5
    Medium

    CVE-2001-0649

    Last Modified: 26 Aug 2012

    Personal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request.

    Source:Jass Seljamaa
    Published:29 Aug 2001
    5
    Medium

    CVE-2001-0647

    Last Modified: 20 Aug 2012

    Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version.

    Source:slipy
    Published:6 Aug 2001
    5
    Medium

    CVE-2001-0646

    Last Modified: 26 Aug 2012

    Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specific length.

    Source:Jass Seljamaa
    Published:20 Sept 2001
    5
    Medium

    CVE-2001-0643

    Last Modified: 27 Aug 2012

    Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type.

    Source:Georgi Guninski
    Published:20 Sept 2001
    4.6
    Medium

    CVE-2001-0641

    Last Modified: 2 Sept 2012

    Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group man via a long -S option.

    Source:zenith parsec
    Published:13 May 2001
    5
    Medium

    CVE-2001-0630

    Last Modified: 28 Aug 2012

    Directory traversal vulnerability in MIMAnet viewsrc.cgi 2.0 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the 'loc' variable.

    Source:joetesta
    Published:22 Aug 2001
    7.5
    High

    CVE-2001-0626

    Last Modified: 20 Aug 2012

    O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character.

    Source:Roberto Moreno
    Published:22 Aug 2001
    4.6
    Medium

    CVE-2001-0623

    Last Modified: 25 Aug 2012

    sendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop privileges when sending notification emails, which allows local attackers to gain privileges.

    Source:Cade Cairns
    Published:27 Jul 2001
    5
    Medium

    CVE-2001-0616

    Last Modified: 28 Aug 2012

    Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (e.g., GET /aux HTTP/1.0).

    Source:nemesystm
    Published:14 Aug 2001
    5
    Medium

    CVE-2001-0615

    Last Modified: 28 Aug 2012

    Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'.

    Source:nemesystm
    Published:14 Aug 2001
    7.5
    High

    CVE-2001-0614

    Last Modified: 26 Aug 2012

    Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially constructed URL.

    Source:Peter Gründl
    Published:27 Jul 2001
    4.6
    Medium

    CVE-2001-0610

    Last Modified: 24 Aug 2012

    kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in /tmp.

    Source:Paul Starzetz
    Published:27 Jul 2001
    9.8
    Critical

    CVE-2001-0609

    Last Modified: 22 Aug 2012

    Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.

    Source:Lez
    Published:27 Jul 2001
    7.2
    High

    CVE-2001-0597

    Last Modified: 22 Aug 2012

    Zetetic Secure Tool for Recalling Important Passwords (STRIP) 0.5 and earlier for the PalmOS allows a local attacker to recover passwords via a brute force attack. This attack is made feasible by STRIP's use of SysRandom, which is seeded by TimeGetTicks, and an implementation flaw which vastly reduces the password 'search space'.

    Source:Thomas Roessler
    Published:27 Jul 2001
    7.5
    High

    CVE-2001-0596

    Last Modified: 25 Aug 2012

    Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript.

    Source:Florian Wesch
    Published:9 Apr 2001
    4.6
    Medium

    CVE-2001-0595

    Last Modified: 15 Nov 2017

    Buffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute arbitrary commands via the KCMS_PROFILES environment variable, e.g. as demonstrated using the kcms_configure program.

    Source:Last Stage of Delirium
    Published:2 Aug 2001
    4.6
    Medium

    CVE-2001-0594

    Last Modified: 22 Aug 2012

    kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.

    Source:Riley Hassell
    Published:2 Aug 2001
    5
    Medium

    CVE-2001-0593

    Last Modified: 22 Aug 2012

    Anaconda Partners Clipper 3.3 and earlier allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the template parameter.

    Source:UkR hacking team
    Published:22 Aug 2001
    5
    Medium

    CVE-2001-0590

    Last Modified: 22 Aug 2012

    Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).

    Source:lovehacker
    Published:2 Aug 2001
    2.1
    Low

    CVE-2001-0584

    Last Modified: 20 Aug 2012

    IMAP server in Alt-N Technologies MDaemon 3.5.6 allows a local user to cause a denial of service (hang) via long (1) SELECT or (2) EXAMINE commands.

    Source:nitr0s
    Published:27 Jul 2001
    5
    Medium

    CVE-2001-0581

    Last Modified: 2 Sept 2012

    Spytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large number of connections to port 6387.

    Source:nemesystm
    Published:27 Jul 2001
    5
    Medium

    CVE-2001-0580

    Last Modified: 26 Aug 2012

    Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting to port 6070, sending some data, and closing the connection.

    Source:neme-dhc
    Published:27 Jul 2001
    7.5
    High

    CVE-2001-0579

    Last Modified: 22 Aug 2012

    lpadmin in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first argument to the command.

