2.1
    Low

    CVE-2001-1549

    Last Modified: 23 Sept 2012

    Tiny Personal Firewall 1.0 and 2.0 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters.

    Source:Tom Liston
    Published:31 Dec 2001
    7.8
    High

    CVE-2001-1546

    Last Modified: 9 Sept 2012

    Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file.

    Source:shoeboy
    Published:31 Dec 2001
    5
    Medium

    CVE-2001-1528

    Last Modified: 6 Sept 2012

    AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.

    Source:Gary O'Leary-Steele
    Published:31 Dec 2001
    5
    Medium

    CVE-2001-1525

    Last Modified: 8 Sept 2012

    Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly other files via a ".." in the cid parameter.

    Source:markus arndt
    Published:31 Dec 2001
    4.3
    Medium

    CVE-2001-1524

    Last Modified: 8 Sept 2012

    Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and file parameters in modules.php, (3) subject, story and storyext parameters in submit.php, (4) upload parameter in admin.php and (5) fname parameter in friend.php.

    Source:Cabezon Aurélien
    Published:31 Dec 2001
    3.6
    Low

    CVE-2001-1519

    Last Modified: 4 Sept 2012

    RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it

    Source:Camisade
    Published:31 Dec 2001
    2.1
    Low

    CVE-2001-1518

    Last Modified: 5 Sept 2012

    RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. NOTE: the vendor disputes this vulnerability, however the vendor also presents a scenario in which other users could be affected if running on a Terminal Server. Therefore this is a vulnerability.

    Source:Camisade
    Published:31 Dec 2001
    7.5
    High

    CVE-2001-1502

    Last Modified: 6 Sept 2012

    webcart.cgi in Mountain Network Systems WebCart 8.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the NEXTPAGE parameter.

    Published:31 Dec 2001
    5
    Medium

    CVE-2001-1501

    Last Modified: 20 Aug 2012

    The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/" sequences in the argument.

    Source:Frank DENIS
    Published:31 Dec 2001
    5
    Medium

    CVE-2001-1491

    Last Modified: 9 Sept 2012

    Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

    Source:Pavel Titov
    Published:31 Dec 2001
    5
    Medium

    CVE-2001-1490

    Last Modified: 9 Sept 2012

    Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

    Source:Pavel Titov
    Published:31 Dec 2001
    5
    Medium

    CVE-2001-1489

    Last Modified: 9 Sept 2012

    Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

    Source:Pavel Titov
    Published:31 Dec 2001
    4.6
    Medium

    CVE-2001-1487

    Last Modified: 9 Sept 2012

    popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option.

    Source:IhaQueR
    Published:31 Dec 2001
    7.5
    High

    CVE-2001-1473

    Last Modified: 16 Apr 2026

    The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target.

    Published:18 Jan 2001
    4.6
    Medium

    CVE-2001-1472

    Last Modified: 3 Sept 2012

    SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.

    Source:kill-9
    Published:3 Aug 2001
    8.8
    High

    CVE-2001-1471

    Last Modified: 4 Sept 2012

    prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

    Source:UnderSpell
    Published:31 Jul 2001
    7.5
    High

    CVE-2001-1460

    Last Modified: 6 Sept 2012

    SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter.

    Source:anonymous
    Published:13 Oct 2001
    4.6
    Medium

    CVE-2001-1442

    Last Modified: 24 Aug 2012

    Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privileges via a long -c command line argument.

    Source:Enrique A.
    Published:21 Apr 2001
    2.1
    Low

    CVE-2001-1412

    Last Modified: 1 Sept 2012

    nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument.

    Source:Steven Kreuzer
    Published:25 Oct 2003
    5
    Medium

    CVE-2001-1410

    Last Modified: 6 Sept 2012

    Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow attackers to simulate a victim's display and conduct unauthorized activities or steal sensitive data via social engineering.

    Source:Georgi Guninski
    Published:17 Jul 2003
    5
    Medium

    CVE-2001-1408

    Last Modified: 17 Nov 2016

    Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the mailbox parameter.

    Source:kf
    Published:5 Jul 2001
    7.2
    High

    CVE-2001-1384

    Last Modified: 23 Sept 2012

    ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or setgid program that itself calls an unprivileged program, such as newgrp.

    Source:Rafal Wojtczuk
    Published:18 Oct 2001
    10
    Critical

    CVE-2001-1370

    Last Modified: 3 Sept 2012

    prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.

    Source:giancarlo pinerolo
    Published:21 Jul 2001
    4.6
    Medium

    CVE-2001-1354

    Last Modified: 2 Sept 2012

    NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.

    Source:byterage
    Published:20 Jul 2001
    4.6
    Medium

    CVE-2001-1347

    Last Modified: 28 Aug 2012

    Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due to an exception, and allow hijacking of resources such as named pipes.

