CVE-2001-0 to CVE-2001-999
343 CVEs with public proof-of-concept exploits.
- CVE-2001-00061 PoCThe Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to…
- CVE-2001-00071 PoCBuffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web…
- CVE-2001-00081 PoCBackdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.
- CVE-2001-00092 PoCsDirectory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack.
- CVE-2001-00104 PoCsBuffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
- CVE-2001-00211 PoCMailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the…
- CVE-2001-00221 PoCsimplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the…
- CVE-2001-00231 PoCeverythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config…
- CVE-2001-00241 PoCsimplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail…
- CVE-2001-00251 PoCad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.
- CVE-2001-00261 PoCrp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length…
- CVE-2001-00282 PoCsBuffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands…
- CVE-2001-00291 PoCBuffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a…
- CVE-2001-00321 PoCFormat string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain root privileges via…
- CVE-2001-00341 PoCKTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false…
- CVE-2001-00371 PoCDirectory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot…
- CVE-2001-00381 PoCOffline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in…
- CVE-2001-00401 PoCAPC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by…
- CVE-2001-00411 PoCMemory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of…
- CVE-2001-00421 PoCPHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c"…
- CVE-2001-00491 PoCWatchGuard SOHO FireWall 2.2.1 and earlier allows remote attackers to cause a denial of service via a large number of GET requests.
- CVE-2001-00501 PoCBuffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an…
- CVE-2001-00511 PoCIBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain…
- CVE-2001-00521 PoCIBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.
- CVE-2001-00532 PoCsOne-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
- CVE-2001-00541 PoCDirectory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by…
- CVE-2001-00591 PoCpatchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.
- CVE-2001-00661 PoCSecure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses…
- CVE-2001-00741 PoCDirectory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in…
- CVE-2001-00751 PoCDirectory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the…
- CVE-2001-00801 PoCCisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a…
- CVE-2001-00821 PoCCheck Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented…
- CVE-2001-00841 PoCGTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to…
- CVE-2001-00872 PoCsitetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users…
- CVE-2001-00891 PoCInternet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML…
- CVE-2001-00931 PoCVulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that…
- CVE-2001-00954 PoCscatman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.
- CVE-2001-00971 PoCThe Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST…
- CVE-2001-00981 PoCBuffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with…
- CVE-2001-00991 PoCbsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.
- CVE-2001-01001 PoCbslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.
- CVE-2001-01092 PoCsrctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file.
- CVE-2001-01101 PoCBuffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable.
- CVE-2001-01111 PoCFormat string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument.
- CVE-2001-01121 PoCMultiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.
- CVE-2001-01131 PoCstatsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used…
- CVE-2001-01141 PoCstatsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.
- CVE-2001-01152 PoCsBuffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.
- CVE-2001-01221 PoCKernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows…
- CVE-2001-01231 PoCDirectory traversal vulnerability in eXtropia bbs_forum.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack…
- CVE-2001-01291 PoCBuffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute…
- CVE-2001-01365 PoCsMemory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE…
- CVE-2001-01371 PoCWindows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a…
- CVE-2001-01442 PoCsCORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an…
- CVE-2001-01481 PoCThe WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a…
- CVE-2001-01491 PoCWindows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript…
- CVE-2001-01501 PoCInternet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could…
- CVE-2001-01511 PoCIIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.
- CVE-2001-01521 PoCThe password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password information to a…
- CVE-2001-01621 PoCWinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.
- CVE-2001-01631 PoCCisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP…
- CVE-2001-01651 PoCBuffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name)…
- CVE-2001-01672 PoCsBuffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary…
- CVE-2001-01682 PoCsBuffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary…
- CVE-2001-01691 PoCWhen using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in…
- CVE-2001-01703 PoCsglibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing…
- CVE-2001-01711 PoCBuffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via…
- CVE-2001-01721 PoCBuffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands…
- CVE-2001-01731 PoCBuffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote…
- CVE-2001-01771 PoCWebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a…
- CVE-2001-01801 PoCLars Ellingsen guestserver.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the "email" parameter.
- CVE-2001-01832 PoCsipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet,…
- CVE-2001-01841 PoCeEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user…
- CVE-2001-01871 PoCFormat string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute…
- CVE-2001-01891 PoCDirectory traversal vulnerability in LocalWEB2000 HTTP server allows remote attackers to read arbitrary commands via a .. (dot dot) attack…
- CVE-2001-01921 PoCBuffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.
