Skip to main content

Year archive

CVEs published in 2001

Archive summary

1,676 CVEs published in 2001 — 157 Critical, 631 High, 706 Medium, 182 Low, 0 Unrated.

CVE-2001-0940

Published Sep 21, 2001

Buffer overflow in the GUI authentication code of Check Point VPN-1/FireWall-1 Management Server 4.0 and 4.1 allows remote attackers to execute arbitrary code via a long user name.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1023

Published Sep 21, 2001

Xcache 2.1 allows remote attackers to determine the absolute path of web server documents by requesting a URL that is not cached by Xcache, which returns the full pathname in the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0507

Published Sep 20, 2001

IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privil…

CVSS 7.2 · High
Buzz score
12.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0508

Published Sep 20, 2001

Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0541

Published Sep 20, 2001

Buffer overflow in Microsoft Windows Media Player 7.1 and earlier allows remote attackers to execute arbitrary commands via a malformed Windows Media Station (.NSC) file.

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0546

Published Sep 20, 2001

Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion…

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0547

Published Sep 20, 2001

Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).

CVSS 2.1 · Low
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0636

Published Sep 20, 2001

Buffer overflows in Raytheon SilentRunner allow remote attackers to (1) cause a denial of service in the collector (cle.exe) component of SilentRunner 2.0 via traffic containing l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0642

Published Sep 20, 2001

Directory traversal vulnerability in IncrediMail version 1400185 and earlier allows local users to overwrite files on the local hard drive by appending .. (dot dot) sequences to f…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-0643

Published Sep 20, 2001

Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0644

Published Sep 20, 2001

Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 stores passwords in plaintext in the "Rumpus User Database" file in the prefs folder, which could allow attackers to gain privileges…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0645

Published Sep 20, 2001

Symantec/AXENT NetProwler 3.5.x contains several default passwords, which could allow remote attackers to (1) access to the management tier via the "admin" password, or (2) connec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0648

Published Sep 20, 2001

Directory traversal vulnerability in PHProjekt 2.1 and earlier allows a remote attacker to conduct unauthorized activities via a dot dot (..) attack on the file module.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0649

Published Sep 20, 2001

Personal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0650

Published Sep 20, 2001

Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0653

Published Sep 20, 2001

Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d)…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0658

Published Sep 20, 2001

Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0659

Published Sep 20, 2001

Buffer overflow in IrDA driver providing infrared data exchange on Windows 2000 allows attackers who are physically close to the machine to cause a denial of service (reboot) via…

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0668

Published Sep 20, 2001

Buffer overflow in line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to execute arbitrary commands.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 476-500 of 1,676 CVEsPage 20 of 68