7.2
    High

    CVE-2001-0111

    Last Modified: 16 Aug 2012

    Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument.

    Source:Michel Kaempf
    Published:12 Mar 2001
    7.2
    High

    CVE-2001-0110

    Last Modified: 16 Apr 2026

    Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable.

    Source:teleh0r
    Published:12 Mar 2001
    1.2
    Low

    CVE-2001-0109

    Last Modified: 16 Aug 2012

    rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file.

    Source:IhaQueR
    Published:12 Mar 2001
    10
    Critical

    CVE-2001-0100

    Last Modified: 14 Aug 2012

    bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.

    Source:rivendell_team
    Published:12 Feb 2001
    10
    Critical

    CVE-2001-0099

    Last Modified: 14 Aug 2012

    bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.

    Source:rivendell_team
    Published:12 Feb 2001
    10
    Critical

    CVE-2001-0098

    Last Modified: 14 Aug 2012

    Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.

    Source:peter.grundl
    Published:2 Feb 2001
    5
    Medium

    CVE-2001-0097

    Last Modified: 14 Aug 2012

    The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request.

    Source:SNS Research
    Published:2 Feb 2001
    1.2
    Low

    CVE-2001-0095

    Last Modified: 16 Apr 2026

    catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.

    Source:lwc
    Published:12 Feb 2001
    7.2
    High

    CVE-2001-0093

    Last Modified: 4 Dec 2016

    Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.

    Source:Teso
    Published:2 Feb 2001
    2.6
    Low

    CVE-2001-0089

    Last Modified: 22 Nov 2017

    Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.

    Source:Key
    Published:16 Feb 2001
    7.2
    High

    CVE-2001-0087

    Last Modified: 14 Aug 2012

    itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.

    Source:V9
    Published:2 Feb 2001
    7.2
    High

    CVE-2001-0084

    Last Modified: 14 Aug 2012

    GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.

    Source:V9
    Published:2 Feb 2001
    7.5
    High

    CVE-2001-0082

    Last Modified: 14 Aug 2012

    Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.

    Source:Thomas Lopatic
    Published:2 Feb 2001
    5
    Medium

    CVE-2001-0080

    Last Modified: 14 Aug 2012

    Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client, which generates a protocol mismatch error.

    Source:blackangels
    Published:12 Feb 2001
    5
    Medium

    CVE-2001-0075

    Last Modified: 14 Aug 2012

    Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter.

    Source:Ksecurity
    Published:2 Feb 2001
    5
    Medium

    CVE-2001-0074

    Last Modified: 14 Aug 2012

    Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter.

    Source:bt
    Published:2 Feb 2001
    7.2
    High

    CVE-2001-0066

    Last Modified: 16 Mar 2016

    Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer.

    Source:Michel Kaempf
    Published:26 Nov 2000
    6.2
    Medium

    CVE-2001-0059

    Last Modified: 14 Aug 2012

    patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.

    Source:Larry W. Cashdollar
    Published:12 Feb 2001
    5
    Medium

    CVE-2001-0054

    Last Modified: 26 Dec 2016

    Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.

    Source:Zoa_Chien
    Published:16 Feb 2001
    10
    Critical

    CVE-2001-0053

    Last Modified: 22 Nov 2017

    One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.

    Source:Scrippie
    Published:12 Feb 2001
    2.1
    Low

    CVE-2001-0052

    Last Modified: 13 Aug 2012

    IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.

    Source:benjurry
    Published:2 Feb 2001
    7.5
    High

    CVE-2001-0051

    Last Modified: 13 Aug 2012

    IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.

    Source:benjurry
    Published:2 Feb 2001
    10
    Critical

    CVE-2001-0050

    Last Modified: 13 Aug 2012

    Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address that resolves to a long DNS hostname or domain name.

    Source:nimrood
    Published:7 Dec 2000
    5
    Medium

    CVE-2001-0049

    Last Modified: 13 Aug 2012

    WatchGuard SOHO FireWall 2.2.1 and earlier allows remote attackers to cause a denial of service via a large number of GET requests.

    Source:Filip Maertens
    Published:2 Feb 2001
    5
    Medium

    CVE-2001-0042

    Last Modified: 13 Aug 2012

    PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.

