10
    Critical

    CVE-2001-0803

    Last Modified: 16 Apr 2026

    Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.

    Source:noir
    Published:6 Dec 2001
    10
    Critical

    CVE-2001-0800

    Last Modified: 1 Apr 2017

    lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.

    Source:H D Moore
    Published:22 Nov 2001
    10
    Critical

    CVE-2001-0797

    Last Modified: 6 Mar 2011

    Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.

    Source:Metasploit
    Published:12 Dec 2001
    5
    Medium

    CVE-2001-0791

    Last Modified: 28 Aug 2012

    Trend Micro InterScan VirusWall for Windows NT allows remote attackers to make configuration changes by directly calling certain CGI programs, which do not restrict access.

    Source:snsadv
    Published:12 Oct 2001
    5
    Medium

    CVE-2001-0788

    Last Modified: 30 Aug 2012

    Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute path for the server directory by viewing the Location header.

    Source:SNS Research
    Published:12 Oct 2001
    4.6
    Medium

    CVE-2001-0787

    Last Modified: 15 Nov 2017

    LPRng in Red Hat Linux 7.0 and 7.1 does not properly drop memberships in supplemental groups when lowering privileges, which could allow a local user to elevate privileges.

    Source:zen-parse
    Published:12 Jun 2001
    5
    Medium

    CVE-2001-0784

    Last Modified: 1 Sept 2012

    Directory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack using encoded URL characters.

    Source:gollum
    Published:26 Jun 2001
    7.2
    High

    CVE-2001-0782

    Last Modified: 31 Aug 2012

    KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.

    Source:IhaQueR
    Published:12 Oct 2001
    5
    Medium

    CVE-2001-0780

    Last Modified: 28 Aug 2012

    Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information via a .. (dot dot) in the SHOW parameter.

    Source:Marshal
    Published:12 Oct 2001
    10
    Critical

    CVE-2001-0779

    Last Modified: 2 Sept 2012

    Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.

    Source:metaray
    Published:18 Oct 2001
    5
    Medium

    CVE-2001-0778

    Last Modified: 28 Aug 2012

    OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20).

    Source:astral
    Published:12 Oct 2001
    7.5
    High

    CVE-2001-0775

    Last Modified: 15 Nov 2017

    Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field.

    Source:zenith parsec
    Published:10 Jul 2001
    9.8
    Critical

    CVE-2001-0766

    Last Modified: 29 Aug 2012

    Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.

    Source:Stefan Arentz
    Published:12 Oct 2001
    7.2
    High

    CVE-2001-0764

    Last Modified: 31 Aug 2012

    Buffer overflow in ntping in scotty 2.1.0 allows local users to execute arbitrary code via a long hostname as a command line argument.

    Source:Larry W. Cashdollar
    Published:18 Oct 2001
    7.5
    High

    CVE-2001-0763

    Last Modified: 29 Aug 2012

    Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response, which is not properly handled by the svc_logprint function.

    Source:qitest1
    Published:8 Jun 2001
    4.6
    Medium

    CVE-2001-0762

    Last Modified: 29 Aug 2012

    Buffer overflow in su-wrapper 1.1.1 allows local users to execute arbitrary code via a long first argument.

    Source:dex
    Published:12 Oct 2001
    5
    Medium

    CVE-2001-0760

    Last Modified: 1 Sept 2012

    Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field.

    Source:sween
    Published:18 Oct 2001
    7.2
    High

    CVE-2001-0759

    Last Modified: 30 Aug 2012

    Buffer overflow in bctool in Jetico BestCrypt 0.8.1 and earlier allows local users to execute arbitrary code via a file or directory with a long pathname, which is processed during an unmount.

    Source:Carl Livitt
    Published:12 Oct 2001
    7.5
    High

    CVE-2001-0758

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via "CWD ..." command.

    Published:12 Oct 2001
    7.5
    High

    CVE-2001-0751

    Last Modified: 2 Jul 2012

    Cisco switches and routers running CBOS 2.3.8 and earlier use predictable TCP Initial Sequence Numbers (ISN), which allows remote attackers to spoof or hijack TCP connections.

    Source:Stealth & S. Krahmer
    Published:18 Oct 2001
    5
    Medium

    CVE-2001-0748

    Last Modified: 28 Aug 2012

    Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several / (slash) characters to the URI.

    Source:Adnan Rahman
    Published:18 Oct 2001
    10
    Critical

    CVE-2001-0746

    Last Modified: 27 Aug 2012

    Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods.

    Source:Santi Claus
    Published:12 Oct 2001
    5
    Medium

    CVE-2001-0743

    Last Modified: 29 Aug 2012

    Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followed by JavaScript commands.

    Source:Helmuth Antholzer
    Published:12 Oct 2001
    2.1
    Low

    CVE-2001-0741

    Last Modified: 2 Sept 2012

    Cisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets.

