Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1529 1 Ibm 1 Aix 2008-09-05 7.5 HIGH N/A
Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as CVE-2001-0779.
CVE-2001-1530 1 Webmin 1 Webmin 2008-09-05 4.6 MEDIUM N/A
run.cgi in Webmin 0.80 and 0.88 creates temporary files with world-writable permissions, which allows local users to execute arbitrary commands.
CVE-2001-1531 1 Apple 1 Claris Emailer 2008-09-05 7.5 HIGH N/A
Buffer overflow in Claris Emailer 2.0v2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an email attachment with a long filename.
CVE-2001-1572 1 Linux 1 Linux Kernel 2008-09-05 7.5 HIGH N/A
The MAC module in Netfilter in Linux kernel 2.4.1 through 2.4.11, when configured to filter based on MAC addresses, allows remote attackers to bypass packet filters via small packets.
CVE-2001-1532 1 Web Crossing 1 Webx 2008-09-05 5.0 MEDIUM N/A
WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions.
CVE-2001-1533 1 Microsoft 1 Isa Server 2008-09-05 5.0 MEDIUM N/A
** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.
CVE-2001-1292 1 Sambar 1 Sambar Server 2008-09-05 7.5 HIGH N/A
Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password.
CVE-2001-1306 1 Sun 1 Iplanet Directory Server 2008-09-05 7.5 HIGH N/A
iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite.
CVE-2001-1573 1 Trend Micro 1 Interscan Viruswall 2008-09-05 10.0 HIGH N/A
Buffer overflow in smtpscan.dll for Trend Micro InterScan VirusWall 3.51 for Windows NT has allows remote attackers to execute arbitrary code via a certain configuration parameter.
CVE-2001-1574 1 Trend Micro 1 Interscan Viruswall 2008-09-05 10.0 HIGH N/A
Buffer overflow in (1) HttpSaveCVP.dll and (2) HttpSaveCSP.dll in Trend Micro InterScan VirusWall 3.5.1 allows remote attackers to execute arbitrary code.
CVE-2001-1234 1 Gallery Project 1 Gallery 2008-09-05 7.5 HIGH N/A
Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the includedir variable.
CVE-2002-0031 1 Yahoo 1 Messenger 2008-09-05 4.6 MEDIUM N/A
Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (1) call, (2) sendim, (3) getimv, (4) chat, (5) addview, or (6) addfriend.
CVE-2001-1534 1 Apache 1 Http Server 2008-09-05 2.1 LOW N/A
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
CVE-2001-1535 1 Open Source Development Network 1 Slashcode 2008-09-05 4.6 MEDIUM N/A
Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID's from cookies and gain unauthorized access via a brute force attack.
CVE-2001-1540 1 David F. Mischler 1 Iproute 2008-09-05 5.0 MEDIUM N/A
IPRoute 0.973, 0.974 and 1.18 allows remote attackers to cause a denial of service via fragmented IP packets that split the TCP header.
CVE-2001-1541 1 Bsdi 1 Bsd Os 2008-09-05 7.2 HIGH N/A
Buffer overflow in Unix-to-Unix Copy Protocol (UUCP) in BSDI BSD/OS 3.0 through 4.2 allows local users to execute arbitrary code via a long command line argument.
CVE-2001-1314 1 Critical Path 2 Injoin Directory Server, Livecontent Directory 2008-09-05 7.5 HIGH N/A
Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
CVE-2001-1315 1 Critical Path 2 Injoin Directory Server, Livecontent Directory 2008-09-05 7.5 HIGH N/A
Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.
CVE-2001-1549 1 Tiny Software 1 Tiny Personal Firewall 2008-09-05 2.1 LOW N/A
Tiny Personal Firewall 1.0 and 2.0 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters.
CVE-2001-1240 1 Engardelinux 1 Secure Linux 2008-09-05 10.0 HIGH N/A
The default configuration of sudo in Engarde Secure Linux 1.0.1 allows any user in the admin group to run certain commands that could be leveraged to gain full root access.
CVE-2001-1245 1 Opera Software 1 Opera Web Browser 2008-09-05 5.0 MEDIUM N/A
Opera 5.0 for Linux does not properly handle malformed HTTP headers, which allows remote attackers to cause a denial of service, possibly with a header whose value is the same as a MIME header name.
CVE-2001-1551 1 Linux 1 Linux Kernel 2008-09-05 2.1 LOW N/A
Linux kernel 2.2.19 enables CAP_SYS_RESOURCE for setuid processes, which allows local users to exceed disk quota restrictions during execution of setuid programs.
CVE-2001-1270 1 Pkware 1 Pkzip 2008-09-05 2.1 LOW N/A
Directory traversal vulnerability in the console version of PKZip (pkzipc) 4.00 and earlier allows attackers to overwrite arbitrary files during archive extraction with the -rec (recursive) option via a .. (dot dot) attack on the archived files.
CVE-2001-1317 1 Teamware 1 Teamware Office 2008-09-05 7.5 HIGH N/A
Teamware Office Enterprise Directory allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for certain BER object types, as demonstrated by the PROTOS LDAPv3 test suite.
CVE-2001-1543 1 Axis 5 2100 Network Camera, 2110 Network Camera, 2120 Network Camera and 2 more 2008-09-05 7.5 HIGH N/A
Axis network camera 2120, 2110, 2100, 200+ and 200 contains a default administration password "pass", which allows remote attackers to gain access to the camera.
