Skip to main content

Year archive

CVEs published in 2001

Archive summary

1,676 CVEs published in 2001 — 157 Critical, 631 High, 706 Medium, 182 Low, 0 Unrated.

CVE-2001-0674

Published Sep 20, 2001

Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a hexadecimal encoded dot-dot attack (eg. http://…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0675

Published Sep 20, 2001

Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a carriage return <CR> that is…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0676

Published Sep 20, 2001

Directory traversal vulnerability in Rit Research Labs The Bat! 1.48f and earlier allows a remote attacker to create arbitrary files via a "dot dot" attack in the filename for an…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0677

Published Sep 20, 2001

Eudora 5.0.2 allows a remote attacker to read arbitrary files via an email with the path of the target file in the "Attachment Converted" MIME header, which sends the file when th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0680

Published Sep 20, 2001

Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a "dot dot" attack in a LIST (…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0681

Published Sep 20, 2001

Buffer overflow in ftpd in QPC QVT/Net 5.0 and QVT/Term 5.0 allows a remote attacker to cause a denial of service via a long (1) username or (2) password.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0683

Published Sep 20, 2001

Memory leak in Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service (memory exhaustion) by repeatedly sending approximately 5K of data…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0684

Published Sep 20, 2001

Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service by sending seven or more characters to TCP port 5239.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0685

Published Sep 20, 2001

Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-0686

Published Sep 20, 2001

Buffer overflow in mail included with SunOS 5.8 for x86 allows a local user to gain privileges via a long HOME environment variable.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0687

Published Sep 20, 2001

Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0688

Published Sep 20, 2001

Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0689

Published Sep 20, 2001

Vulnerability in TrendMicro Virus Control System 1.8 allows a remote attacker to view configuration files and change the configuration via a certain CGI program.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0691

Published Sep 20, 2001

Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0692

Published Sep 20, 2001

SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and 4.6 allows a remote attacker to bypass firewall filtering via a base64 MIME encoded email attachment whose boundary name e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0694

Published Sep 20, 2001

Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0695

Published Sep 20, 2001

WFTPD 3.00 R5 allows a remote attacker to cause a denial of service by making repeated requests to cd to the floppy drive (A:\).

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0696

Published Sep 20, 2001

NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0697

Published Sep 20, 2001

NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0698

Published Sep 20, 2001

Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0699

Published Sep 20, 2001

Buffer overflow in cb_reset in the System Service Processor (SSP) package of SunOS 5.8 allows a local user to execute arbitrary code via a long argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0700

Published Sep 20, 2001

Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 501-525 of 1,676 CVEsPage 21 of 68