Skip to main content

Year archive

CVEs published in 2001

Archive summary

1,676 CVEs published in 2001 — 157 Critical, 631 High, 706 Medium, 182 Low, 0 Unrated.

CVE-2001-1208

Published Dec 31, 2001

Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1209

Published Dec 31, 2001

Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1211

Published Dec 31, 2001

Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same ser…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1477

Published Dec 31, 2001

The Domain gateway in BEA Tuxedo 7.1 does not perform authorization checks for imported services and qspaces on remote domains, even when an ACL exists, which allows users to acce…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1479

Published Dec 31, 2001

smcboot in Sun SMC (Sun Management Center) 2.0 in Solaris 8 allows local users to delete arbitrary files via a symlink attack on /tmp/smc$SMC_PORT.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1481

Published Dec 31, 2001

Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to ga…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-1482

Published Dec 31, 2001

SQL injection vulnerability in bb_memberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL queries via the $sortby variable.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1483

Published Dec 31, 2001

One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account d…

CVSS 5.0 · Medium
Buzz score
12.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-1487

Published Dec 31, 2001

popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file op…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1488

Published Dec 31, 2001

Open Projects Network Internet Relay Chat (IRC) daemon u2.10.05.18 does not perform a double-reverse DNS lookup, which allows remote attackers to spoof any valid hostname on the I…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1489

Published Dec 31, 2001

Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1490

Published Dec 31, 2001

Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1491

Published Dec 31, 2001

Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1496

Published Dec 31, 2001

Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-1497

Published Dec 31, 2001

Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain co…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1498

Published Dec 31, 2001

Buffer overflow in mod_bf 0.2 allows local users to execute arbitrary commands via a long script.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1499

Published Dec 31, 2001

Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, w…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1500

Published Dec 31, 2001

ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1501

Published Dec 31, 2001

The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numb…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1502

Published Dec 31, 2001

webcart.cgi in Mountain Network Systems WebCart 8.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the NEXTPAGE parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 1,676 CVEsPage 1 of 68