CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2001-0135

    Last Modified: 16 Apr 2026

    The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.

    Published: 14 Feb 2001
    7.2
    High

    CVE-2001-0112

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.

    Published: 14 Feb 2001
    10
    Critical

    CVE-2001-0301

    Last Modified: 16 Apr 2026

    Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings.

    Published: 13 Feb 2001
    10
    Critical

    CVE-2000-0894

    Last Modified: 16 Apr 2026

    HTTP server on the WatchGuard SOHO firewall does not properly restrict access to administrative functions such as password resets or rebooting, which allows attackers to cause a denial of service or conduct unauthorized activities.

    Published: 12 Feb 2001
    10
    Critical

    CVE-2001-0008

    Last Modified: 16 Apr 2026

    Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.

    Published: 12 Feb 2001
    5
    Medium

    CVE-2001-0009

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack.

    Published: 12 Feb 2001
    5
    Medium

    CVE-2001-0014

    Last Modified: 16 Apr 2026

    Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.

    Published: 12 Feb 2001
    10
    Critical

    CVE-2001-0053

    Last Modified: 16 Apr 2026

    One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.

    Published: 12 Feb 2001
    6.2
    Medium

    CVE-2001-0059

    Last Modified: 16 Apr 2026

    patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.

    Published: 12 Feb 2001
    5
    Medium

    CVE-2001-0081

    Last Modified: 16 Apr 2026

    swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.

    Published: 12 Feb 2001
    7.2
    High

    CVE-2001-0094

    Last Modified: 16 Apr 2026

    Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library) in NetBSD 1.5 and FreeBSD 4.2 and earlier, as used in Kerberised applications such as telnetd and login, allows local users to gain root privileges.

    Published: 12 Feb 2001
    1.2
    Low

    CVE-2001-0095

    Last Modified: 16 Apr 2026

    catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.

    Published: 12 Feb 2001
    10
    Critical

    CVE-2001-0100

    Last Modified: 16 Apr 2026

    bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.

    Published: 12 Feb 2001
    10
    Critical

    CVE-2001-0099

    Last Modified: 16 Apr 2026

    bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.

    Published: 12 Feb 2001
    5
    Medium

    CVE-2001-0106

    Last Modified: 16 Apr 2026

    Vulnerability in inetd server in HP-UX 11.04 and earlier allows attackers to cause a denial of service when the "swait" state is used by a server.

    Published: 12 Feb 2001
    2.1
    Low

    CVE-2001-0020

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack.

    Published: 12 Feb 2001
    2.1
    Low

    CVE-2001-0105

    Last Modified: 16 Apr 2026

    Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the "sys" group.

    Published: 12 Feb 2001
    5
    Medium

    CVE-2001-0003

    Last Modified: 16 Apr 2026

    Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.

    Published: 12 Feb 2001
    6.2
    Medium

    CVE-2001-0005

    Last Modified: 16 Apr 2026

    Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.

    Published: 12 Feb 2001
    7.1
    High

    CVE-2001-0006

    Last Modified: 16 Apr 2026

    The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.

    Published: 12 Feb 2001
    5
    Medium

    CVE-2001-0007

    Last Modified: 16 Apr 2026

    Buffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web administration interface.

    Published: 12 Feb 2001
    2.1
    Low

    CVE-2001-0062

    Last Modified: 16 Apr 2026

    procfs in FreeBSD and possibly other operating systems allows local users to cause a denial of service by calling mmap on the process' own mem file, which causes the kernel to hang.

    Published: 12 Feb 2001
    7.2
    High

    CVE-2001-0063

    Last Modified: 16 Apr 2026

    procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges.

    Published: 12 Feb 2001
    2.1
    Low

    CVE-2001-0078

    Last Modified: 16 Apr 2026

    in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.

    Published: 12 Feb 2001
    5
    Medium

    CVE-2001-0080

    Last Modified: 16 Apr 2026

    Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client, which generates a protocol mismatch error.

