CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2001-0719

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file.

    Published: 6 Dec 2001
    10
    Critical

    CVE-2001-0803

    Last Modified: 16 Apr 2026

    Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.

    Published: 6 Dec 2001
    3.6
    Low

    CVE-2001-0806

    Last Modified: 16 Apr 2026

    Apple MacOS X 10.0 and 10.1 allow a local user to read and write to a user's desktop folder via insecure default permissions for the Desktop when it is created in some languages.

    Published: 6 Dec 2001
    4.6
    Medium

    CVE-2001-1272

    Last Modified: 16 Apr 2026

    wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option.

    Published: 6 Dec 2001
    7.5
    High

    CVE-2001-0720

    Last Modified: 16 Apr 2026

    Internet Explorer 5.1 for Macintosh on Mac OS X allows remote attackers to execute arbitrary commands by causing a BinHex or MacBinary file type to be downloaded, which causes the files to be executed if automatic decoding is enabled.

    Published: 6 Dec 2001
    7.2
    High

    CVE-2001-0801

    Last Modified: 16 Apr 2026

    lpstat in IRIX 6.5.13f and earlier allows local users to gain root privileges by specifying a Trojan Horse nettype shared library.

    Published: 6 Dec 2001
    7.5
    High

    CVE-2001-0815

    Last Modified: 16 Apr 2026

    Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request for a long filename that ends in a .pl extension.

    Published: 6 Dec 2001
    5.1
    Medium

    CVE-2001-0828

    Last Modified: 16 Apr 2026

    A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which causes an error message that does not properly quote the Javascript.

    Published: 6 Dec 2001
    7.5
    High

    CVE-2001-0860

    Last Modified: 16 Apr 2026

    Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Address Translation (NAT).

    Published: 6 Dec 2001
    5
    Medium

    CVE-2001-0861

    Last Modified: 16 Apr 2026

    Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic that generates a large number of ICMP Unreachable replies.

    Published: 6 Dec 2001
    7.5
    High

    CVE-2001-0865

    Last Modified: 16 Apr 2026

    Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not support the "fragment" keyword in an outgoing ACL, which could allow fragmented packets in violation of the intended access.

    Published: 6 Dec 2001
    7.5
    High

    CVE-2001-0866

    Last Modified: 16 Apr 2026

    Cisco 12000 with IOS 12.0 and lines card based on Engine 2 does not properly handle an outbound ACL when an input ACL is not configured on all the interfaces of a multi port line card, which could allow remote attackers to bypass the intended access controls.

    Published: 6 Dec 2001
    7.5
    High

    CVE-2001-0836

    Last Modified: 16 Apr 2026

    Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Published: 6 Dec 2001
    7.5
    High

    CVE-2001-0864

    Last Modified: 16 Apr 2026

    Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions.

    Published: 6 Dec 2001
    5
    Medium

    CVE-2001-0663

    Last Modified: 16 Apr 2026

    Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.

    Published: 6 Dec 2001
    10
    Critical

    CVE-2001-0850

    Last Modified: 16 Apr 2026

    A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allow local or remote users to exploit those functions with a buffer overflow.

    Published: 6 Dec 2001
    7.5
    High

    CVE-2001-0857

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter.

    Published: 6 Dec 2001
    3.6
    Low

    CVE-2001-0946

    Last Modified: 16 Apr 2026

    apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification dates of arbitrary files via a symlink attack on the LOW_POWER temporary file, which could be used to cause a denial of service, e.g. by creating /etc/nologin and disabling logins.

    Published: 4 Dec 2001
    7.5
    High

    CVE-2001-0948

    Last Modified: 16 Apr 2026

    Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the certificate is viewed.

    Published: 4 Dec 2001
    7.5
    High

    CVE-2001-0949

    Last Modified: 16 Apr 2026

    Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6) maxConnPerSite, (7) maxMsgLen, (8) exitTime, (9) blockTime, (10) nextUpdatePeriod, (11) buildLocal, (12) maxOCSPValidityPeriod, (13) extension, and (14) a particular combination of parameters associated with private key generation that form a string of a certain length.

    Published: 4 Dec 2001
    7.5
    High

    CVE-2001-0950

    Last Modified: 16 Apr 2026

    ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.

    Published: 4 Dec 2001
    7.5
    High

    CVE-2001-0947

    Last Modified: 16 Apr 2026

    Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path.

    Published: 4 Dec 2001
    7.2
    High

    CVE-2001-0872

    Last Modified: 16 Apr 2026

    OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.

    Published: 4 Dec 2001
    5
    Medium

    CVE-2001-0945

    Last Modified: 16 Apr 2026

    Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line.

    Published: 3 Dec 2001
    7.2
    High

    CVE-2001-0944

    Last Modified: 16 Apr 2026

    DDE in mIRC allows local users to launch applications under another user's account via a DDE message that executes a command, which may be executed by the other user's process.

    Published: 2 Dec 2001
    7.5
    High

    CVE-2001-1437

    Last Modified: 16 Apr 2026

    easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out.

    Published: 1 Dec 2001
    5
    Medium

    CVE-2001-0870

    Last Modified: 16 Apr 2026

    HTTP server in Alchemy Eye and Alchemy Network Monitor 1.9x through 2.6.18 is enabled without authentication by default, which allows remote attackers to obtain network monitoring logs with potentially sensitive information by directly requesting the eye.ini file.

