CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2001-1155

    Last Modified: 16 Apr 2026

    TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spoofing.

    Published: 23 Aug 2001
    5
    Medium

    CVE-2001-0394

    Last Modified: 16 Apr 2026

    Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory.

    Published: 22 Aug 2001
    5
    Medium

    CVE-2001-0585

    Last Modified: 16 Apr 2026

    Gordano NTMail 6.0.3c allows a remote attacker to create a denial of service via a long (>= 255 characters) URL request to port 8000 or port 9000.

    Published: 22 Aug 2001
    4.6
    Medium

    CVE-2001-0586

    Last Modified: 16 Apr 2026

    TrendMicro ScanMail for Exchange 3.5 Evaluation allows a local attacker to recover the administrative credentials for ScanMail via a combination of unprotected registry keys and weakly encrypted passwords.

    Published: 22 Aug 2001
    2.1
    Low

    CVE-2001-0589

    Last Modified: 16 Apr 2026

    NetScreen ScreenOS prior to 2.5r6 on the NetScreen-10 and Netscreen-100 can allow a local attacker to bypass the DMZ 'denial' policy via specific traffic patterns.

    Published: 22 Aug 2001
    5
    Medium

    CVE-2001-0613

    Last Modified: 16 Apr 2026

    Omnicron Technologies OmniHTTPD Professional 2.08 and earlier allows a remote attacker to create a denial of service via a long POST URL request.

    Published: 22 Aug 2001
    3.7
    Low

    CVE-2001-0627

    Last Modified: 16 Apr 2026

    vi as included with SCO OpenServer 5.0 - 5.0.6 allows a local attacker to overwrite arbitrary files via a symlink attack.

    Published: 22 Aug 2001
    5
    Medium

    CVE-2001-0630

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in MIMAnet viewsrc.cgi 2.0 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the 'loc' variable.

    Published: 22 Aug 2001
    7.5
    High

    CVE-2001-0626

    Last Modified: 16 Apr 2026

    O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character.

    Published: 22 Aug 2001
    7.2
    High

    CVE-2001-0625

    Last Modified: 16 Apr 2026

    ftpdownload in Computer Associates InoculateIT 6.0 allows a local attacker to overwrite arbitrary files via a symlink attack on /tmp/ftpdownload.log .

    Published: 22 Aug 2001
    7.2
    High

    CVE-2001-0634

    Last Modified: 16 Apr 2026

    Sun Chili!Soft ASP has weak permissions on various configuration files, which allows a local attacker to gain additional privileges and create a denial of service.

    Published: 22 Aug 2001
    7.5
    High

    CVE-2001-0591

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack.

    Published: 22 Aug 2001
    5
    Medium

    CVE-2001-1150

    Last Modified: 16 Apr 2026

    Vulnerability in cgiWebupdate.exe in Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.5.2 through 3.5.4 allows remote attackers to read arbitrary files.

    Published: 22 Aug 2001
    5
    Medium

    CVE-2001-0564

    Last Modified: 16 Apr 2026

    APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of service via repeated failed logon attempts which temporarily locks the card.

    Published: 22 Aug 2001
    5
    Medium

    CVE-2001-0593

    Last Modified: 16 Apr 2026

    Anaconda Partners Clipper 3.3 and earlier allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the template parameter.

    Published: 22 Aug 2001
    5
    Medium

    CVE-2001-0612

    Last Modified: 16 Apr 2026

    McAfee Remote Desktop 3.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of packets to port 5045.

    Published: 22 Aug 2001
    5
    Medium

    CVE-2001-1139

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ASCII NT WinWrapper Professional allows remote attackers to read arbitrary files via a .. (dot dot) in the server request.

    Published: 22 Aug 2001
    5
    Medium

    CVE-2001-1294

    Last Modified: 16 Apr 2026

    Buffer overflow in A-V Tronics Inetserv 3.2.1 and earlier allows remote attackers to cause a denial of service (crash) in the Webmail interface via a long username and password.

    Published: 22 Aug 2001
    5
    Medium

    CVE-2001-0631

    Last Modified: 6 Apr 2026

    Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users.

    Published: 22 Aug 2001
    5
    Medium

    CVE-2001-1140

    Last Modified: 16 Apr 2026

    BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request.

    Published: 22 Aug 2001
    5
    Medium

    CVE-2001-1131

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in WhitSoft Development SlimFTPd 2.2 allows an attacker to read arbitrary files and directories via a ... (modified dot dot) in the CD command.

    Published: 21 Aug 2001
    2.1
    Low

    CVE-2001-1133

    Last Modified: 16 Apr 2026

    Vulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kernel via a particular sequence of instructions.

    Published: 21 Aug 2001
    5
    Medium

    CVE-2001-1149

    Last Modified: 16 Apr 2026

    Panda Antivirus Platinum before 6.23.00 allows a remore attacker to cause a denial of service (crash) when a user selects an action for a malformed UPX packed executable file.