    Source:Secure Network Operations
    Published:27 Jul 2001
    4.6
    Medium

    CVE-2001-0578

    Last Modified: 22 Aug 2012

    Buffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a long first argument to the lpforms command.

    Source:Secure Network Operations
    Published:27 Jul 2001
    7.2
    High

    CVE-2001-0577

    Last Modified: 22 Aug 2012

    recon in SCO OpenServer 5.0 through 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first command line argument.

    Source:Secure Network Operations
    Published:27 Jul 2001
    4.6
    Medium

    CVE-2001-0576

    Last Modified: 22 Aug 2012

    lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the '-u' command line parameter.

    Source:Secure Network Operations
    Published:27 Jul 2001
    4.6
    Medium

    CVE-2001-0575

    Last Modified: 22 Aug 2012

    Buffer overflow in lpshut in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a long first argument to lpshut.

    Source:Secure Network Operations
    Published:27 Jul 2001
    5
    Medium

    CVE-2001-0574

    Last Modified: 26 Aug 2012

    Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot) in the URL.

    Source:neme-dhc
    Published:14 Aug 2001
    5
    Medium

    CVE-2001-0571

    Last Modified: 22 Aug 2012

    Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the requested URL.

    Source:Erik Tayler
    Published:27 Jul 2001
    5
    Medium

    CVE-2001-0566

    Last Modified: 24 Jan 2017

    Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disabled.

    Source:bashis
    Published:27 Jul 2001
    4.6
    Medium

    CVE-2001-0565

    Last Modified: 24 Aug 2012

    Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.

    Source:Pablo Sor
    Published:14 Aug 2001
    5
    Medium

    CVE-2001-0564

    Last Modified: 20 Aug 2012

    APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of service via repeated failed logon attempts which temporarily locks the card.

    Source:altomo
    Published:22 Aug 2001
    5
    Medium

    CVE-2001-0563

    Last Modified: 2 Sept 2012

    ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via large (> 160000 character) strings sent to port 23.

    Source:nemesystm
    Published:14 Aug 2001
    7.5
    High

    CVE-2001-0561

    Last Modified: 26 Aug 2012

    Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.

    Source:neme-dhc
    Published:27 Jul 2001
    7.2
    High

    CVE-2001-0559

    Last Modified: 26 Aug 2012

    crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.

    Source:Sebastian Krahmer
    Published:14 Aug 2001
    5
    Medium

    CVE-2001-0558

    Last Modified: 26 Aug 2012

    T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0).

    Source:neme-dhc
    Published:14 Aug 2001
    5
    Medium

    CVE-2001-0557

    Last Modified: 26 Aug 2012

    T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).

    Source:neme-dhc
    Published:27 Jul 2001
    10
    Critical

    CVE-2001-0555

    Last Modified: 30 Aug 2012

    ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITEWare Editor's Desktop or (2) the template parameter in SWEditServlet.

    Source:Foundstone Labs
    Published:27 Jul 2001
    10
    Critical

    CVE-2001-0554

    Last Modified: 2 Sept 2012

    Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.

    Source:Dvorak
    Published:18 Jul 2001
    7.2
    High

    CVE-2001-0553

    Last Modified: 2 Sept 2012

    SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field.

    Source:hypoclear
    Published:14 Aug 2001
    10
    Critical

    CVE-2001-0552

    Last Modified: 29 Aug 2012

    ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message.

    Source:Milo van der Zee
    Published:29 Aug 2001
    7.5
    High

    CVE-2001-0550

    Last Modified: 4 Dec 2016

    wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).

    Source:Teso
    Published:30 Apr 2001
    4.6
    Medium

    CVE-2001-0548

    Last Modified: 3 Sept 2012

    Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.

    Source:NSFOCUS Security Team
    Published:14 Aug 2001
    10
    Critical

    CVE-2001-0538

    Last Modified: 2 Sept 2012

    Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.

    Source:Georgi Guninski
    Published:14 Aug 2001
    9.3
    Critical

    CVE-2001-0537

    Last Modified: 15 Jun 2017

    HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.

    Source:cronos
    Published:21 Jul 2001
    10
    Critical

    CVE-2001-0527

    Last Modified: 2 Nov 2017

    DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.

    Source:Franklin DeMatto
    Published:14 Aug 2001
    4.6
    Medium

    CVE-2001-0526

    Last Modified: 16 Apr 2026

    Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable.

    Published:14 Aug 2001
    7.5
    High

    CVE-2001-0522

    Last Modified: 2 Sept 2012

    Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.

    Source:fish stiqz
    Published:29 May 2001
    7.5
    High

    CVE-2001-0521

    Last Modified: 2 Sept 2012

    Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.

    Source:eDvice Security Services
    Published:27 Jul 2001
    7.5
    High

    CVE-2001-0520

    Last Modified: 28 Aug 2012

    Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT tag, or (5) any other tag in which scripts can be defined.

    Source:eDvice Security Services
    Published:27 Jul 2001