Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1266 1 Doug Neal 1 Dnhttpd 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Doug Neal's HTTPD Daemon (DNHTTPD) before 0.4.1 allows remote attackers to view arbitrary files via a .. (dot dot) attack using the dot hex code '%2E'.
CVE-2001-1267 1 Gnu 1 Tar 2008-09-05 2.1 LOW N/A
Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).
CVE-2001-1295 1 Grant Averett 1 Cerberus Ftp Server 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Cerberus FTP Server 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the CD command.
CVE-2001-1321 1 Oracle 1 Internet Directory 2008-09-05 7.5 HIGH N/A
Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.
CVE-2001-1361 1 Twig Development Team 1 Twig 2008-09-05 7.5 HIGH N/A
Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links.
CVE-2001-1226 1 Adcycle 1 Adcycle 2008-09-05 5.0 MEDIUM N/A
AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.
CVE-2001-1225 1 Hughes 1 Msql 2008-09-05 2.1 LOW N/A
Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried.
CVE-2001-1224 1 Les Vanbrunt 1 Adrotate Pro 2008-09-05 7.5 HIGH N/A
get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack.
CVE-2001-1514 1 Macromedia 1 Coldfusion 2008-09-05 10.0 HIGH N/A
ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.
CVE-2001-1516 1 Hans Wolters 1 Phpreview 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in phpReview 0.9.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via user-submitted reviews.
CVE-2001-1519 1 Microsoft 1 Windows 2000 2008-09-05 3.6 LOW N/A
** DISPUTED ** RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it.
CVE-2001-1525 1 Easyscripts 1 Easynews 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly other files via a ".." in the cid parameter.
CVE-2001-1526 1 Easyscripts 1 Easynews 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter.
CVE-2001-1528 1 Amtote International 1 Homebet 2008-09-05 5.0 MEDIUM N/A
AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.
CVE-2001-1529 1 Ibm 1 Aix 2008-09-05 7.5 HIGH N/A
Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as CVE-2001-0779.
CVE-2001-1530 1 Webmin 1 Webmin 2008-09-05 4.6 MEDIUM N/A
run.cgi in Webmin 0.80 and 0.88 creates temporary files with world-writable permissions, which allows local users to execute arbitrary commands.
CVE-2001-1531 1 Apple 1 Claris Emailer 2008-09-05 7.5 HIGH N/A
Buffer overflow in Claris Emailer 2.0v2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an email attachment with a long filename.
CVE-2001-1532 1 Web Crossing 1 Webx 2008-09-05 5.0 MEDIUM N/A
WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions.
CVE-2001-1533 1 Microsoft 1 Isa Server 2008-09-05 5.0 MEDIUM N/A
** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.
CVE-2001-1534 1 Apache 1 Http Server 2008-09-05 2.1 LOW N/A
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
CVE-2001-1535 1 Open Source Development Network 1 Slashcode 2008-09-05 4.6 MEDIUM N/A
Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID's from cookies and gain unauthorized access via a brute force attack.
CVE-2001-1548 1 Zonelabs 1 Zonealarm 2008-09-05 2.1 LOW N/A
ZoneAlarm 2.1 through 2.6 and ZoneAlarm Pro 2.4 and 2.6 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters.
CVE-2001-1549 1 Tiny Software 1 Tiny Personal Firewall 2008-09-05 2.1 LOW N/A
Tiny Personal Firewall 1.0 and 2.0 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters.
CVE-2001-1551 1 Linux 1 Linux Kernel 2008-09-05 2.1 LOW N/A
Linux kernel 2.2.19 enables CAP_SYS_RESOURCE for setuid processes, which allows local users to exceed disk quota restrictions during execution of setuid programs.
CVE-2001-1553 1 University Of California 1 Seti At Home 2008-09-05 4.6 MEDIUM N/A
Buffer overflow in setiathome for SETI@home 3.03, if installed setuid, could allow local users to execute arbitrary code via long command line options (1) socks_server, (2) socks_user, and (3) socks_passwd. NOTE: since the default configuration of setiathome is not setuid, perhaps this issue should not be included in CVE.
CVE-2001-1565 1 Apple 1 Mac Os X 2008-09-05 2.1 LOW N/A
Point to Point Protocol daemon (pppd) in MacOS x 10.0 and 10.1 through 10.1.5 provides the username and password on the command line, which allows local users to obtain authentication information via the ps command.