- CVE-2001-01931 PoCFormat string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.
- CVE-2001-01971 PoCFormat string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.
- CVE-2001-01982 PoCsBuffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF…
- CVE-2001-01991 PoCDirectory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack in…
- CVE-2001-02001 PoCHSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will…
- CVE-2001-02021 PoCPicserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request.
- CVE-2001-02051 PoCDirectory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the…
- CVE-2001-02061 PoCDirectory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot)…
- CVE-2001-02081 PoCMicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions,…
- CVE-2001-02101 PoCDirectory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in…
- CVE-2001-02111 PoCDirectory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the…
- CVE-2001-02121 PoCDirectory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue…
- CVE-2001-02141 PoCWay-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the…
- CVE-2001-02151 PoCROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating…
- CVE-2001-02161 PoCPALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName…
- CVE-2001-02171 PoCDirectory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot…
- CVE-2001-02201 PoCBuffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.
- CVE-2001-02211 PoCBuffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.
- CVE-2001-02241 PoCMuscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.
- CVE-2001-02281 PoCDirectory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in…
- CVE-2001-02331 PoCBuffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary…
- CVE-2001-02362 PoCsBuffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long…
- CVE-2001-02391 PoCMicrosoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long…
- CVE-2001-02418 PoCsBuffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print…
- CVE-2001-02473 PoCsBuffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {}…
- CVE-2001-02501 PoCThe Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the…
- CVE-2001-02531 PoCDirectory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and…
- CVE-2001-02551 PoCFaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter…
- CVE-2001-02591 PoCssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user,…
- CVE-2001-02621 PoCBuffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.
- CVE-2001-02631 PoCGene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2)…
- CVE-2001-02641 PoCGene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file…
- CVE-2001-02651 PoCASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored…
- CVE-2001-02701 PoCMarconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a…
- CVE-2001-02721 PoCDirectory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read arbitrary files…
- CVE-2001-02741 PoCkicq IRC client 1.0.0, and possibly later versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
- CVE-2001-02761 PoCext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly…
- CVE-2001-02771 PoCBuffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute…
- CVE-2001-02791 PoCBuffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.
- CVE-2001-02801 PoCBuffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command.
- CVE-2001-02831 PoCDirectory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various…
- CVE-2001-02861 PoCDirectory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET…
- CVE-2001-02881 PoCCisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote…
- CVE-2001-02891 PoCJoe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain…
- CVE-2001-02931 PoCDirectory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET…
- CVE-2001-02951 PoCDirectory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir…
- CVE-2001-02961 PoCBuffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command.
- CVE-2001-02981 PoCBuffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via…
- CVE-2001-03021 PoCBuffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute…
- CVE-2001-03041 PoCDirectory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL…
- CVE-2001-03051 PoCDirectory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a ..…
- CVE-2001-03061 PoCDirectory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files via a .. (dot…
- CVE-2001-03071 PoCBajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in…
- CVE-2001-03081 PoCUploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands…
- CVE-2001-03114 PoCsVulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client.
- CVE-2001-03161 PoCLinux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.
- CVE-2001-03172 PoCsRace condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running…
- CVE-2001-03191 PoCorderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn…
- CVE-2001-03221 PoCMSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application…
- CVE-2001-03241 PoCWindows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number…
- CVE-2001-03281 PoCTCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking…
- CVE-2001-03291 PoCBugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1)…
- CVE-2001-03339 PoCsDirectory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot)…
- CVE-2001-03361 PoCThe Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a…
- CVE-2001-03412 PoCsBuffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute…
- CVE-2001-03481 PoCMicrosoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a…
- CVE-2001-03601 PoCDirectory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a ..…
- CVE-2001-03652 PoCsEudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML…
- CVE-2001-03661 PoCsaposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program,…
- CVE-2001-03691 PoCBuffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line…
- CVE-2001-03751 PoCCisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of…
- CVE-2001-03801 PoCCrosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default,…
- CVE-2001-03821 PoCComputer Associates CCC\Harvest 5.0 for Windows NT/2000 uses weak encryption for passwords, which allows a remote attacker to gain…
- CVE-2001-03832 PoCsbanners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which…
- CVE-2001-03841 PoCppd in Reliant Sinix allows local users to corrupt arbitrary files via a symlink attack in the /tmp/ppd.trace file.
