7.5
    High

    CVE-2001-0519

    Last Modified: 28 Aug 2012

    Aladdin eSafe Gateway versions 2.x allows a remote attacker to circumvent HTML SCRIPT filtering via a special arrangement of HTML tags which includes SCRIPT tags embedded within other SCRIPT tags.

    Source:eDvice Security Services
    Published:27 Jul 2001
    7.2
    High

    CVE-2001-0507

    Last Modified: 10 Sept 2012

    IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.

    Source:Digital Offense
    Published:20 Sept 2001
    7.2
    High

    CVE-2001-0506

    Last Modified: 4 Sept 2012

    Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.

    Source:Indigo
    Published:20 Sept 2001
    10
    Critical

    CVE-2001-0500

    Last Modified: 8 Dec 2016

    Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.

    Source:Ps0
    Published:21 Jul 2001
    10
    Critical

    CVE-2001-0499

    Last Modified: 27 Oct 2016

    Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.

    Source:Metasploit
    Published:21 Jul 2001
    5
    Medium

    CVE-2001-0495

    Last Modified: 25 Aug 2012

    Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack.

    Source:joetesta
    Published:27 Jun 2001
    5
    Medium

    CVE-2001-0491

    Last Modified: 25 Aug 2012

    Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks, such as (1) .... in CWD, (2) .. in NLST, or (3) ... in NLST.

    Source:joetesta
    Published:24 May 2001
    7.5
    High

    CVE-2001-0490

    Last Modified: 2 Sept 2012

    Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file.

    Source:byterage
    Published:24 May 2001
    5
    Medium

    CVE-2001-0486

    Last Modified: 16 Apr 2026

    Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353.

    Source:honoriak
    Published:2 Jul 2001
    7.2
    High

    CVE-2001-0485

    Last Modified: 22 Nov 2017

    Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option.

    Source:LSD-PLaNET
    Published:27 Jun 2001
    6.4
    Medium

    CVE-2001-0484

    Last Modified: 25 Aug 2012

    Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages.

    Source:Ltlw0lf
    Published:24 May 2001
    7.5
    High

    CVE-2001-0476

    Last Modified: 20 Aug 2012

    Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter.

    Source:teleh0r
    Published:24 May 2001
    7.5
    High

    CVE-2001-0471

    Last Modified: 18 Aug 2012

    SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.

    Source:Jose Nazario
    Published:24 May 2001
    7.2
    High

    CVE-2001-0468

    Last Modified: 20 Aug 2012

    Buffer overflow in FTPFS allows local users to gain root privileges via a long user name.

    Source:Frank DENIS
    Published:24 May 2001
    5
    Medium

    CVE-2001-0467

    Last Modified: 25 Aug 2012

    Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a \... (modified dot dot) in an HTTP URL request.

    Source:joetesta
    Published:27 Jun 2001
    5
    Medium

    CVE-2001-0466

    Last Modified: 22 Aug 2012

    Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:UkR hacking team
    Published:24 May 2001
    10
    Critical

    CVE-2001-0464

    Last Modified: 24 Aug 2012

    Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter.

    Source:Enrique A.
    Published:24 May 2001
    5
    Medium

    CVE-2001-0463

    Last Modified: 25 Aug 2012

    Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.

    Source:ThePike
    Published:27 Jun 2001
    5
    Medium

    CVE-2001-0462

    Last Modified: 25 Aug 2012

    Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Source:neme-dhc
    Published:27 Jun 2001
    7.5
    High

    CVE-2001-0461

    Last Modified: 20 Aug 2012

    template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell metacharacters in the argument to template.cgi.

    Source:Cgisecurity
    Published:27 Jun 2001
    5
    Medium

    CVE-2001-0460

    Last Modified: 20 Aug 2012

    Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header.

    Source:honoriak
    Published:24 May 2001
    7.2
    High

    CVE-2001-0459

    Last Modified: 15 Nov 2017

    Buffer overflows in ascdc Afterstep while running setuid allows local users to gain root privileges via a long (1) -d option, (2) -m option, or (3) -f option.

    Source:anonymous
    Published:24 May 2001
    5
    Medium

    CVE-2001-0454

    Last Modified: 20 Aug 2012

    Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in the HTTP request.

    Source:joetesta
    Published:24 May 2001
    5
    Medium

    CVE-2001-0452

    Last Modified: 26 Aug 2012

    BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.

    Source:joetesta
    Published:24 May 2001
    7.5
    High

    CVE-2001-0442

    Last Modified: 25 Aug 2012

    Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP command.

