Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1167 2008-09-10 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2001-0976. Reason: This candidate is a duplicate of CVE-2001-0976. Notes: CVE-2001-0976 should be used instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
CVE-2001-1049 1 Paul M. Jones 1 Phorecast 2008-09-10 7.5 HIGH N/A
Phorecast PHP script before 0.40 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
CVE-2001-1235 1 Derek Leung 1 Pslash 2008-09-10 7.5 HIGH N/A
pSlash PHP script 0.7 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.
CVE-2001-1236 1 Sebastian Bunka 1 Myphppagetool 2008-09-10 7.5 HIGH N/A
myphpPagetool PHP script 0.4.3-1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.
CVE-2001-0935 1 Washington University 1 Wu-ftpd 2008-09-10 7.5 HIGH N/A
Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CVE-2001-0550.
CVE-2001-0824 1 Ibm 1 Websphere Application Server 2008-09-10 7.5 HIGH N/A
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
CVE-2001-0826 1 Aclogic 1 Cesarftp 2008-09-10 7.5 HIGH N/A
Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD.
CVE-2001-0827 1 Grant Averett 1 Ceberus Ftp Server 2008-09-10 5.0 MEDIUM N/A
Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.
CVE-2001-0829 1 Apache 1 Tomcat 2008-09-10 5.1 MEDIUM N/A
A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
CVE-2001-0890 1 Sane 1 Sane 2008-09-10 2.1 LOW N/A
Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.
CVE-2001-0516 1 Oracle 2 Oracle8i, Oracle9i 2008-09-10 5.0 MEDIUM N/A
Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains an incorrect requester_version value that does not match an expected offset to the data.
CVE-2001-0487 1 Ibm 1 Aix Snmp 2008-09-10 5.0 MEDIUM N/A
AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.
CVE-2001-0744 1 Horde 1 Imp 2008-09-10 2.1 LOW N/A
Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file.
CVE-2001-0588 1 Sco 1 Openserver 2008-09-10 4.6 MEDIUM N/A
sendmail 8.9.3, as included with the MMDF 2.43.3b package in SCO OpenServer 5.0.6, can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command.
CVE-2001-0534 2 Lucent, Merit 2 Radius, Radius 2008-09-10 10.0 HIGH N/A
Multiple buffer overflows in RADIUS daemon radiusd in (1) Merit 3.6b and (2) Lucent 2.1-2 RADIUS allow remote attackers to cause a denial of service or execute arbitrary commands.
CVE-2001-0515 1 Oracle 2 Database Server, Oracle8i 2008-09-10 5.0 MEDIUM N/A
Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value.
CVE-2001-0556 1 Nedit 1 Nedit 2008-09-10 7.2 HIGH N/A
The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users' files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file.
CVE-2001-0580 1 Hughes Technologies 1 Dsl Vdns 2008-09-10 5.0 MEDIUM N/A
Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting to port 6070, sending some data, and closing the connection.
CVE-2001-0498 1 Oracle 1 Oracle8i 2008-09-10 5.0 MEDIUM N/A
Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension.
CVE-2001-0619 1 Lucent 1 Orinoco 2008-09-10 7.5 HIGH N/A
The Lucent Closed Network protocol can allow remote attackers to join Closed Network networks which they do not have access to. The 'Network Name' or SSID, which is used as a shared secret to join the network, is transmitted in the clear.
CVE-2001-0282 1 Guido Frassetto 1 Sedum 2008-09-10 10.0 HIGH N/A
SEDUM 2.1 HTTP server allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.
CVE-2001-0329 1 Mozilla 1 Bugzilla 2008-09-10 7.5 HIGH N/A
Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.
CVE-2001-0352 2 3com, Symbol 2 3crwe747a, 41x1 Access Point 2008-09-10 5.0 MEDIUM N/A
SNMP agents in 3Com AirConnect AP-4111 and Symbol 41X1 Access Point allow remote attackers to obtain the WEP encryption key by reading it from a MIB when the value should be write-only, via (1) dot11WEPDefaultKeyValue in the dot11WEPDefaultKeysTable of the IEEE 802.11b MIB, or (2) ap128bWepKeyValue in the ap128bWEPKeyTable in the Symbol MIB.
