CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2001-1366

    Last Modified: 16 Apr 2026

    netscript before 1.6.3 parses dynamic variables, which could allow remote attackers to alter program behavior or obtain sensitive information.

    Published: 19 Jul 2001
    7.5
    High

    CVE-2001-1361

    Last Modified: 16 Apr 2026

    Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links.

    Published: 19 Jul 2001
    10
    Critical

    CVE-2001-1264

    Last Modified: 16 Apr 2026

    Vulnerability in mkacct in HP-UX 11.04 running Virtualvault Operating System (VVOS) 4.0 and 4.5 allows attackers to elevate privileges.

    Published: 19 Jul 2001
    2.1
    Low

    CVE-2001-1302

    Last Modified: 16 Apr 2026

    The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function.

    Published: 18 Jul 2001
    5
    Medium

    CVE-2001-1303

    Last Modified: 16 Apr 2026

    The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configuration information for the protected network without authentication.

    Published: 18 Jul 2001
    5
    Medium

    CVE-2001-1373

    Last Modified: 16 Apr 2026

    MailSafe in Zone Labs ZoneAlarm 2.6 and earlier and ZoneAlarm Pro 2.6 and 2.4 does not block prohibited file types with long file names, which allows remote attackers to send potentially dangerous attachments.

    Published: 18 Jul 2001
    7.5
    High

    CVE-2001-1030

    Last Modified: 16 Apr 2026

    Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.

    Published: 18 Jul 2001
    10
    Critical

    CVE-2001-0554

    Last Modified: 16 Apr 2026

    Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.

    Published: 18 Jul 2001
    5
    Medium

    CVE-1999-1569

    Last Modified: 16 Apr 2026

    Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed UDP connection packets, which exceeds the server's player limit.

    Published: 17 Jul 2001
    7.5
    High

    CVE-2001-0974

    Last Modified: 16 Apr 2026

    Format string vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 17 Jul 2001
    7.2
    High

    CVE-2001-1179

    Last Modified: 16 Apr 2026

    xman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters.

    Published: 17 Jul 2001
    7.2
    High

    CVE-2001-1182

    Last Modified: 16 Apr 2026

    Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges.

    Published: 17 Jul 2001
    7.5
    High

    CVE-2001-0980

    Last Modified: 16 Apr 2026

    docview before 1.0-15 allows remote attackers to execute arbitrary commands via shell metacharacters that are processed when converting a man page to a web page.

    Published: 17 Jul 2001
    6.2
    Medium

    CVE-2001-1177

    Last Modified: 16 Apr 2026

    ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 17 Jul 2001
    7.5
    High

    CVE-2001-1241

    Last Modified: 16 Apr 2026

    Un-CGI 1.9 and earlier does not verify that a CGI script has the execution bits set before executing it, which allows remote attackers to execute arbitrary commands by directing Un-CGI to a document that begins with "#!" and the desired program name.

    Published: 17 Jul 2001
    7.5
    High

    CVE-2001-1242

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form.

    Published: 17 Jul 2001
    7.2
    High

    CVE-2001-1181

    Last Modified: 16 Apr 2026

    Dynamically Loadable Kernel Module (dlkm) static kernel symbol table in HP-UX 11.11 is not properly configured, which allows local users to gain privileges.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1313

    Last Modified: 16 Apr 2026

    Lotus Domino R5 before R5.0.7a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via miscellaneous packets with semi-valid BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1317

    Last Modified: 16 Apr 2026

    Teamware Office Enterprise Directory allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for certain BER object types, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1316

    Last Modified: 16 Apr 2026

    Buffer overflows in Teamware Office Enterprise Directory allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1309

    Last Modified: 16 Apr 2026

    Buffer overflows in IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1308

    Last Modified: 16 Apr 2026

    Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-0975

    Last Modified: 16 Apr 2026

    Buffer overflow vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1311

    Last Modified: 16 Apr 2026

    Buffer overflows in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1321

    Last Modified: 16 Apr 2026

    Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1314

    Last Modified: 16 Apr 2026

    Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1315

    Last Modified: 16 Apr 2026

    Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    5
    Medium

    CVE-2001-1319

    Last Modified: 16 Apr 2026

    Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.8
    High

    CVE-2001-1238

    Last Modified: 16 Apr 2026

    Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1310

    Last Modified: 16 Apr 2026

    IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for the L field of a BER encoding, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1312

    Last Modified: 16 Apr 2026

    Format string vulnerabilities in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1318

    Last Modified: 16 Apr 2026

    Vulnerabilities in Qualcomm Eudora WorldMail Server may allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1320

    Last Modified: 16 Apr 2026

    Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via exceptional BER encodings (possibly buffer overflows), as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1306

    Last Modified: 16 Apr 2026

    iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    7.5
    High

    CVE-2001-1307

    Last Modified: 16 Apr 2026

    Buffer overflows in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

    Published: 16 Jul 2001
    5
    Medium

    CVE-2001-0977

    Last Modified: 16 Apr 2026

    slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field.

    Published: 16 Jul 2001
    10
    Critical

    CVE-2001-1053

    Last Modified: 16 Apr 2026

    AdLogin.pm in AdCycle 1.15 and earlier allows remote attackers to bypass authentication and gain privileges by injecting SQL code in the $password argument.

    Published: 13 Jul 2001
    5
    Medium

    CVE-2001-1082

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack.

    Published: 13 Jul 2001
    9.8
    Critical

    CVE-2001-1291

    Last Modified: 16 Apr 2026

    The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.

    Published: 12 Jul 2001
    2.1
    Low

    CVE-2001-1270

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the console version of PKZip (pkzipc) 4.00 and earlier allows attackers to overwrite arbitrary files during archive extraction with the -rec (recursive) option via a .. (dot dot) attack on the archived files.

    Published: 12 Jul 2001
    5
    Medium

    CVE-2001-1142

    Last Modified: 16 Apr 2026

    ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the password file to gain privileges.

    Published: 12 Jul 2001
    2.1
    Low

    CVE-2001-1271

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in rar 2.02 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) attack on archived filenames.

    Published: 12 Jul 2001
    7.5
    High

    CVE-2001-1176

    Last Modified: 16 Apr 2026

    Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via format strings in the control connection.

    Published: 12 Jul 2001
    5
    Medium

    CVE-2001-1183

    Last Modified: 16 Apr 2026

    PPTP implementation in Cisco IOS 12.1 and 12.2 allows remote attackers to cause a denial of service (crash) via a malformed packet.

    Published: 12 Jul 2001
    2.1
    Low

    CVE-2001-1267

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).

    Published: 12 Jul 2001
    7.2
    High

    CVE-2001-1175

    Last Modified: 16 Apr 2026

    vipw in the util-linux package before 2.10 causes /etc/shadow to be world-readable in some cases, which would make it easier for local users to perform brute force password guessing.

    Published: 12 Jul 2001
    6.4
    Medium

    CVE-2001-1120

    Last Modified: 16 Apr 2026

    Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates.

    Published: 11 Jul 2001
    5
    Medium

    CVE-2001-1144

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in McAfee ASaP VirusScan agent 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request.

    Published: 11 Jul 2001
    5
    Medium

    CVE-2001-1143

    Last Modified: 16 Apr 2026

    IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.

    Published: 11 Jul 2001
    7.2
    High

    CVE-2001-1178

    Last Modified: 16 Apr 2026

    Buffer overflow in xman allows local users to gain privileges via a long MANPATH environment variable.

    Published: 11 Jul 2001