- CVE-2001-03851 PoCGoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.
- CVE-2001-03861 PoCAnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.
- CVE-2001-03901 PoCIBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long…
- CVE-2001-03991 PoCCaucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF…
- CVE-2001-04001 PoCnph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.
- CVE-2001-04011 PoCBuffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
- CVE-2001-04021 PoCIPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access…
- CVE-2001-04031 PoC/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.
- CVE-2001-04051 PoCip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT…
- CVE-2001-04061 PoCSamba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more…
- CVE-2001-04071 PoCDirectory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a…
- CVE-2001-04091 PoCvim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the…
- CVE-2001-04144 PoCsBuffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and…
- CVE-2001-04181 PoCcontent.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting…
- CVE-2001-04191 PoCBuffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server…
- CVE-2001-04212 PoCsFTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with…
- CVE-2001-04221 PoCBuffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
- CVE-2001-04231 PoCBuffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a…
- CVE-2001-04251 PoCAdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request,…
- CVE-2001-04261 PoCBuffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG…
- CVE-2001-04321 PoCBuffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote…
- CVE-2001-04401 PoCBuffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute…
- CVE-2001-04421 PoCBuffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly…
- CVE-2001-04521 PoCBRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed…
- CVE-2001-04542 PoCsDirectory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in…
- CVE-2001-04592 PoCsBuffer overflows in ascdc Afterstep while running setuid allows local users to gain root privileges via a long (1) -d option, (2) -m…
- CVE-2001-04601 PoCWebsweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory…
- CVE-2001-04611 PoCtemplate.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell…
- CVE-2001-04621 PoCDirectory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in…
- CVE-2001-04631 PoCDirectory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0…
- CVE-2001-04641 PoCBuffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter.
- CVE-2001-04661 PoCDirectory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file…
- CVE-2001-04671 PoCDirectory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a \...…
- CVE-2001-04681 PoCBuffer overflow in FTPFS allows local users to gain root privileges via a long user name.
- CVE-2001-04711 PoCSSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to…
- CVE-2001-04761 PoCMultiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands…
- CVE-2001-04841 PoCTektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and…
- CVE-2001-04854 PoCsUnknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute…
- CVE-2001-04863 PoCsRemote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353.
- CVE-2001-04901 PoCBuffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file.
- CVE-2001-04911 PoCDirectory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot…
- CVE-2001-04951 PoCDirectory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot)…
- CVE-2001-04993 PoCsBuffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges…
- CVE-2001-05006 PoCsBuffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote…
- CVE-2001-05062 PoCsBuffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive…
- CVE-2001-05071 PoCIIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse…
- CVE-2001-05191 PoCAladdin eSafe Gateway versions 2.x allows a remote attacker to circumvent HTML SCRIPT filtering via a special arrangement of HTML tags…
- CVE-2001-05201 PoCAladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts…
- CVE-2001-05211 PoCAladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of…
- CVE-2001-05221 PoCFormat string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format…
- CVE-2001-05252 PoCsBuffer overflow in dsh in dqs 3.2.7 in SuSE Linux 7.0 and earlier, and possibly other operating systems, allows local users to gain…
- CVE-2001-05261 PoCBuffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the…
- CVE-2001-05271 PoCDCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and…
- CVE-2001-05378 PoCsHTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization…
- CVE-2001-05382 PoCsMicrosoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a…
- CVE-2001-05481 PoCBuffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.
- CVE-2001-05502 PoCswu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly…
- CVE-2001-05522 PoCsovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary…
- CVE-2001-05532 PoCsSSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to…
- CVE-2001-05541 PoCBuffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via…
- CVE-2001-05551 PoCScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through…
- CVE-2001-05571 PoCT. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded…
- CVE-2001-05581 PoCT. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a…
- CVE-2001-05592 PoCscrontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which…
- CVE-2001-05613 PoCsDirectory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot…
- CVE-2001-05631 PoCElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via large (> 160000…
- CVE-2001-05641 PoCAPC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial…
- CVE-2001-05653 PoCsBuffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.
- CVE-2001-05661 PoCCisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when…
- CVE-2001-05701 PoCminicom 1.83.1 and earlier allows a local attacker to gain additional privileges via numerous format string attacks.
