CVE Feed

    Dashboard / CVE

    1.2
    Low

    CVE-2001-1333

    Last Modified: 16 Apr 2026

    Linux CUPS before 1.1.6 does not securely handle temporary files, possibly due to a symlink vulnerability that could allow local users to overwrite files.

    Published: 5 Mar 2001
    7.5
    High

    CVE-2001-1332

    Last Modified: 16 Apr 2026

    Buffer overflows in Linux CUPS before 1.1.6 may allow remote attackers to execute arbitrary code.

    Published: 5 Mar 2001
    7.5
    High

    CVE-2001-1103

    Last Modified: 16 Apr 2026

    FTP Voyager ActiveX control before 8.0, when it is marked as safe for scripting (the default) or if allowed by the IObjectSafety interface, allows remote attackers to execute arbitrary commands.

    Published: 3 Mar 2001
    7.5
    High

    CVE-2001-1445

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the SMTP server in Lotus Domino 5.0 through 5.7 allows remote attackers to bypass mail relaying restrictions via crafted e-mail addresses in "RCPT TO" commands.

    Published: 1 Mar 2001
    7.2
    High

    CVE-2001-0556

    Last Modified: 16 Apr 2026

    The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users' files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file.

    Published: 1 Mar 2001
    5
    Medium

    CVE-2001-1434

    Last Modified: 16 Apr 2026

    Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topology information via an "snmp-server host" command, which creates a readable "community" community string if one has not been previously created.

    Published: 28 Feb 2001
    7.5
    High

    CVE-2004-1776

    Last Modified: 16 Apr 2026

    Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data via the cable-docsis read-write community string used by the Data Over Cable Service Interface Specification (DOCSIS) standard.

    Published: 28 Feb 2001
    4.6
    Medium

    CVE-2001-0289

    Last Modified: 16 Apr 2026

    Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory.

    Published: 28 Feb 2001
    5
    Medium

    CVE-2001-1435

    Last Modified: 16 Apr 2026

    inetd in Compaq Tru64 UNIX 5.1 allows attackers to cause a denial of service (network connection loss) by causing one of the services handled by inetd to core dump during startup, which causes inetd to stop accepting connections to all of its services.

    Published: 23 Feb 2001
    2.1
    Low

    CVE-2001-0568

    Last Modified: 16 Apr 2026

    Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes.

    Published: 23 Feb 2001
    2.1
    Low

    CVE-2001-0569

    Last Modified: 16 Apr 2026

    Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) ObjectManager, (2) PropertyManager, and (3) PropertySheet.

    Published: 23 Feb 2001
    7.2
    High

    CVE-2001-0279

    Last Modified: 16 Apr 2026

    Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.

    Published: 22 Feb 2001
    7.2
    High

    CVE-2001-1374

    Last Modified: 16 Apr 2026

    expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.

    Published: 18 Feb 2001
    4.6
    Medium

    CVE-2001-1375

    Last Modified: 16 Apr 2026

    tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before other directories, which could allow local users to execute arbitrary code via a Trojan horse library that is under a user-controlled directory.

    Published: 18 Feb 2001
    1.2
    Low

    CVE-2000-0890

    Last Modified: 16 Apr 2026

    periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack.

    Published: 16 Feb 2001
    7.2
    High

    CVE-2001-0034

    Last Modified: 16 Apr 2026

    KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.

    Published: 16 Feb 2001
    7.2
    High

    CVE-2001-0035

    Last Modified: 16 Apr 2026

    Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request.

    Published: 16 Feb 2001
    7.8
    High

    CVE-2001-0041

    Last Modified: 16 Apr 2026

    Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts.

    Published: 16 Feb 2001
    5
    Medium

    CVE-2001-0042

    Last Modified: 16 Apr 2026

    PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.

    Published: 16 Feb 2001
    10
    Critical

    CVE-2001-0043

    Last Modified: 16 Apr 2026

    phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program.

    Published: 16 Feb 2001
    5
    Medium

    CVE-2001-0039

    Last Modified: 16 Apr 2026

    IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.

    Published: 16 Feb 2001
    2.1
    Low

    CVE-2001-0040

    Last Modified: 16 Apr 2026

    APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file.

    Published: 16 Feb 2001
    7.5
    High

    CVE-2001-0056

    Last Modified: 16 Apr 2026

    The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.

    Published: 16 Feb 2001
    5
    Medium

    CVE-2001-0057

    Last Modified: 16 Apr 2026

    Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.

    Published: 16 Feb 2001
    2.6
    Low

    CVE-2001-0091

    Last Modified: 16 Apr 2026

    The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.

