CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2001-0615

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'.

    Published: 14 Aug 2001
    5
    Medium

    CVE-2001-1231

    Last Modified: 16 Apr 2026

    GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.

    Published: 14 Aug 2001
    5
    Medium

    CVE-2001-1232

    Last Modified: 16 Apr 2026

    GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".

    Published: 14 Aug 2001
    5
    Medium

    CVE-2001-1233

    Last Modified: 16 Apr 2026

    Netware Enterprise Web Server 5.1 running GroupWise WebAccess 5.5 with Novell Directory Services (NDS) enabled allows remote attackers to enumerate user names, group names and other system information by accessing ndsobj.nlm.

    Published: 14 Aug 2001
    7.5
    High

    CVE-2001-1114

    Last Modified: 16 Apr 2026

    book.cgi in NetCode NC Book 0.2b allows remote attackers to execute arbitrary commands via shell metacharacters in the "current" parameter.

    Published: 13 Aug 2001
    7.5
    High

    CVE-2001-1292

    Last Modified: 16 Apr 2026

    Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password.

    Published: 13 Aug 2001
    10
    Critical

    CVE-2001-1113

    Last Modified: 16 Apr 2026

    Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command.

    Published: 13 Aug 2001
    5
    Medium

    CVE-2001-1115

    Last Modified: 16 Apr 2026

    generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.

    Published: 13 Aug 2001
    7.5
    High

    CVE-2001-1157

    Last Modified: 16 Apr 2026

    Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using Unicode.

    Published: 12 Aug 2001
    5
    Medium

    CVE-2001-1117

    Last Modified: 16 Apr 2026

    LinkSys EtherFast BEFSR41 Cable/DSL routers running firmware before 1.39.3 Beta allows a remote attacker to view administration and user passwords by connecting to the router and viewing the HTML source for (1) index.htm and (2) Password.htm.

    Published: 10 Aug 2001
    5
    Medium

    CVE-2001-1134

    Last Modified: 16 Apr 2026

    Xerox DocuPrint N40 Printers allow remote attackers to cause a denial of service via malformed data, such as that produced by the Code Red worm.

    Published: 9 Aug 2001
    10
    Critical

    CVE-2001-1009

    Last Modified: 16 Apr 2026

    Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as part of a response to a LIST request.

    Published: 9 Aug 2001
    5
    Medium

    CVE-2001-1259

    Last Modified: 16 Apr 2026

    Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload.

    Published: 7 Aug 2001
    5
    Medium

    CVE-2001-1261

    Last Modified: 16 Apr 2026

    Avaya Argent Office 2.1 may allow remote attackers to change hold music by spoofing a legitimate server's response to a TFTP broadcast and providing an alternate HoldMusic file.

    Published: 7 Aug 2001
    7.5
    High

    CVE-2001-1262

    Last Modified: 16 Apr 2026

    Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string.

    Published: 7 Aug 2001
    10
    Critical

    CVE-2001-1260

    Last Modified: 16 Apr 2026

    Avaya Argent Office uses weak encryption (trivial encoding) for passwords, which allows remote attackers to gain administrator privileges by sniffing and decrypting the sniffing the passwords during a system reboot.

    Published: 7 Aug 2001
    1.2
    Low

    CVE-2001-1301

    Last Modified: 16 Apr 2026

    rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.

    Published: 7 Aug 2001
    5
    Medium

    CVE-2001-0647

    Last Modified: 16 Apr 2026

    Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version.

    Published: 6 Aug 2001
    10
    Critical

    CVE-2001-1356

    Last Modified: 16 Apr 2026

    NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.

    Published: 4 Aug 2001
    6.2
    Medium

    CVE-2001-1119

    Last Modified: 16 Apr 2026

    cda in xmcd 3.0.2 and 2.6 in SuSE Linux allows local users to overwrite arbitrary files via a symlink attack.

    Published: 3 Aug 2001
    2.1
    Low

    CVE-2001-1122

    Last Modified: 16 Apr 2026

    Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode.

    Published: 3 Aug 2001
    5
    Medium

    CVE-2001-1304

    Last Modified: 16 Apr 2026

    Buffer overflow in SHOUTcast Server 1.8.2 allows remote attackers to cause a denial of service (crash) via several HTTP requests with a long (1) user-agent or (2) host HTTP header.

    Published: 3 Aug 2001
    4.6
    Medium

    CVE-2001-1472

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.

    Published: 3 Aug 2001
    7.5
    High

    CVE-2001-1118

    Last Modified: 16 Apr 2026

    A module in Roxen 2.0 before 2.0.92, and 2.1 before 2.1.264, does not properly decode UTF-8, Mac and ISO-2202 encoded URLs, which could allow a remote attacker to execute arbitrary commands or view arbitrary files via an encoded URL.

    Published: 2 Aug 2001
    4.6
    Medium

    CVE-2001-0594

    Last Modified: 16 Apr 2026

    kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.

    Published: 2 Aug 2001
    4.6
    Medium

    CVE-2001-0573

    Last Modified: 16 Apr 2026

    lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory.