CVE-2001-1566 2 Vanessa, Verge 2 Vanessa Logger, Perdition 2008-09-05 7.5 HIGH N/A
Format string vulnerability in libvanessa_logger 0.0.1 in Perdition 0.1.8 allows remote attackers to execute arbitrary code via format string specifiers in the __vanessa_logger_log function.
CVE-2001-1568 1 Cmg 1 Wap Gateway 2008-09-05 6.4 MEDIUM N/A
CMG WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack.
CVE-2001-1356 1 Netwin 1 Surgeftp 2008-09-05 10.0 HIGH N/A
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.
CVE-2001-1569 1 Cmg 1 Openwave Wap Gateway 2008-09-05 6.4 MEDIUM N/A
Openwave WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack.
CVE-2001-1271 1 Rarsoft 1 Rar 2008-09-05 2.1 LOW N/A
Directory traversal vulnerability in rar 2.02 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) attack on archived filenames.
CVE-2001-1339 1 Beck Ipc Gmbh 1 Ipc At Chip Embedded-webserver 2008-09-05 7.5 HIGH N/A
Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.
CVE-2001-1338 1 Beck Ipc Gmbh 1 Ipc At Chip Telnetd Server 2008-09-05 5.0 MEDIUM N/A
Beck IPC GmbH IPC@CHIP TelnetD server generates different responses when given valid and invalid login names, which allows remote attackers to determine accounts on the system.
CVE-2001-1337 1 Beck Ipc Gmbh 1 Ipc At Chip Embedded-webserver 2008-09-05 5.0 MEDIUM N/A
Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to cause a denial of service via a long HTTP request.
CVE-2001-1272 1 Wliang 1 Wmtv 2008-09-05 4.6 MEDIUM N/A
wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option.
CVE-2001-1304 1 Nullsoft 1 Shoutcast Server 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in SHOUTcast Server 1.8.2 allows remote attackers to cause a denial of service (crash) via several HTTP requests with a long (1) user-agent or (2) host HTTP header.
CVE-2001-1301 2 Gnu, Xemacs 2 Emacs, Xemacs 2008-09-05 1.2 LOW N/A
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.
CVE-2001-1300 1 Dynu Systems Inc. 1 Dynu Ftp Server 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Dynu FTP server 1.05 and earlier allows remote attackers to read arbitrary files via a .. in the CD (CWD) command.
CVE-2001-1273 1 Linux 1 Linux Kernel 2008-09-05 2.1 LOW N/A
The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).
CVE-2001-1357 1 Phpheaven 1 Phpmychat 2008-09-05 7.5 HIGH N/A
Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.
CVE-2001-1270 1 Pkware 1 Pkzip 2008-09-05 2.1 LOW N/A
Directory traversal vulnerability in the console version of PKZip (pkzipc) 4.00 and earlier allows attackers to overwrite arbitrary files during archive extraction with the -rec (recursive) option via a .. (dot dot) attack on the archived files.
CVE-2001-1358 1 Phpheaven 1 Phpmychat 2008-09-05 7.2 HIGH N/A
Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.
CVE-2001-1360 1 Mostang 1 Sane 2008-09-05 7.2 HIGH N/A
Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned.
CVE-2001-1220 1 D-link 1 Dwl-1000ap 2008-09-05 10.0 HIGH N/A
D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point stores the administrative password in plaintext in the default Management Information Base (MIB), which allows remote attackers to gain administrative privileges.
CVE-2001-1156 1 Typsoft 1 Typsoft Ftp Server 2008-09-05 5.0 MEDIUM N/A
TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1) STOR or (2) RETR.
CVE-2001-1221 1 D-link 1 Dwl-1000ap 2008-09-05 5.0 MEDIUM N/A
D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of 'public' which allows remote attackers to gain sensitive information.
CVE-2001-1222 1 Plesk 1 Plesk Server Administrator 2008-09-05 5.0 MEDIUM N/A
Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.
CVE-2001-1133 1 Bsdi 1 Bsd Os 2008-09-05 2.1 LOW N/A
Vulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kernel via a particular sequence of instructions.
CVE-2001-1223 1 Elsa 1 Lancom 1100 Office 2008-09-05 10.0 HIGH N/A
The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server.
CVE-2001-1131 1 Whitsoft Development 1 Slimftpd 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in WhitSoft Development SlimFTPd 2.2 allows an attacker to read arbitrary files and directories via a ... (modified dot dot) in the CD command.