CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2001-1106

    Last Modified: 16 Apr 2026

    The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.

    Published: 25 Jul 2001
    5
    Medium

    CVE-2002-0810

    Last Modified: 16 Apr 2026

    Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.

    Published: 25 Jul 2001
    5
    Medium

    CVE-2001-1097

    Last Modified: 16 Apr 2026

    Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.

    Published: 24 Jul 2001
    7.5
    High

    CVE-2001-0991

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in Proxomitron Naoko-4 BetaFour and earlier allows remote attackers to execute arbitrary script on other clients via an incorrect URL containing the malicious script, which is printed back in an error message.

    Published: 24 Jul 2001
    2.1
    Low

    CVE-2001-0993

    Last Modified: 16 Apr 2026

    sendmsg function in NetBSD 1.3 through 1.5 allows local users to cause a denial of service (kernel trap or panic) via a msghdr structure with a large msg_controllen length.

    Published: 24 Jul 2001
    5
    Medium

    CVE-2001-0982

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in IBM Tivoli WebSEAL Policy Director 3.01 through 3.7.1 allows remote attackers to read arbitrary files or directories via encoded .. (dot dot) sequences containing "%2e" strings.

    Published: 23 Jul 2001
    7.2
    High

    CVE-2001-0988

    Last Modified: 16 Apr 2026

    Arkeia backup server 4.2.8-2 and earlier creates its database files with world-writable permissions, which could allow local users to overwrite the files or obtain sensitive information.

    Published: 23 Jul 2001
    7.2
    High

    CVE-2001-0989

    Last Modified: 16 Apr 2026

    Buffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or (2) a long callsign.

    Published: 23 Jul 2001
    7.5
    High

    CVE-2001-0987

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by causing the Javascript to be inserted into error messages that are generated by CGIWrap.

    Published: 22 Jul 2001
    5
    Medium

    CVE-2001-1010

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) attack on the page parameter.

    Published: 22 Jul 2001
    10
    Critical

    CVE-2001-0534

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in RADIUS daemon radiusd in (1) Merit 3.6b and (2) Lucent 2.1-2 RADIUS allow remote attackers to cause a denial of service or execute arbitrary commands.

    Published: 21 Jul 2001
    7.5
    High

    CVE-2000-0891

    Last Modified: 16 Apr 2026

    A default ECL in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands by attaching a malicious program in an email message that is automatically executed when the user opens the email.

    Published: 21 Jul 2001
    5
    Medium

    CVE-2001-0018

    Last Modified: 16 Apr 2026

    Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests.

    Published: 21 Jul 2001
    7.5
    High

    CVE-2001-0340

    Last Modified: 16 Apr 2026

    An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.

    Published: 21 Jul 2001
    7.5
    High

    CVE-2001-0341

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.

    Published: 21 Jul 2001
    5
    Medium

    CVE-2001-0348

    Last Modified: 16 Apr 2026

    Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.

    Published: 21 Jul 2001
    10
    Critical

    CVE-2001-0353

    Last Modified: 16 Apr 2026

    Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine.

    Published: 21 Jul 2001
    2.1
    Low

    CVE-2001-0351

    Last Modified: 16 Apr 2026

    Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.

    Published: 21 Jul 2001
    5
    Medium

    CVE-2001-0352

    Last Modified: 16 Apr 2026

    SNMP agents in 3Com AirConnect AP-4111 and Symbol 41X1 Access Point allow remote attackers to obtain the WEP encryption key by reading it from a MIB when the value should be write-only, via (1) dot11WEPDefaultKeyValue in the dot11WEPDefaultKeysTable of the IEEE 802.11b MIB, or (2) ap128bWepKeyValue in the ap128bWEPKeyTable in the Symbol MIB.

    Published: 21 Jul 2001
    4.6
    Medium

    CVE-2001-0501

    Last Modified: 16 Apr 2026

    Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.

    Published: 21 Jul 2001
    4.6
    Medium

    CVE-2001-0502

    Last Modified: 16 Apr 2026

    Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users.

    Published: 21 Jul 2001
    5
    Medium

    CVE-2001-0503

    Last Modified: 16 Apr 2026

    Microsoft NetMeeting 3.01 with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service via a malformed string to the NetMeeting service port, aka a variant of the "NetMeeting Desktop Sharing" vulnerability.

    Published: 21 Jul 2001
    5
    Medium

    CVE-2001-0515

    Last Modified: 16 Apr 2026

    Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value.

    Published: 21 Jul 2001
    3.6
    Low

    CVE-2001-1258

    Last Modified: 16 Apr 2026

    Horde Internet Messaging Program (IMP) before 2.2.6 allows local users to read IMP configuration files and steal the Horde database password by placing the prefs.lang file containing PHP code on the server.

