Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1249 1 Vwebserver 1 Vwebserver 2008-09-10 5.0 MEDIUM N/A
vWebServer 1.2.0 allows remote attackers to cause a denial of service via a URL that contains MS-DOS device names.
CVE-2001-1248 1 Vwebserver 1 Vwebserver 2008-09-10 5.0 MEDIUM N/A
vWebServer 1.2.0 allows remote attackers to view arbitrary ASP scripts via a request for an ASP script that ends with a URL-encoded space character (%20).
CVE-2001-1507 1 Openbsd 1 Openssh 2008-09-10 7.5 HIGH N/A
OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.
CVE-2001-1281 1 Ipswitch 1 Imail 2008-09-10 5.0 MEDIUM N/A
Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser parameter in the "Change User Information" web form.
CVE-2001-1322 1 Xinetd 1 Xinetd 2008-09-10 3.6 LOW N/A
xinetd 2.1.8 and earlier runs with a default umask of 0, which could allow local users to read or modify files that are created by an application that runs under xinetd but does not set its own safe umask.
CVE-2001-1283 1 Ipswitch 1 Imail 2008-09-10 7.5 HIGH N/A
The webmail interface for Ipswitch IMail 7.04 and earlier allows remote authenticated users to cause a denial of service (crash) via a mailbox name that contains a large number of . (dot) or other characters to programs such as (1) readmail.cgi or (2) printmail.cgi, possibly due to a buffer overflow that may allow execution of arbitrary code.
CVE-2001-1252 1 Pgp 1 Keyserver 2008-09-10 10.0 HIGH N/A
Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs that directly access cgi-bin instead of keyserver/cgi-bin for the programs (1) console, (2) cs, (3) multi_config and (4) directory.
CVE-2001-1282 1 Ipswitch 1 Imail 2008-09-10 5.0 MEDIUM N/A
Ipswitch IMail 7.04 and earlier records the physical path of attachments in an e-mail message header, which could allow remote attackers to obtain potentially sensitive configuration information.
CVE-2001-1280 1 Ipswitch 1 Imail 2008-09-10 5.0 MEDIUM N/A
POP3 Server for Ipswitch IMail 7.04 and earlier generates different responses to valid and invalid user names, which allows remote attackers to determine users on the system.
CVE-2001-1296 1 Marc Logemann 1 More.groupware 2008-09-10 5.0 MEDIUM N/A
More.groupware PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
CVE-2001-1246 1 Php 1 Php 2008-09-10 7.5 HIGH N/A
PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.
CVE-2001-1241 1 Steve Grimm 1 Un-cgi 2008-09-10 7.5 HIGH N/A
Un-CGI 1.9 and earlier does not verify that a CGI script has the execution bits set before executing it, which allows remote attackers to execute arbitrary commands by directing Un-CGI to a document that begins with "#!" and the desired program name.
CVE-2001-1284 1 Ipswitch 1 Imail 2008-09-10 7.5 HIGH N/A
Ipswitch IMail 7.04 and earlier uses predictable session IDs for authentication, which allows remote attackers to hijack sessions of other users.
CVE-2001-1331 2 Debian, Progeny 2 Debian Linux, Debian 2008-09-10 1.2 LOW N/A
mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.
CVE-2001-1242 1 Steve Grimm 1 Un-cgi 2008-09-10 7.5 HIGH N/A
Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form.
CVE-2001-1298 1 Grant Horwood 1 Webodex 2008-09-10 5.0 MEDIUM N/A
Webodex PHP script 1.0 and earlier allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
CVE-2001-1297 1 Actionpoll 1 Actionpoll 2008-09-10 7.5 HIGH N/A
PHP remote file inclusion vulnerability in Actionpoll PHP script before 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter.
CVE-2001-1289 1 Id Software 1 Quake 3 Arena 2008-09-10 5.0 MEDIUM N/A
Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters.
CVE-2001-1285 1 Ipswitch 1 Imail 2008-09-10 5.0 MEDIUM N/A
Directory traversal vulnerability in readmail.cgi for Ipswitch IMail 7.04 and earlier allows remote attackers to access the mailboxes of other users via a .. (dot dot) in the mbx parameter.
CVE-2001-1341 1 Beck Ipc Gmbh 1 Ipc At Chip Embedded-webserver 2008-09-10 5.0 MEDIUM N/A
The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program.
CVE-2001-1239 1 Connect Inc. 1 Powernet Ix 2008-09-10 5.0 MEDIUM N/A
PowerNet IX allows remote attackers to cause a denial of service via a port scan.
CVE-2001-1237 1 Peaceworks Computer Consulting 1 Phormation 2008-09-10 7.5 HIGH N/A
Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable.
CVE-2001-1324 1 Paul Jarc 1 Idtools 2008-09-10 4.6 MEDIUM N/A
cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.
CVE-2001-1552 1 Microsoft 1 Windows Me 2008-09-10 5.0 MEDIUM N/A
ssdpsrv.exe in Windows ME allows remote attackers to cause a denial of service by sending multiple newlines in a Simple Service Discovery Protocol (SSDP) message. NOTE: multiple replies to the original post state that the problem could not be reproduced.