    Source:bashis
    Published:18 Oct 2001
    5
    Medium

    CVE-2001-0740

    Last Modified: 26 Aug 2012

    3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attackers to cause a denial of service via a long string containing a large number of "%s" strings, possibly triggering a format string vulnerability.

    Source:Sniffer
    Published:18 Oct 2001
    2.1
    Low

    CVE-2001-0736

    Last Modified: 13 Aug 2012

    Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.

    Source:mat
    Published:31 Mar 2001
    7.2
    High

    CVE-2001-0735

    Last Modified: 31 Aug 2012

    Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file.

    Source:teleh0r
    Published:12 Oct 2001
    5
    Medium

    CVE-2001-0731

    Last Modified: 2 Sept 2012

    Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.

    Source:Kevin
    Published:9 Jul 2001
    6.4
    Medium

    CVE-2001-0722

    Last Modified: 7 Sept 2012

    Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."

    Source:Jouko Pynnonen
    Published:6 Dec 2001
    5
    Medium

    CVE-2001-0711

    Last Modified: 20 Aug 2012

    Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management Interface (ILMI) SNMP community string.

    Source:pask
    Published:31 Aug 2001
    2.1
    Low

    CVE-2001-0706

    Last Modified: 30 Aug 2012

    Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies a large number of sub-folders.

    Source:Jass Seljamaa
    Published:20 Sept 2001
    5
    Medium

    CVE-2001-0705

    Last Modified: 30 Aug 2012

    Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument.

    Source:ViperSV
    Published:29 Aug 2001
    7.5
    High

    CVE-2001-0704

    Last Modified: 30 Aug 2012

    tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist.

    Source:ViperSV
    Published:29 Aug 2001
    5
    Medium

    CVE-2001-0703

    Last Modified: 6 Sept 2016

    tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with an MS-DOS device name in the template parameter.

    Source:NERF Security
    Published:29 Aug 2001
    7.5
    High

    CVE-2001-0702

    Last Modified: 12 May 2017

    Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) password, or (3) PASV command.

    Source:Cartel
    Published:29 Aug 2001
    7.2
    High

    CVE-2001-0701

    Last Modified: 30 Aug 2012

    Buffer overflow in ptexec in the Sun Validation Test Suite 4.3 and earlier allows a local user to gain privileges via a long -o argument.

    Source:Pablo Sor
    Published:20 Sept 2001
    7.5
    High

    CVE-2001-0700

    Last Modified: 30 Aug 2012

    Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header.

    Source:White_E
    Published:20 Sept 2001
    5
    Medium

    CVE-2001-0697

    Last Modified: 11 Jul 2017

    NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.

    Source:the Strumpf Noir Society
    Published:20 Sept 2001
    5
    Medium

    CVE-2001-0693

    Last Modified: 29 Aug 2012

    WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).

    Source:Auriemma Luigi
    Published:29 Aug 2001
    7.5
    High

    CVE-2001-0690

    Last Modified: 29 Aug 2012

    Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers.

    Source:Megyer Laszlo
    Published:6 Jun 2001
    5
    Medium

    CVE-2001-0688

    Last Modified: 29 Aug 2012

    Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command.

    Source:byterage
    Published:29 Aug 2001
    2.6
    Low

    CVE-2001-0685

    Last Modified: 29 Aug 2012

    Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file.

    Source:Uwe Ohse
    Published:20 Sept 2001
    5
    Medium

    CVE-2001-0680

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a "dot dot" attack in a LIST (ls) command.

    Published:20 Sept 2001
    10
    Critical

    CVE-2001-0679

    Last Modified: 5 Jul 2012

    A buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to the server.

    Source:Alain Thivillon & Stephane Aubert
    Published:8 Nov 1999
    5
    Medium

    CVE-2001-0675

    Last Modified: 27 Aug 2012

    Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a carriage return <CR> that is not followed by a line feed <LF>.

    Source:3APA3A
    Published:20 Sept 2001
    7.5
    High

    CVE-2001-0669

    Last Modified: 5 Sept 2012

    Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL.

    Source:blackangels
    Published:12 Oct 2001
    7.5
    High

    CVE-2001-0664

    Last Modified: 6 Sept 2012

    Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing vulnerability."

    Source:kikkert security
    Published:30 Oct 2001
    5
    Medium

    CVE-2001-0663

    Last Modified: 23 Sept 2012

    Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.

    Source:Luciano Martins
    Published:6 Dec 2001
    4.6
    Medium

    CVE-2001-0653

    Last Modified: 4 Sept 2012

    Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d) command line arguments, which is interpreted as a negative number.

    Source:grange
    Published:21 Aug 2001
    7.2
    High

    CVE-2001-0652

    Last Modified: 4 Sept 2012

    Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.

    Source:Nsfocus
    Published:30 Oct 2001