5
    Medium

    CVE-2001-0228

    Last Modified: 18 Aug 2012

    Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request.

    Source:Sergey Nenashev
    Published:9 Mar 2001
    5
    Medium

    CVE-2001-0224

    Last Modified: 18 Aug 2012

    Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.

    Source:cuctema
    Published:9 Mar 2001
    7.2
    High

    CVE-2001-0221

    Last Modified: 16 Apr 2026

    Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.

    Source:dethy
    Published:7 May 2001
    7.2
    High

    CVE-2001-0220

    Last Modified: 16 Apr 2026

    Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.

    Source:dethy
    Published:9 Mar 2001
    5
    Medium

    CVE-2001-0217

    Last Modified: 18 Aug 2012

    Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.

    Source:cuctema
    Published:9 Mar 2001
    7.5
    High

    CVE-2001-0216

    Last Modified: 18 Aug 2012

    PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName parameter.

    Source:cuctema
    Published:9 Mar 2001
    5
    Medium

    CVE-2001-0215

    Last Modified: 18 Aug 2012

    ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename with a null byte.

    Source:cuctema
    Published:2 Jun 2001
    5
    Medium

    CVE-2001-0214

    Last Modified: 18 Aug 2012

    Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.

    Source:cuctema
    Published:9 Mar 2001
    7.5
    High

    CVE-2001-0212

    Last Modified: 18 Aug 2012

    Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.

    Source:cuctema
    Published:9 Mar 2001
    5
    Medium

    CVE-2001-0211

    Last Modified: 18 Aug 2012

    Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.

    Source:cuctema
    Published:9 Mar 2001
    5
    Medium

    CVE-2001-0210

    Last Modified: 18 Aug 2012

    Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page parameter.

    Source:slipy
    Published:9 Mar 2001
    4.6
    Medium

    CVE-2001-0208

    Last Modified: 18 Aug 2012

    MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.

    Source:Dixie Flatline
    Published:9 Mar 2001
    5
    Medium

    CVE-2001-0206

    Last Modified: 18 Aug 2012

    Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into the requested pathname of an HTTP GET request.

    Source:joetesta
    Published:9 Mar 2001
    5
    Medium

    CVE-2001-0205

    Last Modified: 18 Aug 2012

    Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested pathname, a modified .. (dot dot) attack.

    Source:joetesta
    Published:9 Mar 2001
    5
    Medium

    CVE-2001-0202

    Last Modified: 18 Aug 2012

    Picserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request.

    Source:joetesta
    Published:9 Mar 2001
    5
    Medium

    CVE-2001-0200

    Last Modified: 18 Aug 2012

    HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled.

    Source:Joe Testa
    Published:9 Mar 2001
    5
    Medium

    CVE-2001-0199

    Last Modified: 18 Aug 2012

    Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the HTTP GET request.

    Source:Joe Testa
    Published:9 Mar 2001
    7.6
    High

    CVE-2001-0198

    Last Modified: 18 Aug 2012

    Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.

    Source:UNYUN
    Published:9 Mar 2001
    10
    Critical

    CVE-2001-0197

    Last Modified: 17 Aug 2012

    Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.

    Source:CyRaX
    Published:21 Jan 2001
    7.2
    High

    CVE-2001-0193

    Last Modified: 18 Aug 2012

    Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.

    Source:IhaQueR
    Published:3 May 2001
    10
    Critical

    CVE-2001-0192

    Last Modified: 18 Aug 2012

    Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.

    Source:isno
    Published:9 Mar 2001
    5
    Medium

    CVE-2001-0189

    Last Modified: 17 Aug 2012

    Directory traversal vulnerability in LocalWEB2000 HTTP server allows remote attackers to read arbitrary commands via a .. (dot dot) attack in an HTTP GET request.

    Source:SNS Research
    Published:26 Mar 2001
    10
    Critical

    CVE-2001-0187

    Last Modified: 17 Aug 2012

    Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.

    Source:Wu-ftpd team
    Published:26 Mar 2001
    2.6
    Low

    CVE-2001-0184

    Last Modified: 17 Aug 2012

    eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user views the packet.

    Source:grazer
    Published:9 Mar 2001
    7.5
    High

    CVE-2001-0183

    Last Modified: 27 Aug 2012

    ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes the packet appear to be part of an established connection.

