2001-07-18 | CVE-2001-1030 | Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning. | 7.5 |
2001-07-17 | CVE-2001-0980 | Unspecified vulnerability in Caldera Openlinux Server and Openlinux Workstation docview before 1.0-15 allows remote attackers to execute arbitrary commands via shell metacharacters that are processed when converting a man page to a web page. | 7.5 |
2001-06-27 | CVE-2001-1164 | Local Security vulnerability in Caldera Unixware 7.0 Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt. | 7.2 |
2001-06-08 | CVE-2001-1359 | Authentication Failure Hijacking vulnerability in Volution Client Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server. network low complexity caldera critical | 10.0 |
2001-03-26 | CVE-2001-0181 | Unspecified vulnerability in Caldera products Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrary commands. network low complexity caldera critical | 10.0 |
2001-03-26 | CVE-2001-0178 | kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges. | 2.1 |
2001-03-12 | CVE-2001-0139 | inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations. | 1.2 |
2001-01-09 | CVE-2000-1134 | Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack. | 7.2 |
2000-12-19 | CVE-2000-0917 | Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. | 10.0 |
2000-11-14 | CVE-2000-0844 | Permissions, Privileges, and Access Controls vulnerability in multiple products Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. | 10.0 |