Skip to main content

Year archive

CVEs published in 2001

Archive summary

1,676 CVEs published in 2001 — 157 Critical, 631 High, 706 Medium, 182 Low, 0 Unrated.

CVE-2000-1194

Published Aug 31, 2001

Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1196

Published Aug 31, 2001

PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1197

Published Aug 31, 2001

POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-1198

Published Aug 31, 2001

qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files fo…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1199

Published Aug 31, 2001

PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1200

Published Aug 31, 2001

Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SI…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1201

Published Aug 31, 2001

Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1202

Published Aug 31, 2001

ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious loc…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0711

Published Aug 31, 2001

Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management Interface (ILMI) SNMP community string.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0943

Published Aug 31, 2001

dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0965

Published Aug 31, 2001

glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0966

Published Aug 31, 2001

Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the CD (CWD) command.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-0967

Published Aug 31, 2001

Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct br…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-0968

Published Aug 31, 2001

Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-0969

Published Aug 31, 2001

ipfw in FreeBSD does not properly handle the use of "me" in its rules when point to point interfaces are used, which causes ipfw to allow connections from arbitrary remote hosts.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-0970

Published Aug 31, 2001

Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0971

Published Aug 31, 2001

Directory traversal vulnerability in ACI 4d webserver allows remote attackers to read arbitrary files via a .. (dot dot) or drive letter (e.g., C:) in an HTTP request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0972

Published Aug 31, 2001

Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-0973

Published Aug 31, 2001

BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag spac…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0976

Published Aug 31, 2001

Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified librarie…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0981

Published Aug 31, 2001

HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the reques…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-0983

Published Aug 31, 2001

UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read the file to decrypt the passwords and gain privileges.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0995

Published Aug 31, 2001

PHProjekt before 2.4a allows remote attackers to perform actions as other PHProjekt users by modifying the ID number in an HTTP request to PHProjekt CGI programs.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1002

Published Aug 31, 2001

The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remot…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 601-625 of 1,676 CVEsPage 25 of 68