CVE-2001-0284 1 Openbsd 1 Openbsd 2008-09-10 10.0 HIGH N/A
Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option.
CVE-2001-0013 1 Isc 1 Bind 2008-09-10 10.0 HIGH N/A
Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.
CVE-2001-0391 1 Imatix 1 Xitami 2008-09-10 5.0 MEDIUM N/A
Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory.
CVE-2001-0012 1 Isc 1 Bind 2008-09-10 5.0 MEDIUM N/A
BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.
CVE-2001-0011 1 Isc 1 Bind 2008-09-10 10.0 HIGH N/A
Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.
CVE-2001-0010 1 Isc 1 Bind 2008-09-10 10.0 HIGH N/A
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
CVE-2001-0443 1 Qpc Software 2 Qvt Net, Qvt Term Plus 2008-09-10 7.5 HIGH N/A
Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password.
CVE-2000-1117 1 Ibm 1 Lotus Notes 2008-09-10 5.0 MEDIUM N/A
The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.
CVE-2000-1183 1 Nec 1 Socks 5 2008-09-10 7.2 HIGH N/A
Buffer overflow in socks5 server on Linux allows attackers to execute arbitrary commands via a long connection request.
CVE-2000-1150 1 Xavier Ducrohet 1 Felix 2008-09-10 5.0 MEDIUM N/A
Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.
CVE-2000-1151 1 Abisoft 1 Baxter 2008-09-10 5.0 MEDIUM N/A
Baxter IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.
CVE-2000-1154 1 Joe Kloss 1 Robinhood 2008-09-10 5.0 MEDIUM N/A
RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.
CVE-2000-1192 1 Btt Software 1 Snmp Trap Watcher 2008-09-10 7.5 HIGH N/A
Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap.
CVE-2000-1153 1 Kenny Carruthers 1 Postmaster 2008-09-10 5.0 MEDIUM N/A
PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.
CVE-2000-1188 1 I-soft 1 Quikstore 2008-09-10 5.0 MEDIUM N/A
Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter.
CVE-2000-1236 1 Oracle 1 Application Server 2008-09-10 7.5 HIGH N/A
SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.
CVE-2000-1155 1 Joe Kloss 1 Robinhood 2008-09-10 5.0 MEDIUM N/A
RHDaemon in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.
CVE-2000-0616 1 Hp 1 Mpe Ix 2008-09-10 4.6 MEDIUM N/A
Vulnerability in HP TurboIMAGE DBUTIL allows local users to gain additional privileges via DBUTIL.PUB.SYS.
CVE-2000-0608 1 Netwin 2 Cwmail, Dmailweb 2008-09-10 5.0 MEDIUM N/A
NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost).
CVE-2000-0598 1 Fortech 1 Proxy\+ 2008-09-10 5.0 MEDIUM N/A
Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy.
CVE-2000-0607 3 Debian, Mandrakesoft, Redhat 3 Debian Linux, Mandrake Linux, Linux 2008-09-10 7.2 HIGH N/A
Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings.
CVE-2000-0554 1 Lilikoi 1 Ceilidh 2008-09-10 5.0 MEDIUM N/A
Ceilidh allows remote attackers to obtain the real path of the Ceilidh directory via the translated_path hidden form field.
CVE-2000-0606 3 Debian, Mandrakesoft, Redhat 3 Debian Linux, Mandrake Linux, Linux 2008-09-10 7.2 HIGH N/A
Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.
CVE-2000-0605 1 Blackboard 1 Courseinfo 2008-09-10 2.1 LOW N/A
Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords.
CVE-2000-0604 1 Redhat 1 Linux 2008-09-10 4.6 MEDIUM N/A
gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uucp.
CVE-2000-0558 1 Hp 1 Openview Network Node Manager 2008-09-10 10.0 HIGH N/A
Buffer overflow in HP Openview Network Node Manager 6.1 allows remote attackers to execute arbitrary commands via the Alarm service (OVALARMSRV) on port 2345.
CVE-2000-0690 1 Cgi Script Center 1 Auction Weaver 2008-09-10 10.0 HIGH N/A
Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.