CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2001-0294

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in TYPSoft FTP Server 0.85 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in a GET command, or (2) a ... in a CWD command.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0302

    Last Modified: 16 Apr 2026

    Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0303

    Last Modified: 16 Apr 2026

    tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0298

    Last Modified: 16 Apr 2026

    Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.

    Published: 4 Apr 2001
    7.5
    High

    CVE-2001-0308

    Last Modified: 16 Apr 2026

    UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0312

    Last Modified: 16 Apr 2026

    IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0306

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

    Published: 4 Apr 2001
    7.5
    High

    CVE-2001-0307

    Last Modified: 16 Apr 2026

    Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.

    Published: 4 Apr 2001
    10
    Critical

    CVE-2001-0320

    Last Modified: 16 Apr 2026

    bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.

    Published: 4 Apr 2001
    7.5
    High

    CVE-2001-0325

    Last Modified: 16 Apr 2026

    Buffer overflow in QNX RTP 5.60 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large number of arguments to the stat command.

    Published: 4 Apr 2001
    6.4
    Medium

    CVE-2001-0323

    Last Modified: 16 Apr 2026

    The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host.

    Published: 4 Apr 2001
    2.6
    Low

    CVE-2001-0324

    Last Modified: 16 Apr 2026

    Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.

    Published: 4 Apr 2001
    2.1
    Low

    CVE-2001-0275

    Last Modified: 16 Apr 2026

    Moby Netsuite Web Server 1.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.

    Published: 4 Apr 2001
    10
    Critical

    CVE-2001-0296

    Last Modified: 16 Apr 2026

    Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command.

    Published: 4 Apr 2001
    7.5
    High

    CVE-2001-0314

    Last Modified: 16 Apr 2026

    Buffer overflow in www.tol module in America Online (AOL) 5.0 may allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL in a link.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0322

    Last Modified: 16 Apr 2026

    MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0253

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0254

    Last Modified: 16 Apr 2026

    FaSTream FTP++ Server 2.0 allows remote attackers to obtain the real pathname of the server via the "pwd" command.

    Published: 4 Apr 2001
    10
    Critical

    CVE-2001-0277

    Last Modified: 16 Apr 2026

    Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.

    Published: 4 Apr 2001
    10
    Critical

    CVE-2001-0282

    Last Modified: 16 Apr 2026

    SEDUM 2.1 HTTP server allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.

    Published: 4 Apr 2001
    6.4
    Medium

    CVE-2001-0283

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0297

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Simple Server HTTPd 1.0 (originally Free Java Server) allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Published: 4 Apr 2001
    2.1
    Low

    CVE-2001-0300

    Last Modified: 16 Apr 2026

    oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0304

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0305

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in the StartID parameter.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0313

    Last Modified: 16 Apr 2026

    Borderware Firewall Server 6.1.2 allows remote attackers to cause a denial of service via a ping to the broadcast address of the public network on which the server is placed, which causes the server to continuously send pings (echo requests) to the network.

    Published: 4 Apr 2001
    7.5
    High

    CVE-2001-0315

    Last Modified: 16 Apr 2026

    The locking feature in mIRC 5.7 allows local users to bypass the password mechanism by modifying the LockOptions registry key.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0251

    Last Modified: 16 Apr 2026

    The Web Publishing feature in Netscape Enterprise Server 3.x allows remote attackers to cause a denial of service via the REVLOG command.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0255

    Last Modified: 16 Apr 2026

    FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0258

    Last Modified: 16 Apr 2026

    The Easycom/Safecom Print Server (firmware 404.590) PrintGuide server allows remote attackers to cause a denial of service via a large number of connections that send null characters.

    Published: 4 Apr 2001
    2.6
    Low

    CVE-2001-0273

    Last Modified: 16 Apr 2026

    pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in cleartext.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0286

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.

    Published: 4 Apr 2001
    10
    Critical

    CVE-2001-0414

    Last Modified: 16 Apr 2026

    Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.