- CVE-2001-05711 PoCDirectory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4…
- CVE-2001-05741 PoCDirectory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot)…
- CVE-2001-05751 PoCBuffer overflow in lpshut in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a long first argument to…
- CVE-2001-05761 PoClpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow…
- CVE-2001-05771 PoCrecon in SCO OpenServer 5.0 through 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the…
- CVE-2001-05781 PoCBuffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a long first argument…
- CVE-2001-05791 PoClpadmin in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first…
- CVE-2001-05801 PoCHughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting to port 6070,…
- CVE-2001-05811 PoCSpytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large number of connections to port…
- CVE-2001-05841 PoCIMAP server in Alt-N Technologies MDaemon 3.5.6 allows a local user to cause a denial of service (hang) via long (1) SELECT or (2) EXAMINE…
- CVE-2001-05901 PoCApache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a…
- CVE-2001-05931 PoCAnaconda Partners Clipper 3.3 and earlier allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the template…
- CVE-2001-05942 PoCskcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command…
- CVE-2001-05952 PoCsBuffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute arbitrary commands via the…
- CVE-2001-05961 PoCNetscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the…
- CVE-2001-05971 PoCZetetic Secure Tool for Recalling Important Passwords (STRIP) 0.5 and earlier for the PalmOS allows a local attacker to recover passwords…
- CVE-2001-06092 PoCsFormat string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed…
- CVE-2001-06101 PoCkfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in…
- CVE-2001-06141 PoCCarello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially…
- CVE-2001-06151 PoCDirectory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary…
- CVE-2001-06161 PoCFaust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which…
- CVE-2001-06232 PoCssendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop privileges when…
- CVE-2001-06261 PoCO'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL…
- CVE-2001-06301 PoCDirectory traversal vulnerability in MIMAnet viewsrc.cgi 2.0 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack…
- CVE-2001-06412 PoCsBuffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group man via a long -S…
- CVE-2001-06431 PoCInternet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick…
- CVE-2001-06461 PoCMaxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name…
- CVE-2001-06471 PoCOrange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not…
- CVE-2001-06491 PoCPersonal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request.
- CVE-2001-06522 PoCsHeap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2)…
- CVE-2001-06534 PoCsSendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large…
- CVE-2001-06631 PoCTerminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote…
- CVE-2001-06641 PoCInternet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP…
- CVE-2001-06691 PoCVarious Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion…
- CVE-2001-06751 PoCRit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account…
- CVE-2001-06792 PoCsA buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to…
- CVE-2001-06801 PoCDirectory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web…
- CVE-2001-06851 PoCThibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab…
- CVE-2001-06881 PoCBroker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .")…
- CVE-2001-06901 PoCFormat string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote…
- CVE-2001-06931 PoCWebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).
- CVE-2001-06971 PoCNetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.
- CVE-2001-07001 PoCBuffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header.
- CVE-2001-07011 PoCBuffer overflow in ptexec in the Sun Validation Test Suite 4.3 and earlier allows a local user to gain privileges via a long -o argument.
- CVE-2001-07021 PoCCerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1)…
- CVE-2001-07031 PoCtradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with an MS-DOS device…
- CVE-2001-07041 PoCtradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a…
- CVE-2001-07051 PoCDirectory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the…
- CVE-2001-07061 PoCMaximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies…
- CVE-2001-07111 PoCCisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management…
- CVE-2001-07221 PoCInternet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First…
- CVE-2001-07311 PoCApache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing…
- CVE-2001-07354 PoCsBuffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via…
- CVE-2001-07361 PoCVulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary…
- CVE-2001-07403 PoCs3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attackers to cause a…
- CVE-2001-07411 PoCCisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets.
- CVE-2001-07431 PoCPaging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped '…
- CVE-2001-07462 PoCsBuffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of…
- CVE-2001-07481 PoCAcme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by…
- CVE-2001-07511 PoCCisco switches and routers running CBOS 2.3.8 and earlier use predictable TCP Initial Sequence Numbers (ISN), which allows remote…
- CVE-2001-07581 PoCDirectory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via "CWD ..." command.
- CVE-2001-07591 PoCBuffer overflow in bctool in Jetico BestCrypt 0.8.1 and earlier allows local users to execute arbitrary code via a file or directory with…
- CVE-2001-07601 PoCCitrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not…
- CVE-2001-07622 PoCsBuffer overflow in su-wrapper 1.1.1 allows local users to execute arbitrary code via a long first argument.
