Skip to main content

Year archive

CVEs published in 2001

Archive summary

1,676 CVEs published in 2001 — 157 Critical, 631 High, 706 Medium, 182 Low, 0 Unrated.

CVE-2001-0701

Published Sep 20, 2001

Buffer overflow in ptexec in the Sun Validation Test Suite 4.3 and earlier allows a local user to gain privileges via a long -o argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0702

Published Sep 20, 2001

Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) password, or (3) PASV command.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0703

Published Sep 20, 2001

tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with an MS-DOS device name in the template parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0704

Published Sep 20, 2001

tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0705

Published Sep 20, 2001

Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequenc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0707

Published Sep 20, 2001

Denicomp RSHD 2.18 and earlier allows a remote attacker to cause a denial of service (crash) via a long string to port 514.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0708

Published Sep 20, 2001

Denicomp REXECD 1.05 and earlier allows a remote attacker to cause a denial of service (crash) via a long string.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0709

Published Sep 20, 2001

Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0710

Published Sep 20, 2001

NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the m…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0963

Published Sep 20, 2001

Directory traversal vulnerability in SpoonFTP 1.1 allows local and sometimes remote attackers to access files outside of the FTP root via a ... (modified dot dot) in the CD (CWD)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0964

Published Sep 20, 2001

Buffer overflow in client for Half-Life 1.1.0.8 and earlier allows malicious remote servers to execute arbitrary code via a long console command.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1018

Published Sep 20, 2001

Lotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that contains a long sequence of / (s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1029

Published Sep 20, 2001

libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to b…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-1215

Published Sep 19, 2001

The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0961

Published Sep 18, 2001

Buffer overflow in tab expansion capability of the most program allows local or remote attackers to execute arbitrary code via a malformed file that is viewed with most.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-1353

Published Sep 18, 2001

ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-0986

Published Sep 14, 2001

SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source cod…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0984

Published Sep 13, 2001

Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized"…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1136

Published Sep 13, 2001

The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 526-550 of 1,676 CVEsPage 22 of 68