Skip to main content

Year archive

CVEs published in 2001

Archive summary

1,676 CVEs published in 2001 — 157 Critical, 631 High, 706 Medium, 182 Low, 0 Unrated.

CVE-2001-1003

Published Aug 31, 2001

Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can read the WEBCT.SVR file to decrypt the passwords and gain addi…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1004

Published Aug 31, 2001

Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name co…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1005

Published Aug 31, 2001

Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1006

Published Aug 31, 2001

Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to restrict access, which allows an attacker…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1007

Published Aug 31, 2001

Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attacke…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1008

Published Aug 31, 2001

Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that ha…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1009

Published Aug 31, 2001

Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negat…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-1025

Published Aug 31, 2001

PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-1027

Published Aug 31, 2001

Buffer overflow in WindowMaker (aka wmaker) 0.64 and earlier allows remote attackers to execute arbitrary code via a long window title.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-1036

Published Aug 31, 2001

GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1039

Published Aug 31, 2001

The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1040

Published Aug 31, 2001

HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the pas…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1041

Published Aug 31, 2001

oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alter…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1061

Published Aug 31, 2001

Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-1062

Published Aug 31, 2001

Buffer overflow in mana in OpenServer 5.0.6a and earlier allows local users to execute arbitrary code.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1063

Published Aug 31, 2001

Buffer overflow in uidadmin in Caldera Open Unix 8.0.0 and UnixWare 7 allows local users to gain root privileges via a long -S (scheme) command line argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1064

Published Aug 31, 2001

Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) teln…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1065

Published Aug 31, 2001

Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, whi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1066

Published Aug 31, 2001

ns6install installation script for Netscape 6.01 on Solaris, and other versions including 6.2.1 beta, allows local users to overwrite arbitrary files via a symlink attack.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1067

Published Aug 31, 2001

Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP request with a long Authorization header.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-1068

Published Aug 31, 2001

qpopper 4.01 with PAM based authentication on Red Hat systems generates different error messages when an invalid username is provided instead of a valid name, which allows remote…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1069

Published Aug 31, 2001

libCoolType library as used in Adobe Acrobat (acroread) on Linux creates the AdobeFnt.lst file with world-writable permissions, which allows local users to modify the file and pos…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1070

Published Aug 31, 2001

Sage Software MAS 200 allows remote attackers to cause a denial of service by connecting to port 10000 and entering a series of control characters.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1072

Published Aug 31, 2001

Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1073

Published Aug 31, 2001

Webridge PX Application Suite allows remote attackers to obtain sensitive information via a malformed request that generates a server error message, which includes full pathname o…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 626-650 of 1,676 CVEsPage 26 of 68