    Published: 4 Apr 2001
    2.1
    Low

    CVE-2001-0736

    Last Modified: 16 Apr 2026

    Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.

    Published: 31 Mar 2001
    6.2
    Medium

    CVE-2001-1390

    Last Modified: 16 Apr 2026

    Unknown vulnerability in binfmt_misc in the Linux kernel before 2.2.19, related to user pages.

    Published: 27 Mar 2001
    3.6
    Low

    CVE-2001-1396

    Last Modified: 16 Apr 2026

    Unknown vulnerabilities in strnlen_user for Linux kernel before 2.2.19, with unknown impact.

    Published: 27 Mar 2001
    2.1
    Low

    CVE-2001-1397

    Last Modified: 16 Apr 2026

    The System V (SYS5) shared memory implementation for Linux kernel before 2.2.19 could allow attackers to modify recently freed memory.

    Published: 27 Mar 2001
    5.5
    Medium

    CVE-2001-1391

    Last Modified: 16 Apr 2026

    Off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory.

    Published: 27 Mar 2001
    2.1
    Low

    CVE-2001-1392

    Last Modified: 16 Apr 2026

    The Linux kernel before 2.2.19 does not have unregister calls for (1) CPUID and (2) MSR drivers, which could cause a DoS (crash) by unloading and reloading the drivers.

    Published: 27 Mar 2001
    2.1
    Low

    CVE-2001-1393

    Last Modified: 16 Apr 2026

    Unknown vulnerability in classifier code for Linux kernel before 2.2.19 could result in denial of service (hang).

    Published: 27 Mar 2001
    2.1
    Low

    CVE-2001-1394

    Last Modified: 16 Apr 2026

    Signedness error in (1) getsockopt and (2) setsockopt for Linux kernel before 2.2.19 allows local users to cause a denial of service.

    Published: 27 Mar 2001
    7.5
    High

    CVE-2001-1398

    Last Modified: 16 Apr 2026

    Masquerading code for Linux kernel before 2.2.19 does not fully check packet lengths in certain cases, which may lead to a vulnerability.

    Published: 27 Mar 2001
    2.1
    Low

    CVE-2001-1400

    Last Modified: 16 Apr 2026

    Unknown vulnerabilities in the UDP port allocation for Linux kernel before 2.2.19 could allow local users to cause a denial of service (deadlock).

    Published: 27 Mar 2001
    2.1
    Low

    CVE-2001-1399

    Last Modified: 16 Apr 2026

    Certain operations in Linux kernel before 2.2.19 on the x86 architecture copy the wrong number of bytes, which might allow attackers to modify memory, aka "User access asm bug on x86."

    Published: 27 Mar 2001
    3.6
    Low

    CVE-2001-1395

    Last Modified: 16 Apr 2026

    Unknown vulnerability in sockfilter for Linux kernel before 2.2.19 related to "boundary cases," with unknown impact.

    Published: 27 Mar 2001
    7.6
    High

    CVE-2001-0166

    Last Modified: 16 Apr 2026

    Macromedia Shockwave Flash plugin version 8 and earlier allows remote attackers to cause a denial of service via malformed tag length specifiers in a SWF file.

    Published: 26 Mar 2001
    5
    Medium

    CVE-2001-0175

    Last Modified: 16 Apr 2026

    The caching module in Netscape Fasttrack Server 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by requesting a large number of non-existent URLs.

    Published: 26 Mar 2001
    7.2
    High

    CVE-2001-0176

    Last Modified: 16 Apr 2026

    The setuid doroot program in Voyant Sonata 3.x executes arbitrary command line arguments, which allows local users to gain root privileges.

    Published: 26 Mar 2001
    7.5
    High

    CVE-2001-0183

    Last Modified: 16 Apr 2026

    ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes the packet appear to be part of an established connection.

    Published: 26 Mar 2001
    5
    Medium

    CVE-2001-0185

    Last Modified: 16 Apr 2026

    Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router's telnet program to connect to the router's IP address, which causes a crash.

    Published: 26 Mar 2001