5
    Medium

    CVE-2001-0375

    Last Modified: 22 Aug 2012

    Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests.

    Source:Claudiu Calomfirescu
    Published:18 Jun 2001
    7.2
    High

    CVE-2001-0369

    Last Modified: 20 Aug 2012

    Buffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line argument (non-existent printer name).

    Source:Luciano Rocha
    Published:24 May 2001
    7.5
    High

    CVE-2001-0365

    Last Modified: 20 Aug 2012

    Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options are enabled, via an HTML email message containing Javascript, with ActiveX controls and malicious code within IMG tags.

    Source:http-equiv
    Published:27 Jun 2001
    5
    Medium

    CVE-2001-0360

    Last Modified: 20 Aug 2012

    Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) attack in the helpon parameter.

    Source:Martin J. Muench
    Published:24 May 2001
    5
    Medium

    CVE-2001-0348

    Last Modified: 29 Aug 2012

    Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.

    Source:Michal Zalewski
    Published:21 Jul 2001
    7.5
    High

    CVE-2001-0341

    Last Modified: 30 Aug 2012

    Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.

    Source:NSFOCUS Security Team
    Published:21 Jul 2001
    5
    Medium

    CVE-2001-0336

    Last Modified: 26 Aug 2012

    The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.

    Source:Nelson Bunker
    Published:27 Jun 2001
    7.5
    High

    CVE-2001-0333

    Last Modified: 26 Aug 2012

    Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.

    Source:Filip Maertens
    Published:27 Jun 2001
    7.5
    High

    CVE-2001-0329

    Last Modified: 18 Jul 2012

    Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.

    Source:Frank van Vliet karin
    Published:24 May 2001
    5
    Medium

    CVE-2001-0328

    Last Modified: 2 Jul 2012

    TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN.

    Source:Stealth & S. Krahmer
    Published:1 May 2001
    2.6
    Low

    CVE-2001-0324

    Last Modified: 18 Aug 2012

    Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.

    Source:Georgi Guninski
    Published:4 Apr 2001
    5
    Medium

    CVE-2001-0322

    Last Modified: 16 Aug 2012

    MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.

    Source:Thor Larholm
    Published:4 Apr 2001
    7.5
    High

    CVE-2001-0319

    Last Modified: 18 Aug 2012

    orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.

    Source:Rudi Carell
    Published:3 May 2001
    3.7
    Low

    CVE-2001-0317

    Last Modified: 7 Mar 2019

    Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.

    Source:Wojciech Purczynski
    Published:8 Feb 2001
    4.6
    Medium

    CVE-2001-0316

    Last Modified: 7 Mar 2019

    Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.

    Source:Chris Evans
    Published:8 Feb 2001
    4.6
    Medium

    CVE-2001-0311

    Last Modified: 6 Mar 2011

    Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client.

    Source:Metasploit
    Published:7 May 2001
    7.5
    High

    CVE-2001-0308

    Last Modified: 18 Aug 2012

    UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.

    Source:joetesta
    Published:4 Apr 2001
    7.5
    High

    CVE-2001-0307

    Last Modified: 18 Aug 2012

    Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.

    Source:joetesta
    Published:4 Apr 2001
    5
    Medium

    CVE-2001-0306

    Last Modified: 18 Aug 2012

    Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

    Source:slipy
    Published:4 Apr 2001
    5
    Medium

    CVE-2001-0305

    Last Modified: 18 Aug 2012

    Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in the StartID parameter.

    Source:slipy
    Published:4 Apr 2001
    5
    Medium

    CVE-2001-0304

    Last Modified: 18 Aug 2012

    Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request.

    Source:joetesta
    Published:4 Apr 2001
    5
    Medium

    CVE-2001-0302

    Last Modified: 18 Aug 2012

    Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL.

    Source:joetesta
    Published:4 Apr 2001
    5
    Medium

    CVE-2001-0298

    Last Modified: 20 Aug 2012

    Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.

    Source:slipy
    Published:4 Apr 2001
    10
    Critical

    CVE-2001-0296

    Last Modified: 25 Aug 2012

    Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command.

    Source:Len Budney
    Published:4 Apr 2001
    5
    Medium

    CVE-2001-0295

    Last Modified: 20 Aug 2012

    Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." command.