    Source:china nsl
    Published:16 Feb 2001
    7.8
    High

    CVE-2001-0041

    Last Modified: 13 Aug 2012

    Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts.

    Source:blackangels
    Published:16 Feb 2001
    2.1
    Low

    CVE-2001-0040

    Last Modified: 3 Feb 2017

    APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file.

    Source:the itch
    Published:16 Feb 2001
    5
    Medium

    CVE-2001-0038

    Last Modified: 13 Aug 2012

    Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in the requested URL.

    Source:Dodger
    Published:2 Feb 2001
    5
    Medium

    CVE-2001-0037

    Last Modified: 13 Aug 2012

    Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifiers.

    Source:SNS Research
    Published:2 Feb 2001
    7.2
    High

    CVE-2001-0034

    Last Modified: 13 Aug 2012

    KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.

    Source:Jouko Pynnonen
    Published:16 Feb 2001
    10
    Critical

    CVE-2001-0032

    Last Modified: 13 Aug 2012

    Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain root privileges via malicious format string specifiers in a URL.

    Source:c0ncept
    Published:2 Feb 2001
    10
    Critical

    CVE-2001-0029

    Last Modified: 28 Mar 2016

    Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or domain name that is obtained from a reverse DNS lookup.

    Source:diman
    Published:2 Feb 2001
    10
    Critical

    CVE-2001-0028

    Last Modified: 14 Aug 2012

    Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of " (quotation) characters.

    Source:diman
    Published:12 Feb 2001
    5
    Medium

    CVE-2001-0026

    Last Modified: 14 Aug 2012

    rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option.

    Source:dethy
    Published:11 Dec 2000
    10
    Critical

    CVE-2001-0025

    Last Modified: 14 Aug 2012

    ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.

    Source:rpc
    Published:2 Feb 2001
    10
    Critical

    CVE-2001-0024

    Last Modified: 14 Aug 2012

    simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter.

    Source:rpc
    Published:2 Feb 2001
    10
    Critical

    CVE-2001-0023

    Last Modified: 14 Aug 2012

    everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.

    Source:rpc
    Published:2 Feb 2001
    10
    Critical

    CVE-2001-0022

    Last Modified: 14 Aug 2012

    simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter.

    Source:suid
    Published:2 Feb 2001
    10
    Critical

    CVE-2001-0021

    Last Modified: 13 Aug 2012

    MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.

    Source:Secure Reality Advisories
    Published:16 Feb 2001
    10
    Critical

    CVE-2001-0010

    Last Modified: 8 Sept 2017

    Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.

    Source:Gneisenau
    Published:29 Jan 2001
    5
    Medium

    CVE-2001-0009

    Last Modified: 14 Aug 2012

    Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack.

    Source:Michael Smith
    Published:12 Feb 2001
    10
    Critical

    CVE-2001-0008

    Last Modified: 14 Aug 2012

    Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.

    Source:Frank Schlottmann-Goedde
    Published:12 Feb 2001
    5
    Medium

    CVE-2001-0007

    Last Modified: 14 Aug 2012

    Buffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web administration interface.

    Source:Nsfocus
    Published:12 Feb 2001
    7.1
    High

    CVE-2001-0006

    Last Modified: 17 Aug 2012

    The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.

    Source:Arne Vidstrom
    Published:12 Feb 2001
    7.5
    High

    CVE-2000-1244

    Last Modified: 10 Aug 2012

    Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the "From" field, which allows remote attackers to bypass virus protection.

    Source:Hugo Caye
    Published:31 Dec 2000
    5
    Medium

    CVE-2000-1234

    Last Modified: 17 Aug 2012

    violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters.

    Source:Max Vision
    Published:31 Dec 2000
    5
    Medium

    CVE-2000-1230

    Last Modified: 17 Aug 2012

    Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".

    Source:Max Vision
    Published:31 Dec 2000
    5
    Medium

    CVE-2000-1228

    Last Modified: 17 Aug 2012

    Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.

    Source:Max Vision
    Published:31 Dec 2000
    5
    Medium

    CVE-2000-1224

    Last Modified: 11 Aug 2012

    Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others.

    Source:benjurry
    Published:23 Nov 2000
    10
    Critical

    CVE-2000-1221

    Last Modified: 16 Nov 2017

    The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.

    Source:anonymous
    Published:8 Jan 2000