Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2001-06-23 CVE-2001-1162 Remote Arbitrary File Creation vulnerability in Samba
Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a ..
network
low complexity
samba hp
critical
10.0
2001-06-21 CVE-2001-1078 Remote Format String vulnerability in eXtremail
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.
network
low complexity
extremail
critical
10.0
2001-06-18 CVE-2001-0414 Remote Buffer Overflow vulnerability in Dave Mills Ntpd and Xntp3
Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.
network
low complexity
dave-mills
critical
10.0
2001-06-18 CVE-2001-0372 Unspecified vulnerability in Akopia Interchange 4.5.3
Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.
network
low complexity
akopia
critical
10.0
2001-06-18 CVE-2001-0249 Incorrect Calculation of Buffer Size vulnerability in multiple products
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
network
low complexity
hp oracle sgi CWE-131
critical
9.8
2001-06-18 CVE-2001-0248 Incorrect Calculation of Buffer Size vulnerability in multiple products
Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.
network
low complexity
sgi hp CWE-131
critical
9.8
2001-06-18 CVE-2001-0247 Buffer Overflow vulnerability in Multiple Vendor BSD ftpd glob()
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.
network
low complexity
mit sgi freebsd netbsd openbsd
critical
10.0
2001-06-16 CVE-2001-1163 Remote Buffer Overflow vulnerability in Munica Netsql 1.0
Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.
network
low complexity
munica
critical
10.0
2001-06-08 CVE-2001-1359 Authentication Failure Hijacking vulnerability in Volution Client
Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server.
network
low complexity
caldera
critical
10.0
2001-06-02 CVE-2001-1046 Buffer Overflow vulnerability in Qualcomm Qpopper 4.0/4.0.1/4.0.2
Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain privileges via a long username.
network
low complexity
qualcomm
critical
10.0