    Published: 12 Feb 2001
    5
    Medium

    CVE-2001-0083

    Last Modified: 16 Apr 2026

    Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the "Severed Windows Media Server Connection" vulnerability.

    Published: 12 Feb 2001
    7.2
    High

    CVE-2001-0085

    Last Modified: 16 Apr 2026

    Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands.

    Published: 12 Feb 2001
    5
    Medium

    CVE-2000-0896

    Last Modified: 16 Apr 2026

    WatchGuard SOHO firewall allows remote attackers to cause a denial of service via a flood of fragmented IP packets, which causes the firewall to drop connections and stop forwarding packets.

    Published: 12 Feb 2001
    5
    Medium

    CVE-2001-0004

    Last Modified: 16 Apr 2026

    IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.

    Published: 12 Feb 2001
    7.2
    High

    CVE-2001-0061

    Last Modified: 16 Apr 2026

    procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by forking a child process and executing a privileged process from the child, while the parent retains access to the child's address space.

    Published: 12 Feb 2001
    2.1
    Low

    CVE-2001-0069

    Last Modified: 16 Apr 2026

    dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack.

    Published: 12 Feb 2001
    10
    Critical

    CVE-2000-0895

    Last Modified: 16 Apr 2026

    Buffer overflow in HTTP server on the WatchGuard SOHO firewall allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long GET request.

    Published: 12 Feb 2001
    10
    Critical

    CVE-2001-0028

    Last Modified: 16 Apr 2026

    Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of " (quotation) characters.

    Published: 12 Feb 2001
    5
    Medium

    CVE-2001-0077

    Last Modified: 16 Apr 2026

    The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations.

    Published: 12 Feb 2001
    5
    Medium

    CVE-2001-0096

    Last Modified: 16 Apr 2026

    FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.

    Published: 12 Feb 2001
    4.6
    Medium

    CVE-2001-0560

    Last Modified: 16 Apr 2026

    Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters).

    Published: 10 Feb 2001
    7.5
    High

    CVE-2001-1454

    Last Modified: 16 Apr 2026

    Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.

    Published: 9 Feb 2001
    7.5
    High

    CVE-2001-1453

    Last Modified: 16 Apr 2026

    Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.

    Published: 9 Feb 2001
    3.7
    Low

    CVE-2001-0317

    Last Modified: 16 Apr 2026

    Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.

    Published: 8 Feb 2001
    4.6
    Medium

    CVE-2001-0316

    Last Modified: 16 Apr 2026

    Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.

    Published: 8 Feb 2001
    2.1
    Low

    CVE-2001-1273

    Last Modified: 16 Apr 2026

    The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).

    Published: 8 Feb 2001
    7.5
    High

    CVE-2001-1357

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.

    Published: 7 Feb 2001
    7.2
    High

    CVE-2001-1358

    Last Modified: 16 Apr 2026

    Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.

    Published: 7 Feb 2001
    7.5
    High

    CVE-2001-1468

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code.

    Published: 7 Feb 2001
    5
    Medium

    CVE-2000-0893

    Last Modified: 16 Apr 2026

    The presence of the Distributed GL Daemon (dgld) service on port 5232 on SGI IRIX systems allows remote attackers to identify the target host as an SGI system.

    Published: 2 Feb 2001
    10
    Critical

    CVE-2001-0023

    Last Modified: 16 Apr 2026

    everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.

    Published: 2 Feb 2001
    10
    Critical

    CVE-2001-0024

    Last Modified: 16 Apr 2026

    simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter.

    Published: 2 Feb 2001
    10
    Critical

    CVE-2001-0025

    Last Modified: 16 Apr 2026

    ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.

    Published: 2 Feb 2001
    7.5
    High

    CVE-2001-0027

    Last Modified: 16 Apr 2026

    mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users.

    Published: 2 Feb 2001
    10
    Critical

    CVE-2001-0022

    Last Modified: 16 Apr 2026

    simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter.

    Published: 2 Feb 2001