    Source:se00020
    Published:3 May 2001
    5
    Medium

    CVE-2001-0293

    Last Modified: 20 Aug 2012

    Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.

    Source:joetesta
    Published:4 Apr 2001
    4.6
    Medium

    CVE-2001-0289

    Last Modified: 20 Aug 2012

    Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory.

    Source:Wkit Security
    Published:28 Feb 2001
    7.5
    High

    CVE-2001-0288

    Last Modified: 2 Jul 2012

    Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.

    Source:Stealth & S. Krahmer
    Published:3 May 2001
    5
    Medium

    CVE-2001-0286

    Last Modified: 20 Aug 2012

    Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.

    Source:slipy
    Published:4 Apr 2001
    6.4
    Medium

    CVE-2001-0283

    Last Modified: 20 Aug 2012

    Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.

    Source:se00020
    Published:4 Apr 2001
    10
    Critical

    CVE-2001-0280

    Last Modified: 20 Aug 2012

    Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command.

    Source:Martin Rakhmanoff
    Published:3 May 2001
    7.2
    High

    CVE-2001-0279

    Last Modified: 29 Aug 2012

    Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.

    Source:MaXX
    Published:22 Feb 2001
    10
    Critical

    CVE-2001-0277

    Last Modified: 18 Aug 2012

    Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.

    Source:SNS Research
    Published:4 Apr 2001
    6.4
    Medium

    CVE-2001-0276

    Last Modified: 18 Aug 2012

    ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path.

    Source:SNS Research
    Published:3 May 2001
    7.5
    High

    CVE-2001-0274

    Last Modified: 20 Aug 2012

    kicq IRC client 1.0.0, and possibly later versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

    Source:Marc Roessler
    Published:3 May 2001
    5
    Medium

    CVE-2001-0272

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the templ parameter.

    Source:Tom Parker
    Published:4 Apr 2001
    5
    Medium

    CVE-2001-0270

    Last Modified: 20 Aug 2012

    Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set.

    Source:J.K. Garvey
    Published:4 Apr 2001
    2.1
    Low

    CVE-2001-0265

    Last Modified: 27 Aug 2012

    ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file.

    Source:Chris Anley
    Published:18 Jun 2001
    5
    Medium

    CVE-2001-0264

    Last Modified: 22 Aug 2012

    Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.

    Source:Rob Beck
    Published:24 May 2001
    7.5
    High

    CVE-2001-0263

    Last Modified: 22 Aug 2012

    Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.

    Source:Rob Beck
    Published:24 May 2001
    7.5
    High

    CVE-2001-0262

    Last Modified: 27 Aug 2012

    Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.

    Source:Craig Davison
    Published:24 May 2001
    3.6
    Low

    CVE-2001-0259

    Last Modified: 16 Aug 2012

    ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker can use to decrypt that user's private key file.

    Source:Richard Silverman
    Published:7 May 2001
    5
    Medium

    CVE-2001-0255

    Last Modified: 17 Aug 2012

    FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname.

    Source:SNS Research
    Published:4 Apr 2001
    5
    Medium

    CVE-2001-0253

    Last Modified: 17 Aug 2012

    Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.

    Source:MC GaN
    Published:4 Apr 2001
    5
    Medium

    CVE-2001-0250

    Last Modified: 17 Aug 2012

    The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command.

    Source:Security Research Team
    Published:4 Apr 2001
    10
    Critical

    CVE-2001-0247

    Last Modified: 22 Aug 2012

    Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.

    Source:fish stiqz
    Published:24 May 2001
    10
    Critical

    CVE-2001-0241

    Last Modified: 10 Dec 2018

    Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.

    Source:storm
    Published:27 Jun 2001
    7.5
    High

    CVE-2001-0239

    Last Modified: 24 Aug 2012

    Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.

    Source:SecureXpert Labs
    Published:2 Jul 2001
    10
    Critical

    CVE-2001-0236

    Last Modified: 20 Aug 2012

    Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.

    Source:Last Stage of Delirium
    Published:3 May 2001
    10
    Critical

    CVE-2001-0233

    Last Modified: 16 Aug 2012

    Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.

    Source:tHE rECIdjVO
    Published:18 Jan 2001