CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2001-0288

    Last Modified: 16 Apr 2026

    Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.

    Published: 3 May 2001
    4.6
    Medium

    CVE-2001-0290

    Last Modified: 16 Apr 2026

    Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.

    Published: 3 May 2001
    7.5
    High

    CVE-2001-0319

    Last Modified: 16 Apr 2026

    orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.

    Published: 3 May 2001
    1.2
    Low

    CVE-2001-1331

    Last Modified: 16 Apr 2026

    mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.

    Published: 3 May 2001
    10
    Critical

    CVE-2001-0284

    Last Modified: 16 Apr 2026

    Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option.

    Published: 3 May 2001
    7.2
    High

    CVE-2001-0267

    Last Modified: 16 Apr 2026

    NM debug in HP MPE/iX 6.5 and earlier does not properly handle breakpoints, which allows local users to gain privileges.

    Published: 3 May 2001
    7.5
    High

    CVE-2001-0274

    Last Modified: 16 Apr 2026

    kicq IRC client 1.0.0, and possibly later versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

    Published: 3 May 2001
    7.2
    High

    CVE-2001-0570

    Last Modified: 16 Apr 2026

    minicom 1.83.1 and earlier allows a local attacker to gain additional privileges via numerous format string attacks.

    Published: 3 May 2001
    4.6
    Medium

    CVE-2001-0635

    Last Modified: 16 Apr 2026

    Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can allow a local attacker to gain additional privileges by reading sensitive information from the swap file, such as passwords.

    Published: 2 May 2001
    4.6
    Medium

    CVE-2001-0567

    Last Modified: 16 Apr 2026

    Digital Creations Zope 2.3.2 and earlier allows a local attacker to gain additional privileges via the changing of ZClass permission mappings for objects and methods in the ZClass.

    Published: 2 May 2001
    5
    Medium

    CVE-2001-0328

    Last Modified: 16 Apr 2026

    TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN.

    Published: 1 May 2001
    4.6
    Medium

    CVE-2001-0496

    Last Modified: 16 Apr 2026

    kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.

    Published: 30 Apr 2001
    7.5
    High

    CVE-2001-0550

    Last Modified: 16 Apr 2026

    wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).

    Published: 30 Apr 2001
    7.5
    High

    CVE-2001-1323

    Last Modified: 16 Apr 2026

    Buffer overflow in MIT Kerberos 5 (krb5) 1.2.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via base-64 encoded data, which is not properly handled when the radix_encode function processes file glob output from the ftpglob function.

    Published: 25 Apr 2001
    4.6
    Medium

    CVE-2001-1442

    Last Modified: 16 Apr 2026

    Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privileges via a long -c command line argument.

    Published: 21 Apr 2001
    7.5
    High

    CVE-2001-1325

    Last Modified: 16 Apr 2026

    Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).

    Published: 20 Apr 2001
    7.5
    High

    CVE-2001-0439

    Last Modified: 16 Apr 2026

    licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

    Published: 20 Apr 2001
    7.5
    High

    CVE-2001-0440

    Last Modified: 16 Apr 2026

    Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.

    Published: 20 Apr 2001
    2.1
    Low

    CVE-2001-0406

    Last Modified: 16 Apr 2026

    Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.

    Published: 17 Apr 2001
    7.5
    High

    CVE-2001-0489

    Last Modified: 16 Apr 2026

    Format string vulnerability in gftp prior to 2.0.8 allows remote malicious FTP servers to execute arbitrary commands.

    Published: 17 Apr 2001
    7.5
    High

    CVE-2001-0405

    Last Modified: 16 Apr 2026

    ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.

    Published: 16 Apr 2001
    7.5
    High

    CVE-2001-1467

    Last Modified: 16 Apr 2026

    mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.