    Published: 21 Jul 2001
    5
    Medium

    CVE-2001-0346

    Last Modified: 16 Apr 2026

    Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.

    Published: 21 Jul 2001
    7.5
    High

    CVE-2001-0347

    Last Modified: 16 Apr 2026

    Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.

    Published: 21 Jul 2001
    4.6
    Medium

    CVE-2001-0350

    Last Modified: 16 Apr 2026

    Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.

    Published: 21 Jul 2001
    5
    Medium

    CVE-2001-0498

    Last Modified: 16 Apr 2026

    Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension.

    Published: 21 Jul 2001
    10
    Critical

    CVE-2001-0499

    Last Modified: 16 Apr 2026

    Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.

    Published: 21 Jul 2001
    10
    Critical

    CVE-2001-0500

    Last Modified: 16 Apr 2026

    Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.

    Published: 21 Jul 2001
    5
    Medium

    CVE-2001-0513

    Last Modified: 16 Apr 2026

    Oracle listener process on Windows NT redirects connection requests to another port and creates a separate thread to process the request, which allows remote attackers to cause a denial of service by repeatedly connecting to the Oracle listener but not connecting to the redirected port.

    Published: 21 Jul 2001
    7.5
    High

    CVE-2001-0514

    Last Modified: 16 Apr 2026

    SNMP service in Atmel 802.11b VNET-B Access Point 1.3 and earlier, as used in Netgear ME102 and Linksys WAP11, accepts arbitrary community strings with requested MIB modifications, which allows remote attackers to obtain sensitive information such as WEP keys, cause a denial of service, or gain access to the network.

    Published: 21 Jul 2001
    5
    Medium

    CVE-2001-0516

    Last Modified: 16 Apr 2026

    Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains an incorrect requester_version value that does not match an expected offset to the data.

    Published: 21 Jul 2001
    5
    Medium

    CVE-2001-0517

    Last Modified: 16 Apr 2026

    Oracle listener in Oracle 8i on Solaris allows remote attackers to cause a denial of service via a malformed connection packet with a maximum transport data size that is set to 0.

    Published: 21 Jul 2001
    5
    Medium

    CVE-2001-0518

    Last Modified: 16 Apr 2026

    Oracle listener before Oracle 9i allows attackers to cause a denial of service by repeatedly sending the first portion of a fragmented Oracle command without sending the remainder of the command, which causes the listener to hang.

    Published: 21 Jul 2001
    9.3
    Critical

    CVE-2001-0537

    Last Modified: 16 Apr 2026

    HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.

    Published: 21 Jul 2001
    2.6
    Low

    CVE-2000-0892

    Last Modified: 16 Apr 2026

    Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive information, or remote web servers to obtain the information via a telnet: URL.

    Published: 21 Jul 2001
    5
    Medium

    CVE-2001-0345

    Last Modified: 16 Apr 2026

    Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.

    Published: 21 Jul 2001
    7.8
    High

    CVE-2001-0497

    Last Modified: 16 Apr 2026

    dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.

    Published: 21 Jul 2001
    7.5
    High

    CVE-2001-1257

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email.

    Published: 21 Jul 2001
    10
    Critical

    CVE-2001-1370

    Last Modified: 16 Apr 2026

    prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.

    Published: 21 Jul 2001
    7.2
    High

    CVE-2001-0344

    Last Modified: 16 Apr 2026

    An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.

    Published: 21 Jul 2001
    7.2
    High

    CVE-2001-0349

    Last Modified: 16 Apr 2026

    Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.

    Published: 21 Jul 2001
    9.8
    Critical

    CVE-2013-7171

    Last Modified: 21 Nov 2024

    Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root privileges.

    Published: 21 Jul 2001
    4.6
    Medium

    CVE-2001-1354

    Last Modified: 16 Apr 2026

    NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.

    Published: 20 Jul 2001
    10
    Critical

    CVE-2001-1355

    Last Modified: 16 Apr 2026

    Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitrary code via long arguments to (1) the -del command or (2) the -lookup command.

    Published: 20 Jul 2001
    7.5
    High

    CVE-2001-1265

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary files via a .. (dot dot) attack.

    Published: 20 Jul 2001
    10
    Critical

    CVE-2001-1363

    Last Modified: 16 Apr 2026

    Vulnerability in phpWebSite before 0.7.9 related to running multiple instances in the same domain, which may allow attackers to gain administrative privileges.

    Published: 19 Jul 2001
    4.6
    Medium

    CVE-2001-1172

    Last Modified: 16 Apr 2026

    OmniSecure HTTProtect 1.1.1 allows a superuser without omnish privileges to modify a protected file by creating a symbolic link to that file.

    Published: 19 Jul 2001
    7.2
    High

    CVE-2001-1360

    Last Modified: 16 Apr 2026

    Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned.

    Published: 19 Jul 2001