    Source:Aragon Gouveia
    Published:26 Mar 2001
    5
    Medium

    CVE-2001-0177

    Last Modified: 14 Aug 2012

    WebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a server clone.

    Source:Murat - 2
    Published:9 Mar 2001
    10
    Critical

    CVE-2001-0173

    Last Modified: 18 Aug 2012

    Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header.

    Source:Jin Ho You
    Published:9 Mar 2001
    7.2
    High

    CVE-2001-0172

    Last Modified: 4 Sept 2016

    Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name.

    Source:Marc Lehmann
    Published:9 Mar 2001
    10
    Critical

    CVE-2001-0171

    Last Modified: 25 Jan 2018

    Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request.

    Source:joetesta
    Published:9 Mar 2001
    2.1
    Low

    CVE-2001-0170

    Last Modified: 15 Nov 2017

    glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.

    Source:krochos
    Published:10 Jan 2001
    2.1
    Low

    CVE-2001-0169

    Last Modified: 22 Nov 2017

    When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.

    Source:Shadow
    Published:16 Jan 2001
    10
    Critical

    CVE-2001-0168

    Last Modified: 10 Mar 2011

    Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.

    Source:Metasploit
    Published:9 Mar 2001
    7.6
    High

    CVE-2001-0167

    Last Modified: 10 Mar 2011

    Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.

    Source:Metasploit
    Published:9 Mar 2001
    7.2
    High

    CVE-2001-0165

    Last Modified: 18 Aug 2012

    Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.

    Source:UNYUN
    Published:3 May 2001
    4.6
    Medium

    CVE-2001-0163

    Last Modified: 2 Jul 2012

    Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.

    Source:Stealth & S. Krahmer
    Published:1 Jan 2001
    7.5
    High

    CVE-2001-0162

    Last Modified: 2 Jul 2012

    WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.

    Source:Stealth & S. Krahmer
    Published:1 Jan 2001
    5
    Medium

    CVE-2001-0151

    Last Modified: 20 Aug 2012

    IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.

    Source:Georgi Guninski
    Published:7 May 2001
    5.1
    Medium

    CVE-2001-0150

    Last Modified: 20 Aug 2012

    Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.

    Source:Oliver Friedrichs
    Published:7 May 2001
    5
    Medium

    CVE-2001-0149

    Last Modified: 4 Aug 2012

    Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.

    Source:Georgi Guninski
    Published:7 May 2001
    7.5
    High

    CVE-2001-0148

    Last Modified: 14 Aug 2012

    The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.

    Source:Georgi Guninski
    Published:7 May 2001
    10
    Critical

    CVE-2001-0144

    Last Modified: 14 Aug 2017

    CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.

    Source:Teso
    Published:12 Mar 2001
    5.1
    Medium

    CVE-2001-0137

    Last Modified: 16 Aug 2012

    Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file named skin.wmz, then referencing that skin in the codebase parameter to an applet tag, aka the Windows Media Player Skins File Download" vulnerability.

    Source:Georgi Guninski
    Published:12 Mar 2001
    5
    Medium

    CVE-2001-0136

    Last Modified: 29 Aug 2017

    Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed.

    Source:JeT-Li
    Published:12 Mar 2001
    10
    Critical

    CVE-2001-0129

    Last Modified: 16 Aug 2012

    Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long connect request.

    Source:CyRaX
    Published:12 Mar 2001
    5
    Medium

    CVE-2001-0123

    Last Modified: 14 Aug 2012

    Directory traversal vulnerability in eXtropia bbs_forum.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the file parameter.

    Source:scott
    Published:12 Mar 2001
    5
    Medium

    CVE-2001-0122

    Last Modified: 14 Aug 2012

    Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.

    Source:Peter Grundl
    Published:13 Mar 2001
    7.2
    High

    CVE-2001-0115

    Last Modified: 16 Apr 2026

    Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.

    Source:ahmed
    Published:12 Mar 2001
    5
    Medium

    CVE-2001-0114

    Last Modified: 16 Aug 2012

    statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.

    Source:Joe Testa
    Published:14 Feb 2001
    10
    Critical

    CVE-2001-0113

    Last Modified: 16 Aug 2012

    statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script.

    Source:Joe Testa
    Published:14 Feb 2001
    7.2
    High

    CVE-2001-0112

    Last Modified: 22 Nov 2017

    Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.

    Source:Michel Kaempf
    Published:14 Feb 2001