    Published: 21 Aug 2001
    5
    Medium

    CVE-2001-1166

    Last Modified: 16 Apr 2026

    linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.

    Published: 21 Aug 2001
    5
    Medium

    CVE-2001-1295

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Cerberus FTP Server 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the CD command.

    Published: 21 Aug 2001
    4.6
    Medium

    CVE-2001-0653

    Last Modified: 16 Apr 2026

    Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d) command line arguments, which is interpreted as a negative number.

    Published: 21 Aug 2001
    5
    Medium

    CVE-2000-1203

    Last Modified: 16 Apr 2026

    Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.

    Published: 20 Aug 2001
    6.2
    Medium

    CVE-2001-1145

    Last Modified: 16 Apr 2026

    fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on the wrong directories.

    Published: 17 Aug 2001
    5
    Medium

    CVE-2001-1305

    Last Modified: 16 Apr 2026

    ICQ 2001a Alpha and earlier allows remote attackers to automatically add arbitrary UINs to an ICQ user's contact list via a URL to a web page with a Content-Type of application/x-icq, which is processed by Internet Explorer.

    Published: 17 Aug 2001
    7.5
    High

    CVE-2001-0504

    Last Modified: 16 Apr 2026

    Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activities such as mail relaying.

    Published: 14 Aug 2001
    7.2
    High

    CVE-2001-0528

    Last Modified: 16 Apr 2026

    Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain privileges.

    Published: 14 Aug 2001
    7.2
    High

    CVE-2001-0529

    Last Modified: 16 Apr 2026

    OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.

    Published: 14 Aug 2001
    5
    Medium

    CVE-2001-0530

    Last Modified: 16 Apr 2026

    Spearhead NetGAP 200 and 300 before build 78 allow a remote attacker to bypass file blocking and content inspection via specially encoded URLs which include '%' characters.

    Published: 14 Aug 2001
    7.2
    High

    CVE-2001-0533

    Last Modified: 16 Apr 2026

    Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.

    Published: 14 Aug 2001
    10
    Critical

    CVE-2001-0538

    Last Modified: 16 Apr 2026

    Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.

    Published: 14 Aug 2001
    7.2
    High

    CVE-2001-0553

    Last Modified: 16 Apr 2026

    SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field.

    Published: 14 Aug 2001
    5
    Medium

    CVE-2001-0558

    Last Modified: 16 Apr 2026

    T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0).

    Published: 14 Aug 2001
    7.2
    High

    CVE-2001-0559

    Last Modified: 16 Apr 2026

    crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.

    Published: 14 Aug 2001
    5
    Medium

    CVE-2001-0563

    Last Modified: 16 Apr 2026

    ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via large (> 160000 character) strings sent to port 23.

    Published: 14 Aug 2001
    7.5
    High

    CVE-2001-0621

    Last Modified: 16 Apr 2026

    The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands.

    Published: 14 Aug 2001
    7.5
    High

    CVE-2001-0622

    Last Modified: 16 Apr 2026

    The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the interface.

    Published: 14 Aug 2001
    7.2
    High

    CVE-2001-0628

    Last Modified: 16 Apr 2026

    Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.

    Published: 14 Aug 2001
    10
    Critical

    CVE-2001-0629

    Last Modified: 16 Apr 2026

    HP Event Correlation Service (ecsd) as included with OpenView Network Node Manager 6.1 allows a remote attacker to gain addition privileges via a buffer overflow attack in the '-restore_config' command line parameter.

    Published: 14 Aug 2001
    7.5
    High

    CVE-2001-1135

    Last Modified: 16 Apr 2026

    ZyXEL Prestige 642R and 642R-I routers do not filter the routers' Telnet and FTP ports on the external WAN interface from inside access, allowing someone on an internal computer to reconfigure the router, if the password is known.

    Published: 14 Aug 2001
    4.6
    Medium

    CVE-2001-0548

    Last Modified: 16 Apr 2026

    Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.

    Published: 14 Aug 2001
    5
    Medium

    CVE-2001-0616

    Last Modified: 16 Apr 2026

    Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (e.g., GET /aux HTTP/1.0).

    Published: 14 Aug 2001
    4.6
    Medium

    CVE-2001-0526

    Last Modified: 16 Apr 2026

    Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable.

    Published: 14 Aug 2001
    10
    Critical

    CVE-2001-0527

    Last Modified: 16 Apr 2026

    DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.

    Published: 14 Aug 2001
    4.6
    Medium

    CVE-2001-0565

    Last Modified: 16 Apr 2026

    Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.

    Published: 14 Aug 2001
    5
    Medium

    CVE-2001-0574

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot) in the URL.

    Published: 14 Aug 2001