CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2001-0675

    Last Modified: 16 Apr 2026

    Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a carriage return <CR> that is not followed by a line feed <LF>.

    Published: 20 Sept 2001
    2.6
    Low

    CVE-2001-0685

    Last Modified: 16 Apr 2026

    Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file.

    Published: 20 Sept 2001
    4.6
    Medium

    CVE-2001-0686

    Last Modified: 16 Apr 2026

    Buffer overflow in mail included with SunOS 5.8 for x86 allows a local user to gain privileges via a long HOME environment variable.

    Published: 20 Sept 2001
    7.5
    High

    CVE-2001-0700

    Last Modified: 16 Apr 2026

    Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header.

    Published: 20 Sept 2001
    7.2
    High

    CVE-2001-0701

    Last Modified: 16 Apr 2026

    Buffer overflow in ptexec in the Sun Validation Test Suite 4.3 and earlier allows a local user to gain privileges via a long -o argument.

    Published: 20 Sept 2001
    7.2
    High

    CVE-2001-0699

    Last Modified: 16 Apr 2026

    Buffer overflow in cb_reset in the System Service Processor (SSP) package of SunOS 5.8 allows a local user to execute arbitrary code via a long argument.

    Published: 20 Sept 2001
    5
    Medium

    CVE-2001-0710

    Last Modified: 16 Apr 2026

    NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool.

    Published: 20 Sept 2001
    2.1
    Low

    CVE-2001-0706

    Last Modified: 16 Apr 2026

    Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies a large number of sub-folders.

    Published: 20 Sept 2001
    7.2
    High

    CVE-2001-0506

    Last Modified: 16 Apr 2026

    Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.

    Published: 20 Sept 2001
    7.5
    High

    CVE-2001-0644

    Last Modified: 16 Apr 2026

    Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 stores passwords in plaintext in the "Rumpus User Database" file in the prefs folder, which could allow attackers to gain privileges on the server.

    Published: 20 Sept 2001
    7.5
    High

    CVE-2001-0658

    Last Modified: 16 Apr 2026

    Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message.

    Published: 20 Sept 2001
    7.5
    High

    CVE-2001-0692

    Last Modified: 16 Apr 2026

    SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and 4.6 allows a remote attacker to bypass firewall filtering via a base64 MIME encoded email attachment whose boundary name ends in two dashes.

    Published: 20 Sept 2001
    5
    Medium

    CVE-2001-0696

    Last Modified: 16 Apr 2026

    NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con.

    Published: 20 Sept 2001
    5
    Medium

    CVE-2001-0508

    Last Modified: 16 Apr 2026

    Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.

    Published: 20 Sept 2001
    5
    Medium

    CVE-2001-0546

    Last Modified: 16 Apr 2026

    Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.

    Published: 20 Sept 2001
    5
    Medium

    CVE-2001-0646

    Last Modified: 16 Apr 2026

    Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specific length.

    Published: 20 Sept 2001
    5
    Medium

    CVE-2001-0698

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command.

    Published: 20 Sept 2001
    7.5
    High

    CVE-2001-0964

    Last Modified: 16 Apr 2026

    Buffer overflow in client for Half-Life 1.1.0.8 and earlier allows malicious remote servers to execute arbitrary code via a long console command.

    Published: 20 Sept 2001
    5
    Medium

    CVE-2001-1018

    Last Modified: 16 Apr 2026

    Lotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that contains a long sequence of / (slash) characters.

    Published: 20 Sept 2001
    7.2
    High

    CVE-2001-0507

    Last Modified: 16 Apr 2026

    IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.

    Published: 20 Sept 2001
    5
    Medium

    CVE-2001-0697

    Last Modified: 16 Apr 2026

    NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.

    Published: 20 Sept 2001
    7.5
    High

    CVE-2001-0963

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in SpoonFTP 1.1 allows local and sometimes remote attackers to access files outside of the FTP root via a ... (modified dot dot) in the CD (CWD) command.

    Published: 20 Sept 2001
    5
    Medium

    CVE-2001-0543

    Last Modified: 16 Apr 2026

    Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed posts.

    Published: 20 Sept 2001
    2.1
    Low

    CVE-2001-0547

    Last Modified: 16 Apr 2026

    Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).

    Published: 20 Sept 2001
    5
    Medium

    CVE-2001-0643

    Last Modified: 16 Apr 2026

    Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type.

    Published: 20 Sept 2001
    2.1
    Low

    CVE-2001-1029

    Last Modified: 16 Apr 2026

    libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.

    Published: 20 Sept 2001
    5
    Medium

    CVE-2000-1215

    Last Modified: 16 Apr 2026

    The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information.

