20 results (0.003 seconds)

CVSS: 10.0EPSS: 0%CPEs: 38EXPL: 1

15 Mar 2002 — Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. Error 'off-by-one' en el código de canal de OpenSSH 2.0 a 3.0.2 permite a usuarios locales o a servidores remotos ganar privilegios. • https://www.exploit-db.com/exploits/21314 • CWE-193: Off-by-one Error •

CVSS: 7.5EPSS: 0%CPEs: 5EXPL: 0

18 Oct 2001 — LogLine function in klogd in sysklogd 1.3 in various Linux distributions allows an attacker to cause a denial of service (hang) by causing null bytes to be placed in log messages. • http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-026-01 •

CVSS: 5.5EPSS: 0%CPEs: 12EXPL: 1

12 Oct 2001 — Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack. • https://www.exploit-db.com/exploits/20493 •

CVSS: 7.8EPSS: 0%CPEs: 13EXPL: 2

20 Sep 2001 — Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group man via a long -S option. • https://www.exploit-db.com/exploits/20843 •

CVSS: 9.1EPSS: 0%CPEs: 15EXPL: 0

18 Jul 2001 — Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning. • http://archives.neohapsis.com/archives/bugtraq/2001-07/0362.html •

CVSS: 6.5EPSS: 0%CPEs: 8EXPL: 0

27 Jun 2001 — sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users to read files that are being processed by sgml-tools. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000390 •

CVSS: 9.8EPSS: 0%CPEs: 15EXPL: 0

27 Jun 2001 — Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands. • http://archives.neohapsis.com/archives/bugtraq/2001-03/0246.html •

CVSS: 5.5EPSS: 0%CPEs: 13EXPL: 2

26 Mar 2001 — glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files. • https://www.exploit-db.com/exploits/258 •

CVSS: 5.5EPSS: 0%CPEs: 7EXPL: 0

12 Mar 2001 — gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack. • http://marc.info/?l=bugtraq&m=97916374410647&w=2 •

CVSS: 5.5EPSS: 0%CPEs: 10EXPL: 0

12 Mar 2001 — sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack. • http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2000-70-028-01 •