    Published: 30 Nov 2001
    7.5
    High

    CVE-2001-0937

    Last Modified: 16 Apr 2026

    PGPMail.pl 1.31 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) recipient or (2) pgpuserid parameters.

    Published: 30 Nov 2001
    7.2
    High

    CVE-2001-0912

    Last Modified: 16 Apr 2026

    Packaging error for expect 8.3.3 in Mandrake Linux 8.1 causes expect to search for its libraries in the /home/snailtalk directory before other directories, which could allow a local user to gain root privileges.

    Published: 30 Nov 2001
    5
    Medium

    CVE-2001-0896

    Last Modified: 16 Apr 2026

    Inetd in OpenServer 5.0.5 allows remote attackers to cause a denial of service (crash) via a port scan, e.g. with nmap -PO.

    Published: 30 Nov 2001
    7.5
    High

    CVE-2001-0936

    Last Modified: 16 Apr 2026

    Buffer overflow in Frox transparent FTP proxy 0.6.6 and earlier, with the local caching method selected, allows remote FTP servers to run arbitrary code via a long response to an MDTM request.

    Published: 30 Nov 2001
    6.4
    Medium

    CVE-2001-0938

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in AspUpload 2.1, in certain configurations, allows remote attackers to upload and read arbitrary files, and list arbitrary directories, via a .. (dot dot) in the Filename parameter in (1) UploadScript11.asp or (2) DirectoryListing.asp.

    Published: 30 Nov 2001
    5
    Medium

    CVE-2001-0939

    Last Modified: 16 Apr 2026

    Lotus Domino 5.08 and earlier allows remote attackers to cause a denial of service (crash) via a SunRPC NULL command to port 443.

    Published: 30 Nov 2001
    4.6
    Medium

    CVE-2001-0941

    Last Modified: 16 Apr 2026

    Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable.

    Published: 30 Nov 2001
    7.5
    High

    CVE-2001-0871

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor allows remote attackers to execute arbitrary commands via an HTTP request containing (1) a .. in versions 2.0 through 2.6.18, or (2) a DOS device name followed by a .. in versions 2.6.19 through 3.0.10.

    Published: 30 Nov 2001
    4.6
    Medium

    CVE-2001-0942

    Last Modified: 16 Apr 2026

    dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a malicious version of dbsnmp.

    Published: 29 Nov 2001
    7.5
    High

    CVE-2001-1449

    Last Modified: 16 Apr 2026

    The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.

    Published: 28 Nov 2001
    5
    Medium

    CVE-2001-0868

    Last Modified: 16 Apr 2026

    Red Hat Stronghold 2.3 to 3.0 allows remote attackers to retrieve system information via an HTTP GET request to (1) stronghold-info or (2) stronghold-status.

    Published: 28 Nov 2001
    5
    Medium

    CVE-2001-0926

    Last Modified: 16 Apr 2026

    SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web root via an HTTP request for a non-existent SSI page, in which the request's body has an #include statement.

    Published: 28 Nov 2001
    7.5
    High

    CVE-2001-0933

    Last Modified: 16 Apr 2026

    Cooolsoft PowerFTP Server 2.03 allows remote attackers to list the contents of arbitrary drives via a ls (LIST) command that includes the drive letter as an argument, e.g. "ls C:".

    Published: 28 Nov 2001
    7.5
    High

    CVE-2001-0934

    Last Modified: 16 Apr 2026

    Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname.

    Published: 28 Nov 2001
    7.5
    High

    CVE-2001-0928

    Last Modified: 16 Apr 2026

    Buffer overflow in the permitted function of GNOME gtop daemon (libgtop_daemon) in libgtop 1.0.13 and earlier may allow remote attackers to execute arbitrary code via long authentication data.

    Published: 28 Nov 2001
    7.5
    High

    CVE-2001-0929

    Last Modified: 16 Apr 2026

    Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists.

    Published: 28 Nov 2001
    7.5
    High

    CVE-2001-0930

    Last Modified: 16 Apr 2026

    Sendpage.pl allows remote attackers to execute arbitrary commands via a message containing shell metacharacters.

    Published: 28 Nov 2001
    7.5
    High

    CVE-2001-0931

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Cooolsoft PowerFTP Server 2.03 allows attackers to list or read arbitrary files and directories via a .. (dot dot) in (1) LS or (2) GET.

    Published: 28 Nov 2001
    7.5
    High

    CVE-2001-0932

    Last Modified: 16 Apr 2026

    Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long command.

    Published: 28 Nov 2001
    7.5
    High

    CVE-2001-0935

    Last Modified: 16 Apr 2026

    Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CVE-2001-0550.

    Published: 28 Nov 2001
    5.1
    Medium

    CVE-2001-0884

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.

    Published: 28 Nov 2001
    7.5
    High

    CVE-2001-0927

    Last Modified: 16 Apr 2026

    Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitrary code via an argument that contains format specifiers that are passed into the (1) syslog_message and (2) syslog_io_message functions.

    Published: 27 Nov 2001
    7.5
    High

    CVE-2001-0875

    Last Modified: 16 Apr 2026

    Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download.

    Published: 26 Nov 2001