Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2001-12-31 CVE-2001-1546 Inadequate Encryption Strength vulnerability in Mckesson Pathways Homecare 6.5
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file.
local
low complexity
mckesson CWE-326
7.8
2001-12-31 CVE-2001-1537 Cleartext Storage of Sensitive Information vulnerability in Symfony Twig
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
network
low complexity
symfony CWE-312
7.5
2001-12-31 CVE-2001-1536 Cleartext Storage of Sensitive Information vulnerability in Audiogalaxy
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.
network
low complexity
audiogalaxy CWE-312
7.5
2001-12-31 CVE-2001-1515 Improper Preservation of Permissions vulnerability in Microsoft Windows 2000
Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended.
network
low complexity
microsoft CWE-281
7.5
2001-12-06 CVE-2001-0830 Missing Release of Resource after Effective Lifetime vulnerability in 6Tunnel Project 6Tunnel 0.08
6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to and disconnecting from the server.
network
low complexity
6tunnel-project CWE-772
7.5
2001-12-04 CVE-2001-0950 Insufficient Entropy vulnerability in Valicert Enterprise Validation Authority 3.3/4.2.1
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.
network
low complexity
valicert CWE-331
7.5
2001-10-18 CVE-2001-0795 Improper Handling of Case Sensitivity vulnerability in Cmfperception Liteserve 1.25
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names.
network
low complexity
cmfperception CWE-178
7.5
2001-08-31 CVE-2001-1452 Origin Validation Error vulnerability in Microsoft Windows 2000 and Windows NT
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.
network
low complexity
microsoft CWE-346
7.5
2001-07-31 CVE-2001-1471 Improper Initialization vulnerability in PHPbb 1.4.0
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.
network
low complexity
phpbb CWE-665
8.8
2001-07-21 CVE-2001-0497 Incorrect Default Permissions vulnerability in ISC Bind
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.
local
low complexity
isc CWE-276
7.8