    Published: 16 Feb 2001
    2.6
    Low

    CVE-2001-0092

    Last Modified: 16 Apr 2026

    A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.

    Published: 16 Feb 2001
    5
    Medium

    CVE-2001-0055

    Last Modified: 16 Apr 2026

    CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.

    Published: 16 Feb 2001
    10
    Critical

    CVE-2001-0021

    Last Modified: 16 Apr 2026

    MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.

    Published: 16 Feb 2001
    7.2
    High

    CVE-2001-0033

    Last Modified: 16 Apr 2026

    KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.

    Published: 16 Feb 2001
    2.6
    Low

    CVE-2001-0089

    Last Modified: 16 Apr 2026

    Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.

    Published: 16 Feb 2001
    5.1
    Medium

    CVE-2001-0090

    Last Modified: 16 Apr 2026

    The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the "Browser Print Template" vulnerability.

    Published: 16 Feb 2001
    5
    Medium

    CVE-2001-0054

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.

    Published: 16 Feb 2001
    5
    Medium

    CVE-2001-0058

    Last Modified: 16 Apr 2026

    The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character.

    Published: 16 Feb 2001
    2.1
    Low

    CVE-2001-1439

    Last Modified: 16 Apr 2026

    Buffer overflow in the text editor functionality in HP-UX 10.01 through 11.04 on HP9000 Series 700 and Series 800 allows local users to cause a denial of service ("system availability") via text editors such as (1) e, (2) ex, (3) vi, (4) edit, (5) view, and (6) vedit.

    Published: 16 Feb 2001
    7.5
    High

    CVE-1999-0359

    Last Modified: 16 Apr 2026

    ptylogin in Unix systems allows users to perform a denial of service by locking out modems, dial out with that modem, or obtain passwords.

    Published: 14 Feb 2001
    2.1
    Low

    CVE-1999-0757

    Last Modified: 16 Apr 2026

    The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates.

    Published: 14 Feb 2001
    5
    Medium

    CVE-1999-0784

    Last Modified: 16 Apr 2026

    Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.

    Published: 14 Feb 2001
    7.2
    High

    CVE-2000-0312

    Last Modified: 16 Apr 2026

    cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron's fake popen function.

    Published: 14 Feb 2001
    5
    Medium

    CVE-2001-0107

    Last Modified: 16 Apr 2026

    Veritas Backup agent on Linux allows remote attackers to cause a denial of service by establishing a connection without sending any data, which causes the process to hang.

    Published: 14 Feb 2001
    5
    Medium

    CVE-2001-0114

    Last Modified: 16 Apr 2026

    statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.

    Published: 14 Feb 2001
    7.6
    High

    CVE-2001-0127

    Last Modified: 16 Apr 2026

    Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag.

    Published: 14 Feb 2001
    10
    Critical

    CVE-2001-0133

    Last Modified: 16 Apr 2026

    The web administration interface for Interscan VirusWall 3.6.x and earlier does not use encryption, which could allow remote attackers to obtain the administrator password to sniff the administrator password via the setpasswd.cgi program or other HTTP GET requests that contain base64 encoded usernames and passwords.

    Published: 14 Feb 2001
    1.2
    Low

    CVE-2001-0132

    Last Modified: 16 Apr 2026

    Interscan VirusWall 3.6.x and earlier follows symbolic links when uninstalling the product, which allows local users to overwrite arbitrary files via a symlink attack.

    Published: 14 Feb 2001
    7.5
    High

    CVE-1999-0923

    Last Modified: 16 Apr 2026

    Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.

    Published: 14 Feb 2001
    5
    Medium

    CVE-1999-0805

    Last Modified: 16 Apr 2026

    Novell NetWare Transaction Tracking System (TTS) in Novell 4.11 and earlier allows remote attackers to cause a denial of service via a large number of requests.

    Published: 14 Feb 2001
    10
    Critical

    CVE-2001-0113

    Last Modified: 16 Apr 2026

    statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script.

    Published: 14 Feb 2001
    10
    Critical

    CVE-2001-0134

    Last Modified: 16 Apr 2026

    Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.

    Published: 14 Feb 2001
    2.1
    Low

    CVE-2001-0135

    Last Modified: 16 Apr 2026

    The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.

    Published: 14 Feb 2001
    7.2
    High

    CVE-2001-0112

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.

    Published: 14 Feb 2001
    10
    Critical

    CVE-2001-0301

    Last Modified: 16 Apr 2026

    Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings.

    Published: 13 Feb 2001