    Source:Przemyslaw Frasunek
    Published:27 Jun 2001
    7.5
    High

    CVE-2001-0440

    Last Modified: 20 Aug 2012

    Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.

    Source:Stan Bubrouski
    Published:20 Apr 2001
    10
    Critical

    CVE-2001-0432

    Last Modified: 22 Aug 2012

    Buffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote attackers to execute arbitrary commands.

    Source:eeye security
    Published:24 May 2001
    7.2
    High

    CVE-2001-0426

    Last Modified: 15 Nov 2017

    Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.

    Source:Last Stage of Delirium
    Published:24 May 2001
    7.5
    High

    CVE-2001-0425

    Last Modified: 18 Aug 2012

    AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to verify login information.

    Source:Neil K
    Published:24 May 2001
    7.2
    High

    CVE-2001-0423

    Last Modified: 22 Aug 2012

    Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.

    Source:Riley Hassell
    Published:2 Jul 2001
    7.2
    High

    CVE-2001-0422

    Last Modified: 22 Aug 2012

    Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.

    Source:Riley Hassell
    Published:2 Jul 2001
    6.4
    Medium

    CVE-2001-0421

    Last Modified: 24 Aug 2012

    FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.

    Source:warning3
    Published:24 May 2001
    7.5
    High

    CVE-2001-0419

    Last Modified: 22 Aug 2012

    Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.

    Source:Fyodor Yarochkin
    Published:24 May 2001
    5
    Medium

    CVE-2001-0418

    Last Modified: 22 Aug 2012

    content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.

    Source:RA-Soft Security
    Published:24 May 2001
    10
    Critical

    CVE-2001-0414

    Last Modified: 6 Mar 2011

    Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.

    Source:Metasploit
    Published:4 Apr 2001
    2.1
    Low

    CVE-2001-0409

    Last Modified: 15 Nov 2017

    vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory.

    Source:zen-parse
    Published:18 Jun 2001
    4.6
    Medium

    CVE-2001-0407

    Last Modified: 22 Aug 2012

    Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).

    Source:lesha
    Published:27 Jun 2001
    2.1
    Low

    CVE-2001-0406

    Last Modified: 2 Dec 2016

    Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.

    Source:Gabriel Maggiotti
    Published:17 Apr 2001
    7.5
    High

    CVE-2001-0405

    Last Modified: 24 Aug 2012

    ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.

    Source:Cristiano Lincoln Mattos
    Published:16 Apr 2001
    7.2
    High

    CVE-2001-0403

    Last Modified: 22 Aug 2012

    /opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.

    Source:KimYongJun
    Published:24 May 2001
    7.5
    High

    CVE-2001-0402

    Last Modified: 15 Nov 2017

    IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted port.

    Source:Thomas Lopatic
    Published:18 Jun 2001
    7.2
    High

    CVE-2001-0401

    Last Modified: 20 Aug 2012

    Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.

    Source:Pablo Sor
    Published:24 May 2001
    7.5
    High

    CVE-2001-0400

    Last Modified: 22 Aug 2012

    nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.

    Source:Kanedaaa
    Published:24 May 2001
    5
    Medium

    CVE-2001-0399

    Last Modified: 22 Aug 2012

    Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.

    Source:lovehacker
    Published:24 May 2001
    5
    Medium

    CVE-2001-0390

    Last Modified: 22 Aug 2012

    IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.

    Source:ET LoWNOISE
    Published:24 May 2001
    5
    Medium

    CVE-2001-0386

    Last Modified: 24 Aug 2012

    AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.

    Source:nemesystm
    Published:2 Jul 2001
    5
    Medium

    CVE-2001-0385

    Last Modified: 25 Jan 2018

    GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.

    Source:nemesystm
    Published:24 May 2001
    2.1
    Low

    CVE-2001-0384

    Last Modified: 24 Aug 2012

    ppd in Reliant Sinix allows local users to corrupt arbitrary files via a symlink attack in the /tmp/ppd.trace file.

    Source:Ruiz Garcia
    Published:24 May 2001
    5
    Medium

    CVE-2001-0383

    Last Modified: 22 Aug 2012

    banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication.

    Source:Juan Diego
    Published:18 Jun 2001
    6.4
    Medium

    CVE-2001-0380

    Last Modified: 28 Aug 2012

    Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented community string 'ILMI'.

    Source:Jacek Lipkowski
    Published:24 May 2001