    Published: 2 Aug 2001
    4.6
    Medium

    CVE-2001-0595

    Last Modified: 16 Apr 2026

    Buffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute arbitrary commands via the KCMS_PROFILES environment variable, e.g. as demonstrated using the kcms_configure program.

    Published: 2 Aug 2001
    7.5
    High

    CVE-2001-1130

    Last Modified: 16 Apr 2026

    Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using a .. in the HTTP referer (from the HTTP_REFERER variable) to point to the directory that contains the keylist.txt file.

    Published: 2 Aug 2001
    5
    Medium

    CVE-2001-0590

    Last Modified: 16 Apr 2026

    Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).

    Published: 2 Aug 2001
    4.6
    Medium

    CVE-2001-1116

    Last Modified: 16 Apr 2026

    Identix BioLogon 2.03 and earlier does not lock secondary displays on a multi-monitor system running Windows 98 or ME, which allows an attacker with physical access to the system to bypass authentication through a secondary display.

    Published: 2 Aug 2001
    7.5
    High

    CVE-2001-1060

    Last Modified: 16 Apr 2026

    phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in tbl_rename.php.

    Published: 31 Jul 2001
    8.8
    High

    CVE-2001-1471

    Last Modified: 16 Apr 2026

    prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

    Published: 31 Jul 2001
    7.5
    High

    CVE-2001-1056

    Last Modified: 16 Apr 2026

    IRC DCC helper in the ip_masq_irc IP masquerading module 2.2 allows remote attackers to bypass intended firewall restrictions by causing the target system to send a "DCC SEND" request to a malicious server which listens on port 6667, which may cause the module to believe that the traffic is a valid request and allow the connection to the port specified in the DCC SEND request.

    Published: 30 Jul 2001
    5
    Medium

    CVE-2001-1057

    Last Modified: 16 Apr 2026

    The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by connecting to port 16286 and not disconnecting, which prevents users from making license requests.

    Published: 30 Jul 2001
    5
    Medium

    CVE-2001-1055

    Last Modified: 16 Apr 2026

    The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP request packets with random source IP and MAC addresses, as demonstrated by ARPNuke.

    Published: 30 Jul 2001
    3.6
    Low

    CVE-2001-1059

    Last Modified: 16 Apr 2026

    VMWare creates a temporary file vmware-log.USERNAME with insecure permissions, which allows local users to read or modify license information.

    Published: 30 Jul 2001
    5
    Medium

    CVE-2001-1289

    Last Modified: 16 Apr 2026

    Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters.

    Published: 29 Jul 2001
    7.5
    High

    CVE-2001-0357

    Last Modified: 16 Apr 2026

    FormMail.pl in FormMail 1.6 and earlier allows a remote attacker to send anonymous email (spam) by modifying the recipient and message parameters.

    Published: 27 Jul 2001
    7.5
    High

    CVE-2001-0520

    Last Modified: 16 Apr 2026

    Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT tag, or (5) any other tag in which scripts can be defined.

    Published: 27 Jul 2001
    7.5
    High

    CVE-2001-0521

    Last Modified: 16 Apr 2026

    Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.

    Published: 27 Jul 2001
    7.5
    High

    CVE-2001-0519

    Last Modified: 16 Apr 2026

    Aladdin eSafe Gateway versions 2.x allows a remote attacker to circumvent HTML SCRIPT filtering via a special arrangement of HTML tags which includes SCRIPT tags embedded within other SCRIPT tags.

    Published: 27 Jul 2001
    7.5
    High

    CVE-2001-0561

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.

    Published: 27 Jul 2001
    7.5
    High

    CVE-2001-0562

    Last Modified: 16 Apr 2026

    a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters.

    Published: 27 Jul 2001
    5
    Medium

    CVE-2001-0557

    Last Modified: 16 Apr 2026

    T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).

    Published: 27 Jul 2001
    4.6
    Medium

    CVE-2001-0576

    Last Modified: 16 Apr 2026

    lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the '-u' command line parameter.

    Published: 27 Jul 2001
    7.2
    High

    CVE-2001-0577

    Last Modified: 16 Apr 2026

    recon in SCO OpenServer 5.0 through 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first command line argument.

    Published: 27 Jul 2001
    4.6
    Medium

    CVE-2001-0578

    Last Modified: 16 Apr 2026

    Buffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a long first argument to the lpforms command.

    Published: 27 Jul 2001
    7.5
    High

    CVE-2001-0579

    Last Modified: 16 Apr 2026

    lpadmin in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first argument to the command.

    Published: 27 Jul 2001
    7.2
    High

    CVE-2001-0587

    Last Modified: 16 Apr 2026

    deliver program in MMDF 2.43.3b in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command.

    Published: 27 Jul 2001
    4.6
    Medium

    CVE-2001-0588

    Last Modified: 16 Apr 2026

    sendmail 8.9.3, as included with the MMDF 2.43.3b package in SCO OpenServer 5.0.6, can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command.

    Published: 27 Jul 2001