-26 CVE-2001-0181 Unspecified vulnerability in Caldera products
Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrary commands.
network
low complexity
caldera
critical
10.0
2001-03-26 CVE-2001-0178 kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
local
low complexity
conectiva caldera mandrakesoft suse
2.1
2001-03-12 CVE-2001-0139 inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
local
high complexity
caldera immunix debian mandrakesoft redhat
1.2
2001-01-09 CVE-2000-1134 Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack. 7.2
2000-12-19 CVE-2000-0917 Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
network
low complexity
caldera redhat trustix
critical
10.0
2000-11-14 CVE-2000-0844 Permissions, Privileges, and Access Controls vulnerability in multiple products
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
10.0