CVE-2001-1512 1 Macromedia 1 Jrun 2008-09-10 6.4 MEDIUM N/A
Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Pages (JSP), a variant of CVE-2000-1050.
CVE-2001-1278 1 Zope 1 Zope 2008-09-10 7.5 HIGH N/A
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
CVE-2001-1254 1 Com2001 1 Alexis Server 2008-09-10 7.5 HIGH N/A
Web Access component for COM2001 Alexis 2.0 and 2.1 in InternetPBX sends username and voice mail passwords in the clear via a Java applet that sends the information to port 8888 of the server, which could allow remote attackers to steal the passwords via sniffing.
CVE-2001-1279 1 Lbl 1 Tcpdump 2008-09-10 7.5 HIGH N/A
Buffer overflow in print-rx.c of tcpdump 3.x (probably 3.6x) allows remote attackers to cause a denial of service and possibly execute arbitrary code via AFS RPC packets with invalid lengths that trigger an integer signedness error, a different vulnerability than CVE-2000-1026.
CVE-2001-1286 1 Ipswitch 1 Imail 2008-09-10 7.5 HIGH N/A
Ipswitch IMail 7.04 and earlier stores a user's session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. via an HTML email that causes the Referrer to be sent to a URL under the attacker's control.
CVE-2001-1383 1 Redhat 1 Linux 2008-09-10 6.2 MEDIUM N/A
initscript in setserial 2.17-4 and earlier uses predictable temporary file names, which could allow local users to conduct unauthorized operations on files.
CVE-2001-1287 1 Ipswitch 1 Imail 2008-09-10 7.5 HIGH N/A
Buffer overflow in Web Calendar in Ipswitch IMail 7.04 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
CVE-2001-1501 1 Proftpd Project 1 Proftpd 2008-09-10 5.0 MEDIUM N/A
The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/" sequences in the argument.
CVE-2001-1369 1 Leon J Breedt 1 Pam-pgsql 2008-09-10 7.5 HIGH N/A
Leon J Breedt pam-pgsql before 0.5.2 allows remote attackers to execute arbitrary SQL code and bypass authentication or modify user account records by injecting SQL statements into user or password fields.
CVE-2001-0935 1 Washington University 1 Wu-ftpd 2008-09-10 7.5 HIGH N/A
Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CVE-2001-0550.
CVE-2001-1187 1 Mutasem Abudahab 2 Csvform, Csvform Plus 2008-09-10 7.5 HIGH N/A
csvform.pl 0.1 allows remote attackers to execute arbitrary commands via metacharacters in the file parameter.
CVE-2001-0824 1 Ibm 1 Websphere Application Server 2008-09-10 7.5 HIGH N/A
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
CVE-2001-1173 1 Masqmail 1 Masqmail 2008-09-10 7.2 HIGH N/A
Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases.
CVE-2001-0829 1 Apache 1 Tomcat 2008-09-10 5.1 MEDIUM N/A
A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
CVE-2001-1121 1 Macromedia 1 Jrun 2008-09-10 7.5 HIGH N/A
DEPRECATED. This entry has been deprecated. It is a duplicate of CVE-2001-1084.
CVE-2001-0827 1 Grant Averett 1 Ceberus Ftp Server 2008-09-10 5.0 MEDIUM N/A
Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.
CVE-2001-1168 1 Phpmyexplorer 2 Phpmyexplorer Classic, Phpmyexplorer Multiuser 2008-09-10 5.0 MEDIUM N/A
Directory traversal vulnerability in index.php in PhpMyExplorer before 1.2.1 allows remote attackers to read arbitrary files via a ..%2F (modified dot dot) in the chemin parameter.
CVE-2001-0826 1 Aclogic 1 Cesarftp 2008-09-10 7.5 HIGH N/A
Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD.
CVE-2001-1235 1 Derek Leung 1 Pslash 2008-09-10 7.5 HIGH N/A
pSlash PHP script 0.7 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.
CVE-2001-0890 1 Sane 1 Sane 2008-09-10 2.1 LOW N/A
Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.
CVE-2001-1134 1 Xerox 1 Docuprint N40 2008-09-10 5.0 MEDIUM N/A
Xerox DocuPrint N40 Printers allow remote attackers to cause a denial of service via malformed data, such as that produced by the Code Red worm.
CVE-2001-1236 1 Sebastian Bunka 1 Myphppagetool 2008-09-10 7.5 HIGH N/A
myphpPagetool PHP script 0.4.3-1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.
CVE-2001-1167 2008-09-10 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2001-0976. Reason: This candidate is a duplicate of CVE-2001-0976. Notes: CVE-2001-0976 should be used instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
CVE-2001-1213 1 Datawizard 1 Ftpxq 2008-09-10 6.4 MEDIUM N/A
The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote attackers to read and write arbitrary files in the root folder.
CVE-2001-1228 1 Gnu 1 Gzip 2008-09-10 7.5 HIGH N/A
Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.
CVE-2001-1215 1 Michael Baumer 1 Pfinger 2008-09-10 7.5 HIGH N/A
Format string vulnerability in PFinger 0.7.5 through 0.7.7 allows remote attackers to execute arbitrary code via format string specifiers in a .plan file.