CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2001-0407

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).

    Published: 27 Jun 2001
    7.5
    High

    CVE-2001-0442

    Last Modified: 16 Apr 2026

    Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP command.

    Published: 27 Jun 2001
    4.6
    Medium

    CVE-2001-0449

    Last Modified: 16 Apr 2026

    Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail command line option.

    Published: 27 Jun 2001
    7.5
    High

    CVE-2001-0461

    Last Modified: 16 Apr 2026

    template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell metacharacters in the argument to template.cgi.

    Published: 27 Jun 2001
    5
    Medium

    CVE-2001-0462

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Published: 27 Jun 2001
    5
    Medium

    CVE-2001-0467

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a \... (modified dot dot) in an HTTP URL request.

    Published: 27 Jun 2001
    5
    Medium

    CVE-2001-0469

    Last Modified: 16 Apr 2026

    rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length.

    Published: 27 Jun 2001
    7.2
    High

    CVE-2001-0485

    Last Modified: 16 Apr 2026

    Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option.

    Published: 27 Jun 2001
    5
    Medium

    CVE-2001-0487

    Last Modified: 16 Apr 2026

    AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.

    Published: 27 Jun 2001
    2.1
    Low

    CVE-2001-0488

    Last Modified: 16 Apr 2026

    pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.

    Published: 27 Jun 2001
    7.5
    High

    CVE-2001-0494

    Last Modified: 16 Apr 2026

    Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header.

    Published: 27 Jun 2001
    5
    Medium

    CVE-2001-0495

    Last Modified: 16 Apr 2026

    Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack.

    Published: 27 Jun 2001
    5
    Medium

    CVE-2001-0493

    Last Modified: 16 Apr 2026

    Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.

    Published: 27 Jun 2001
    5
    Medium

    CVE-2001-0336

    Last Modified: 16 Apr 2026

    The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.

    Published: 27 Jun 2001
    7.5
    High

    CVE-2001-0455

    Last Modified: 16 Apr 2026

    Cisco Aironet 340 Series wireless bridge before 8.55 does not properly disable access to the web interface, which allows remote attackers to modify its configuration.

    Published: 27 Jun 2001
    7.2
    High

    CVE-2001-0481

    Last Modified: 16 Apr 2026

    Vulnerability in rpmdrake in Mandrake Linux 8.0 related to insecure temporary file handling.

    Published: 27 Jun 2001
    10
    Critical

    CVE-2001-0241

    Last Modified: 16 Apr 2026

    Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.

    Published: 27 Jun 2001
    5
    Medium

    CVE-2001-0245

    Last Modified: 16 Apr 2026

    Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.

    Published: 27 Jun 2001
    7.5
    High

    CVE-2001-0331

    Last Modified: 16 Apr 2026

    Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows remote attackers to execute arbitrary commands.

    Published: 27 Jun 2001
    7.5
    High

    CVE-2001-0333

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.

    Published: 27 Jun 2001
    4
    Medium

    CVE-2001-0361

    Last Modified: 16 Apr 2026

    Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a "Bleichenbacher attack" on PKCS#1 version 1.5.

    Published: 27 Jun 2001
    2.1
    Low

    CVE-2001-0378

    Last Modified: 16 Apr 2026

    readline prior to 4.1, in OpenBSD 2.8 and earlier, creates history files with insecure permissions, which allows a local attacker to recover potentially sensitive information via readline history files.

    Published: 27 Jun 2001
    5
    Medium

    CVE-2001-0457

    Last Modified: 16 Apr 2026

    man2html before 1.5-22 allows remote attackers to cause a denial of service (memory exhaustion).

    Published: 27 Jun 2001
    5
    Medium

    CVE-2001-0463

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.

    Published: 27 Jun 2001
    2.1
    Low

    CVE-2001-0474

    Last Modified: 16 Apr 2026

    Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file.

    Published: 27 Jun 2001
    5
    Medium

    CVE-2001-0237

    Last Modified: 16 Apr 2026

    Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.

    Published: 27 Jun 2001
    4.6
    Medium

    CVE-2001-0240

    Last Modified: 16 Apr 2026

    Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.

    Published: 27 Jun 2001
    7.5
    High

    CVE-2001-0244

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.

    Published: 27 Jun 2001
    7.5
    High

    CVE-2001-0330

    Last Modified: 16 Apr 2026

    Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.

    Published: 27 Jun 2001
    7.2
    High

    CVE-2001-0366

    Last Modified: 16 Apr 2026

    saposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse expand program.

    Published: 27 Jun 2001
    10
    Critical

    CVE-2001-0388

    Last Modified: 16 Apr 2026

    time server daemon timed allows remote attackers to cause a denial of service via malformed packets.

    Published: 27 Jun 2001
    7.5
    High

    CVE-2001-0456

    Last Modified: 16 Apr 2026

    postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended.

    Published: 27 Jun 2001
    7.5
    High

    CVE-2001-0475

    Last Modified: 16 Apr 2026

    index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.

    Published: 27 Jun 2001
    5
    Medium

    CVE-2001-0243

    Last Modified: 16 Apr 2026

    Windows Media Player 7 and earlier stores Internet shortcuts in a user's Temporary Files folder with a fixed filename instead of in the Internet Explorer cache, which causes the HTML in those shortcuts to run in the Local Computer Zone instead of the Internet Zone, which allows remote attackers to read certain files.

    Published: 27 Jun 2001
    5
    Medium

    CVE-2001-0335

    Last Modified: 16 Apr 2026

    FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters.

    Published: 27 Jun 2001
    7.2
    High

    CVE-2001-1164

    Last Modified: 16 Apr 2026

    Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.

    Published: 27 Jun 2001
    4.6
    Medium

    CVE-2001-1324

    Last Modified: 16 Apr 2026

    cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.

    Published: 26 Jun 2001
    5
    Medium

    CVE-2001-0784

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack using encoded URL characters.

    Published: 26 Jun 2001
    5
    Medium

    CVE-2001-1083

    Last Modified: 16 Apr 2026

    Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or \ (backward slash).

    Published: 26 Jun 2001
    10
    Critical

    CVE-2001-1162

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.

    Published: 23 Jun 2001
    7.5
    High

    CVE-2001-1328

    Last Modified: 16 Apr 2026

    Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.

    Published: 22 Jun 2001
    6.2
    Medium

    CVE-2001-0906

    Last Modified: 16 Apr 2026

    teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produced when printing .dvi files using lpr.

    Published: 22 Jun 2001
    10
    Critical

    CVE-2001-1078

    Last Modified: 16 Apr 2026

    Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.

    Published: 21 Jun 2001
    7.5
    High

    CVE-2001-1459

    Last Modified: 16 Apr 2026

    OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.

    Published: 19 Jun 2001
    10
    Critical

    CVE-2001-1080

    Last Modified: 16 Apr 2026

    diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.

    Published: 19 Jun 2001
    2.1
    Low

    CVE-2001-0265

    Last Modified: 16 Apr 2026

    ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file.

    Published: 18 Jun 2001
    2.1
    Low

    CVE-2001-0373

    Last Modified: 16 Apr 2026

    The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.

    Published: 18 Jun 2001
    5
    Medium

    CVE-2001-0375

    Last Modified: 16 Apr 2026

    Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests.

    Published: 18 Jun 2001
    5
    Medium

    CVE-2001-0383

    Last Modified: 16 Apr 2026

    banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication.

    Published: 18 Jun 2001
    4.6
    Medium

    CVE-2001-0379

    Last Modified: 16 Apr 2026

    Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.

    Published: 18 Jun 2001