- CVE-2001-07631 PoCBuffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response,…
- CVE-2001-07641 PoCBuffer overflow in ntping in scotty 2.1.0 allows local users to execute arbitrary code via a long hostname as a command line argument.
- CVE-2001-07661 PoCApache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains…
- CVE-2001-07752 PoCsBuffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format…
- CVE-2001-07781 PoCOmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20).
- CVE-2001-07791 PoCBuffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.
- CVE-2001-07801 PoCDirectory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information…
- CVE-2001-07821 PoCKDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.
- CVE-2001-07841 PoCDirectory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a modified .. (dot…
- CVE-2001-07871 PoCLPRng in Red Hat Linux 7.0 and 7.1 does not properly drop memberships in supplemental groups when lowering privileges, which could allow a…
- CVE-2001-07881 PoCInternet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute path for the server…
- CVE-2001-07911 PoCTrend Micro InterScan VirusWall for Windows NT allows remote attackers to make configuration changes by directly calling certain CGI…
- CVE-2001-07979 PoCsBuffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large…
- CVE-2001-08002 PoCslpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.
- CVE-2001-08033 PoCsBuffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to…
- CVE-2001-08041 PoCDirectory traversal vulnerability in story.pl in Interactive Story 1.3 allows a remote attacker to read arbitrary files via a .. (dot dot)…
- CVE-2001-08051 PoCDirectory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to read arbitrary files…
- CVE-2001-08153 PoCsBuffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an…
- CVE-2001-08181 PoCA buffer overflow the '\s' console command in MDBMS 0.99b9 and earlier allows remote attackers to execute arbitrary commands by sending…
- CVE-2001-08202 PoCsBuffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log…
- CVE-2001-08212 PoCsThe default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read…
- CVE-2001-08231 PoCThe pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES…
- CVE-2001-08301 PoC6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial…
- CVE-2001-08331 PoCBuffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment…
- CVE-2001-08361 PoCBuffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.
- CVE-2001-08381 PoCFormat string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string…
- CVE-2001-08391 PoCibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers…
- CVE-2001-08521 PoCTUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header.
- CVE-2001-08551 PoCBuffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM environment variable.
- CVE-2001-08571 PoCCross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of…
- CVE-2001-08731 PoCuuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privileges by calling uux…
- CVE-2001-08752 PoCsInternet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the…
- CVE-2001-08762 PoCsBuffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a…
- CVE-2001-08981 PoCOpera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domains via Javascript…
- CVE-2001-08991 PoCNetwork Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput…
- CVE-2001-09001 PoCDirectory traversal vulnerability in modules.php in Gallery before 1.2.3 allows remote attackers to read arbitrary files via a .. (dot…
- CVE-2001-09062 PoCsteTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produced when printing…
- CVE-2001-09071 PoCLinux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a series of deeply nested…
- CVE-2001-09091 PoCBuffer overflow in helpctr.exe program in Microsoft Help Center for Windows XP allows remote attackers to execute arbitrary code via a…
- CVE-2001-09151 PoCFormat string vulnerability in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via format…
- CVE-2001-09161 PoCBuffer overflow in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via a long check argument…
- CVE-2001-09241 PoCDirectory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a ..…
- CVE-2001-09255 PoCsThe default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via…
- CVE-2001-09323 PoCsBuffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly execute arbitrary code…
- CVE-2001-09341 PoCCooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the…
- CVE-2001-09411 PoCBuffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment…
- CVE-2001-09512 PoCsWindows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (IKE) UDP port 500…
- CVE-2001-09521 PoCTHQ Volition Red Faction Game allows remote attackers to cause a denial of service (hang) of a client or server via packets to UDP port…
- CVE-2001-09561 PoCspeechd 0.54 and earlier, with the Festival or rsynth speech synthesis package, allows attackers to execute arbitrary commands via shell…
- CVE-2001-09651 PoCglFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a…
- CVE-2001-09792 PoCsBuffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long command line…
- CVE-2001-09831 PoCUltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read the file to decrypt…
- CVE-2001-09851 PoCshop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the…
- CVE-2001-09861 PoCSQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path,…
- CVE-2001-09871 PoCCross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by…
- CVE-2001-09891 PoCBuffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or (2) a long…
- CVE-2001-09911 PoCCross-site scripting vulnerability in Proxomitron Naoko-4 BetaFour and earlier allows remote attackers to execute arbitrary script on…
- CVE-2001-09991 PoCOutlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is…