CVE-2001-1318 1 Qualcomm 1 Eudora Worldmail Server 2008-09-05 7.5 HIGH N/A
Vulnerabilities in Qualcomm Eudora WorldMail Server may allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
CVE-2001-1553 1 University Of California 1 Seti At Home 2008-09-05 4.6 MEDIUM N/A
Buffer overflow in setiathome for SETI@home 3.03, if installed setuid, could allow local users to execute arbitrary code via long command line options (1) socks_server, (2) socks_user, and (3) socks_passwd. NOTE: since the default configuration of setiathome is not setuid, perhaps this issue should not be included in CVE.
CVE-2001-1326 1 Qualcomm 1 Eudora 2008-09-05 7.5 HIGH N/A
Eudora 5.1 allows remote attackers to execute arbitrary code when the "Use Microsoft Viewer" option is enabled and the "allow executables in HTML content" option is disabled, via an HTML email with a form that is activated from an image that the attacker spoofs as a link, which causes the user to execute the form and access embedded attachments.
CVE-2001-1271 1 Rarsoft 1 Rar 2008-09-05 2.1 LOW N/A
Directory traversal vulnerability in rar 2.02 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) attack on archived filenames.
CVE-2001-1327 1 Berkeley Softworks 1 Pmake 2008-09-05 4.6 MEDIUM N/A
pmake before 2.1.35 in Turbolinux 6.05 and earlier is installed with setuid root privileges, which could allow local users to gain privileges by exploiting vulnerabilities in pmake or programs that are used by pmake.
CVE-2001-1330 1 Ibm 1 Aix 2008-09-05 7.2 HIGH N/A
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.
CVE-2001-1332 1 Easy Software Products 1 Cups 2008-09-05 7.5 HIGH N/A
Buffer overflows in Linux CUPS before 1.1.6 may allow remote attackers to execute arbitrary code.
CVE-2001-1333 1 Easy Software Products 1 Cups 2008-09-05 1.2 LOW N/A
Linux CUPS before 1.1.6 does not securely handle temporary files, possibly due to a symlink vulnerability that could allow local users to overwrite files.
CVE-2001-1362 1 Horsburgh 1 Npulse 2008-09-05 7.5 HIGH N/A
Vulnerability in the server for nPULSE before 0.53p4.
CVE-2001-1363 1 Phpwebsite Development Team 1 Phpwebsite 2008-09-05 10.0 HIGH N/A
Vulnerability in phpWebSite before 0.7.9 related to running multiple instances in the same domain, which may allow attackers to gain administrative privileges.
CVE-2001-1571 1 Microsoft 1 Windows Xp 2008-09-05 5.0 MEDIUM N/A
The Remote Desktop client in Windows XP sends the most recent user account name in cleartext, which could allow remote attackers to obtain terminal server user account names via sniffing.
CVE-2001-1364 1 Project Purple 1 Autodns 2008-09-05 7.5 HIGH N/A
Vulnerability in autodns.pl for AutoDNS before 0.0.4 related to domain names that are not fully qualified.
CVE-2001-1365 1 Osi Codes Inc. 1 Intragnat 2008-09-05 7.5 HIGH N/A
Vulnerability in IntraGnat before 1.4.
CVE-2001-1366 1 Netscript Project 1 Netscript 2008-09-05 5.0 MEDIUM N/A
netscript before 1.6.3 parses dynamic variables, which could allow remote attackers to alter program behavior or obtain sensitive information.
CVE-2001-1416 1 Aol 1 Instant Messenger 2008-09-05 5.1 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in the log messages in certain Alpha versions of AOL Instant Messenger (AIM) 4.4 allow remote attackers to execute arbitrary web script or HTML via an image in the (1) DATA, (2) STYLE, or (3) BINARY tags.
CVE-2001-1272 1 Wliang 1 Wmtv 2008-09-05 4.6 MEDIUM N/A
wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option.
CVE-2001-1465 1 Surfcontrol 1 Superscout Web Filter 2008-09-05 4.6 MEDIUM N/A
SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements.
CVE-2001-1510 1 Macromedia 1 Jrun 2008-09-05 5.0 MEDIUM N/A
Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.
CVE-2001-1171 1 Checkpoint 1 Firewall-1 2008-09-05 7.2 HIGH N/A
Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy.
CVE-2001-0971 1 Aci 1 4d Webserver 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in ACI 4d webserver allows remote attackers to read arbitrary files via a .. (dot dot) or drive letter (e.g., C:) in an HTTP request.
CVE-2001-1166 1 Freebsd 1 Freebsd 2008-09-05 5.0 MEDIUM N/A
linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.
CVE-2001-1025 1 Francisco Burzi 1 Php-nuke 2008-09-05 10.0 HIGH N/A
PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.
CVE-2001-1211 1 Ipswitch 1 Imail 2008-09-05 7.5 HIGH N/A
Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain.
CVE-2001-1008 1 Sun 2 Java Plug-in, Jre 2008-09-05 7.5 HIGH N/A
Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.
CVE-2001-1149 1 Panda 1 Panda Antivirus Platinum 2008-09-05 5.0 MEDIUM N/A
Panda Antivirus Platinum before 6.23.00 allows a remore attacker to cause a denial of service (crash) when a user selects an action for a malformed UPX packed executable file.