    Published: 19 Sept 2001
    7.5
    High

    CVE-2001-0962

    Last Modified: 16 Apr 2026

    IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.

    Published: 19 Sept 2001
    6.2
    Medium

    CVE-2001-1383

    Last Modified: 16 Apr 2026

    initscript in setserial 2.17-4 and earlier uses predictable temporary file names, which could allow local users to conduct unauthorized operations on files.

    Published: 19 Sept 2001
    10
    Critical

    CVE-2001-0961

    Last Modified: 16 Apr 2026

    Buffer overflow in tab expansion capability of the most program allows local or remote attackers to execute arbitrary code via a malformed file that is viewed with most.

    Published: 18 Sept 2001
    7.5
    High

    CVE-2001-0816

    Last Modified: 16 Apr 2026

    OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypass authorized_keys2 command= restrictions using sftp commands.

    Published: 18 Sept 2001
    2.6
    Low

    CVE-2001-1353

    Last Modified: 16 Apr 2026

    ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.

    Published: 18 Sept 2001
    6.4
    Medium

    CVE-2001-0959

    Last Modified: 16 Apr 2026

    Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 creates a hidden share named ARCSERVE$, which allows remote attackers to obtain sensitive information and overwrite critical files.

    Published: 15 Sept 2001
    7.5
    High

    CVE-2001-1014

    Last Modified: 16 Apr 2026

    eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter.

    Published: 15 Sept 2001
    10
    Critical

    CVE-2001-0960

    Last Modified: 16 Apr 2026

    Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows local and remote attackers to gain privileges.

    Published: 15 Sept 2001
    5
    Medium

    CVE-2001-0986

    Last Modified: 16 Apr 2026

    SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo.

    Published: 14 Sept 2001
    4.6
    Medium

    CVE-2001-0984

    Last Modified: 16 Apr 2026

    Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options enabled, which could allow an attacker with access to the memory (e.g. an administrator) to read the passwords.

    Published: 13 Sept 2001
    2.1
    Low

    CVE-2001-1136

    Last Modified: 16 Apr 2026

    The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.

    Published: 13 Sept 2001
    5
    Medium

    CVE-1999-1081

    Last Modified: 16 Apr 2026

    Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.

    Published: 12 Sept 2001
    5
    Medium

    CVE-1999-1374

    Last Modified: 16 Apr 2026

    perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request.

    Published: 12 Sept 2001
    5
    Medium

    CVE-1999-1373

    Last Modified: 16 Apr 2026

    FORE PowerHub before 5.0.1 allows remote attackers to cause a denial of service (hang) via a TCP SYN scan with TCP/IP OS fingerprinting, e.g. via nmap.

    Published: 12 Sept 2001
    5
    Medium

    CVE-1999-1091

    Last Modified: 16 Apr 2026

    UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.

    Published: 12 Sept 2001
    4.6
    Medium

    CVE-1999-1174

    Last Modified: 16 Apr 2026

    ZIP drive for Iomega ZIP-100 disks allows attackers with physical access to the drive to bypass password protection by inserting a known disk with a known password, waiting for the ZIP drive to power down, manually replacing the known disk with the target disk, and using the known password to access the target disk.

    Published: 12 Sept 2001
    7.5
    High

    CVE-1999-1024

    Last Modified: 16 Apr 2026

    ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which causes an infinite loop and core dump when tcpdump prints the packet.

    Published: 12 Sept 2001
    7.5
    High

    CVE-2001-0958

    Last Modified: 16 Apr 2026

    Buffer overflows in eManager plugin for Trend Micro InterScan VirusWall for NT 3.51 and 3.51J allow remote attackers to execute arbitrary code via long arguments to the CGI programs (1) register.dll, (2) ContentFilter.dll, (3) SFNofitication.dll, (4) register.dll, (5) TOP10.dll, (6) SpamExcp.dll, and (7) spamrule.dll.

    Published: 12 Sept 2001
    7.5
    High

    CVE-2001-1109

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.

    Published: 12 Sept 2001
    5
    Medium

    CVE-2001-1110

    Last Modified: 16 Apr 2026

    EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.

    Published: 12 Sept 2001
    4.6
    Medium

    CVE-2001-1111

    Last Modified: 16 Apr 2026

    EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file.

    Published: 12 Sept 2001
    5
    Medium

    CVE-1999-1557

    Last Modified: 16 Apr 2026

    Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password.

    Published: 12 Sept 2001
    4.6
    Medium

    CVE-1999-1431

    Last Modified: 16 Apr 2026

    ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe.

    Published: 12 Sept 2001