    Published: 11 Apr 2001
    7.5
    High

    CVE-2001-1424

    Last Modified: 16 Apr 2026

    Alcatel Speed Touch ADSL modem running firmware KHDSAA.108, KHDSAA.132, KHDSBA.133, and KHDSAA.134 has a blank default password, which allows remote attackers to gain unauthorized access.

    Published: 10 Apr 2001
    7.5
    High

    CVE-2001-1426

    Last Modified: 16 Apr 2026

    Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 has a TFTP server running without a password, which allows remote attackers to change firmware versions or the device's configurations.

    Published: 10 Apr 2001
    7.5
    High

    CVE-2001-1425

    Last Modified: 16 Apr 2026

    The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login.

    Published: 10 Apr 2001
    7.5
    High

    CVE-2001-0596

    Last Modified: 16 Apr 2026

    Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript.

    Published: 9 Apr 2001
    7.5
    High

    CVE-2001-0145

    Last Modified: 16 Apr 2026

    Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0250

    Last Modified: 16 Apr 2026

    The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command.

    Published: 4 Apr 2001
    7.5
    High

    CVE-2001-0256

    Last Modified: 16 Apr 2026

    FaSTream FTP++ Server 2.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long username.

    Published: 4 Apr 2001
    7.5
    High

    CVE-2001-0257

    Last Modified: 16 Apr 2026

    Buffer overflow in Easycom/Safecom Print Server Web service, version 404.590 and earlier, allows remote attackers to execute arbitrary commands via (1) a long URL or (2) a long HTTP header field such as "Host:".

    Published: 4 Apr 2001
    2.1
    Low

    CVE-2001-0261

    Last Modified: 16 Apr 2026

    Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.

    Published: 4 Apr 2001
    10
    Critical

    CVE-2001-0271

    Last Modified: 16 Apr 2026

    mailnews.cgi 1.3 and earlier allows remote attackers to execute arbitrary commands via a user name that contains shell metacharacters.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0272

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the templ parameter.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0270

    Last Modified: 16 Apr 2026

    Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set.

    Published: 4 Apr 2001
    7.2
    High

    CVE-2001-0281

    Last Modified: 16 Apr 2026

    Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.

    Published: 4 Apr 2001
    10
    Critical

    CVE-2001-0285

    Last Modified: 16 Apr 2026

    Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.

    Published: 4 Apr 2001
    10
    Critical

    CVE-2001-0291

    Last Modified: 16 Apr 2026

    Buffer overflow in post-query sample CGI program allows remote attackers to execute arbitrary commands via an HTTP POST request that contains at least 10001 parameters.

    Published: 4 Apr 2001
    7.5
    High

    CVE-2001-0292

    Last Modified: 16 Apr 2026

    PHP-Nuke 4.4.1a allows remote attackers to modify a user's email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0293

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0294

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in TYPSoft FTP Server 0.85 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in a GET command, or (2) a ... in a CWD command.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0302

    Last Modified: 16 Apr 2026

    Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0303

    Last Modified: 16 Apr 2026

    tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0298

    Last Modified: 16 Apr 2026

    Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.

    Published: 4 Apr 2001
    7.5
    High

    CVE-2001-0308

    Last Modified: 16 Apr 2026

    UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0312

    Last Modified: 16 Apr 2026

    IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.

    Published: 4 Apr 2001
    5
    Medium

    CVE-2001-0306

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

    Published: 4 Apr 2001
    7.5
    High

    CVE-2001-0307

    Last Modified: 16 Apr 2026

    Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.

    Published: 4 Apr 2001
    10
    Critical

    CVE-2001-0320

    Last Modified: 16 Apr 2026

    bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.

    Published: 4 Apr 2001
    7.5
    High

    CVE-2001-0325

    Last Modified: 16 Apr 2026

    Buffer overflow in QNX RTP 5.60 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large number of arguments to the stat command.

    Published: 4 Apr 2001
    6.4
    Medium

    CVE-2001-0323

    Last Modified: 16 Apr 2026

    The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host.

    Published: 4 Apr 2001