Skip to main content

Year archive

CVEs published in 2001

Archive summary

1,676 CVEs published in 2001 — 157 Critical, 631 High, 706 Medium, 182 Low, 0 Unrated.

CVE-2001-1423

Published Oct 10, 2001

Advanced Poll before 1.61, when using a flat file database, allows remote attackers to gain privileges by setting the logged_in parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1071

Published Oct 9, 2001

Cisco IOS 12.2 and earlier running Cisco Discovery Protocol (CDP) allows remote attackers to cause a denial of service (memory consumption) via a flood of CDP neighbor announcemen…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1095

Published Oct 9, 2001

Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1096

Published Oct 9, 2001

Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1414

Published Oct 9, 2001

The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, which allows remote attackers to hide their activities, possibly when certain B…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1128

Published Oct 8, 2001

Buffer overflow in Progress database 8.3D and 9.1C allows local users to execute arbitrary code via long entries in files that are specified by the (1) PROMSGS or (2) PROTERMCAP e…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1147

Published Oct 8, 2001

The PAM implementation in /bin/login of the util-linux package before 2.11 causes a password entry to be rewritten across multiple PAM calls, which could provide the credentials o…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1156

Published Oct 8, 2001

TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1) STOR or (2) RETR.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1100

Published Oct 7, 2001

sendmessage.cgi in W3Mail 1.0.2, and possibly other CGI programs, allows remote attackers to execute arbitrary commands via shell metacharacters in any field of the 'Compose Messa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1417

Published Oct 6, 2001

AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application hang or crash) via a buddy icon GIF file whose length and width values are larger…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1418

Published Oct 6, 2001

AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a malformed WAV file.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1421

Published Oct 6, 2001

AOL Instant Messenger (AIM) 4.7 and earlier allows remote attackers to cause a denial of service (application crash) via a large number of different fonts followed by an HTML HR t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1125

Published Oct 5, 2001

Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-1126

Published Oct 5, 2001

Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1127

Published Oct 5, 2001

Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv, (2) _mprosrv, (3) _mprshut, (4) orarx, (5) sqlcpp, (6) _pro…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1048

Published Oct 2, 2001

AWOL PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1049

Published Oct 2, 2001

Phorecast PHP script before 0.40 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1050

Published Oct 2, 2001

CCCSoftware CCC PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1051

Published Oct 2, 2001

Dark Hart Portal (darkportal) PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1054

Published Oct 2, 2001

PHPAdsNew PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1234

Published Oct 2, 2001

Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1235

Published Oct 2, 2001

pSlash PHP script 0.7 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir va…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 426-450 of 1,676 CVEsPage 18 of 68