    Source:Georgi Guninski
    Published:24 May 2001
    1.2
    Low

    CVE-2001-1346

    Last Modified: 28 Aug 2012

    Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.

    Source:Jonas Eriksson
    Published:18 May 2001
    7.5
    High

    CVE-2001-1344

    Last Modified: 29 Aug 2012

    WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).

    Source:Igor Dobrovitski
    Published:12 Jun 2001
    7.5
    High

    CVE-2001-1343

    Last Modified: 29 Aug 2012

    ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.

    Source:Igor Dobrovitski
    Published:12 Jun 2001
    9.8
    Critical

    CVE-2001-1339

    Last Modified: 2 Sept 2012

    Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.

    Source:Courtesy Sentry Research Labs
    Published:24 May 2001
    5
    Medium

    CVE-2001-1335

    Last Modified: 28 Aug 2012

    Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contains a ...%5c (modified dot dot).

    Source:byterage
    Published:27 May 2001
    5
    Medium

    CVE-2001-1334

    Last Modified: 26 Aug 2012

    Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.

    Source:tobozo tagada
    Published:19 May 2002
    7.5
    High

    CVE-2001-1326

    Last Modified: 28 Aug 2012

    Eudora 5.1 allows remote attackers to execute arbitrary code when the "Use Microsoft Viewer" option is enabled and the "allow executables in HTML content" option is disabled, via an HTML email with a form that is activated from an image that the attacker spoofs as a link, which causes the user to execute the form and access embedded attachments.

    Source:http-equiv
    Published:29 May 2001
    7.5
    High

    CVE-2001-1325

    Last Modified: 24 Aug 2012

    Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).

    Source:Georgi Guninski
    Published:20 Apr 2001
    7.5
    High

    CVE-2001-1320

    Last Modified: 6 Mar 2011

    Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via exceptional BER encodings (possibly buffer overflows), as demonstrated by the PROTOS LDAPv3 test suite.

    Source:Metasploit
    Published:16 Jul 2001
    5
    Medium

    CVE-2001-1303

    Last Modified: 2 Sept 2012

    The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configuration information for the protected network without authentication.

    Source:Haroon Meer & Roelof Temmingh
    Published:18 Jul 2001
    9.8
    Critical

    CVE-2001-1291

    Last Modified: 2 Sept 2012

    The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.

    Source:Siberian
    Published:12 Jul 2001
    5
    Medium

    CVE-2001-1290

    Last Modified: 1 Sept 2012

    admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration, gain privileges, and execute arbitrary Perl code via the table_width parameter.

    Source:Igor Dobrovitski
    Published:28 Jun 2001
    5
    Medium

    CVE-2001-1289

    Last Modified: 3 Sept 2012

    Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters.

    Source:Coolest
    Published:29 Jul 2001
    7.5
    High

    CVE-2001-1287

    Last Modified: 3 Nov 2012

    Buffer overflow in Web Calendar in Ipswitch IMail 7.04 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Source:Andrew Griffiths
    Published:12 Oct 2001
    7.5
    High

    CVE-2001-1274

    Last Modified: 17 Aug 2012

    Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.

    Source:Luis Miguel Silva
    Published:19 Jan 2001
    5
    Medium

    CVE-2001-1263

    Last Modified: 29 Aug 2012

    telnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large number of characters to port 23, possibly due to a buffer overflow.

    Source:nemesystm
    Published:6 Jun 2001
    5
    Medium

    CVE-2001-1259

    Last Modified: 12 Dec 2012

    Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload.

    Source:Jacek Lipkowski
    Published:7 Aug 2001
    7.5
    High

    CVE-2001-1246

    Last Modified: 1 Sept 2012

    PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

    Source:Wojciech Purczynski
    Published:30 Jun 2001
    5
    Medium

    CVE-2001-1244

    Last Modified: 6 Sept 2016

    Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.

    Source:Darren Reed
    Published:7 Jul 2001
    5
    Medium

    CVE-2001-1243

    Last Modified: 1 Sept 2012

    Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.

    Source:VIPER_SV
    Published:4 Jul 2001
    5
    Medium

    CVE-2001-1212

    Last Modified: 9 Sept 2012

    Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascript via the desc parameter.

    Source:Tamer Sahin
    Published:18 Dec 2001
    5
    Medium

    CVE-2001-1209

    Last Modified: 9 Sept 2012

    Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:blackshell
    Published:31 Dec 2001
    7.5
    High

    CVE-2001-1202

    Last Modified: 9 Sept 2012

    Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error.

    Source:SNS Research
    Published:28 Dec 2001
    7.5
    High

    CVE-2001-1199

    Last Modified: 9 Sept 2012

    Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter.

    Source:Tamer Sahin
    Published:17 Dec 2001
    10
    Critical

    CVE-2001-1196

    Last Modified: 9 Sept 2012

    Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument.

    Source:A. Ramos
    Published:17 Dec 2001