CVE-2001-1000 to CVE-2001-1999
128 CVEs with public proof-of-concept exploits.
- CVE-2001-10001 PoCrlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files…
- CVE-2001-10021 PoCThe default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is…
- CVE-2001-10031 PoCRespondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can read the WEBCT.SVR…
- CVE-2001-10092 PoCsFetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory…
- CVE-2001-10102 PoCsDirectory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to overwrite…
- CVE-2001-10132 PoCsApache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no…
- CVE-2001-10151 PoCBuffer overflow in Snes9x 1.37, when installed setuid root, allows local users to gain root privileges via a long command line argument.
- CVE-2001-10212 PoCsBuffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4)…
- CVE-2001-10222 PoCsFormat string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass…
- CVE-2001-10291 PoClibutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and…
- CVE-2001-10361 PoCGNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database…
- CVE-2001-10441 PoCBasilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict…
- CVE-2001-10451 PoCDirectory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to read arbitrary files…
- CVE-2001-10551 PoCThe Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP…
- CVE-2001-10641 PoCCisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections…
- CVE-2001-10673 PoCsBuffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP…
- CVE-2001-10741 PoCWebmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes…
- CVE-2001-10751 PoCpoprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by causing a "POP login…
- CVE-2001-10761 PoCBuffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME…
- CVE-2001-10771 PoCBuffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name argument.
- CVE-2001-10784 PoCsFormat string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format…
- CVE-2001-10801 PoCdiagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to…
- CVE-2001-10831 PoCIcecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial…
- CVE-2001-10852 PoCsLmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
- CVE-2001-10861 PoCXDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which…
- CVE-2001-10881 PoCMicrosoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book"…
- CVE-2001-10921 PoCmsgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink attack on the…
- CVE-2001-10931 PoCBuffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument.
- CVE-2001-10971 PoCCisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.
- CVE-2001-11041 PoCSonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions.
- CVE-2001-11061 PoCThe default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting…
- CVE-2001-11071 PoCSnapStream PVS 1.2a stores its passwords in plaintext in the file SSD.ini, which could allow a remote attacker to gain privileges on the…
- CVE-2001-11081 PoCDirectory traversal vulnerability in SnapStream PVS 1.2a allows remote attackers to read arbitrary files via a .. (dot dot) attack in the…
- CVE-2001-11091 PoCDirectory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in…
- CVE-2001-11121 PoCBuffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of…
- CVE-2001-11131 PoCBuffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested…
- CVE-2001-11151 PoCgenerate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.
- CVE-2001-11221 PoCWindows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running…
- CVE-2001-11272 PoCsBuffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv, (2) _mprosrv, (3)…
- CVE-2001-11301 PoCSdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that…
- CVE-2001-11331 PoCVulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kernel via a particular…
- CVE-2001-11371 PoCD-Link DI-704 Internet Gateway firmware earlier than V2.56b6 allows remote attackers to cause a denial of service (reboot) via malformed…
- CVE-2001-11381 PoCDirectory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary…
- CVE-2001-11421 PoCArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the password file to gain…
- CVE-2001-11561 PoCTYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1) STOR or (2) RETR.
- CVE-2001-11601 PoCudirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell…
- CVE-2001-11621 PoCDirectory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to…
- CVE-2001-11631 PoCBuffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.
- CVE-2001-11651 PoCIntego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by…
- CVE-2001-11701 PoCAmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote attackers to steal…
- CVE-2001-11774 PoCsml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary…
- CVE-2001-11781 PoCBuffer overflow in xman allows local users to gain privileges via a long MANPATH environment variable.
- CVE-2001-11791 PoCxman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters.
- CVE-2001-11842 PoCswrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1)…
- CVE-2001-11851 PoCSome AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the…
- CVE-2001-11861 PoCMicrosoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than…
- CVE-2001-11881 PoCmailto.exe in Brian Dorricott MAILTO 1.0.9 and earlier allows remote attackers to send SPAM e-mail through remote servers by modifying the…
- CVE-2001-11941 PoCZyxel Prestige 681 and 1600 SDSL Routers allow remote attackers to cause a denial of service via malformed packets with (1) an IP length…
- CVE-2001-11951 PoCNovell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows…
- CVE-2001-11961 PoCDirectory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in…
- CVE-2001-11991 PoCCross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to…
- CVE-2001-12012 PoCsBuffer overflow in wmcube-gdk for WMCube/GDK 0.98 allows local users to execute arbitrary code via long lines in the object description…
- CVE-2001-12021 PoCCross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page,…
- CVE-2001-12093 PoCsDirectory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
- CVE-2001-12121 PoCCross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascript via the desc…
- CVE-2001-12432 PoCsScripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash)…
- CVE-2001-12441 PoCMultiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the…
- CVE-2001-12461 PoCPHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and…
- CVE-2001-12591 PoCAvaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload.
- CVE-2001-12631 PoCtelnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large number of…
- CVE-2001-12741 PoCBuffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.
- CVE-2001-12871 PoCBuffer overflow in Web Calendar in Ipswitch IMail 7.04 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET…
- CVE-2001-12891 PoCQuake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins…
- CVE-2001-12901 PoCadmin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration,…
- CVE-2001-12911 PoCThe telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect…
- CVE-2001-12941 PoCBuffer overflow in A-V Tronics Inetserv 3.2.1 and earlier allows remote attackers to cause a denial of service (crash) in the Webmail…
- CVE-2001-13031 PoCThe default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configuration information…
- CVE-2001-13202 PoCsNetwork Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via…
- CVE-2001-13251 PoCInternet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is…
- CVE-2001-13262 PoCsEudora 5.1 allows remote attackers to execute arbitrary code when the "Use Microsoft Viewer" option is enabled and the "allow executables…
- CVE-2001-13341 PoCBlock_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by…
- CVE-2001-13351 PoCDirectory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary…
- CVE-2001-13391 PoCBeck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it…
- CVE-2001-13431 PoCws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell…
- CVE-2001-13441 PoCWSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is…
- CVE-2001-13462 PoCsComputer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack…
- CVE-2001-13471 PoCWindows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled…
- CVE-2001-13541 PoCNetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password…
- CVE-2001-13701 PoCprepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an…
- CVE-2001-13841 PoCptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or…
- CVE-2001-13901 PoCUnknown vulnerability in binfmt_misc in the Linux kernel before 2.2.19, related to user pages.
- CVE-2001-13911 PoCOff-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory.
- CVE-2001-13921 PoCThe Linux kernel before 2.2.19 does not have unregister calls for (1) CPUID and (2) MSR drivers, which could cause a DoS (crash) by…
- CVE-2001-13931 PoCUnknown vulnerability in classifier code for Linux kernel before 2.2.19 could result in denial of service (hang).
- CVE-2001-13941 PoCSignedness error in (1) getsockopt and (2) setsockopt for Linux kernel before 2.2.19 allows local users to cause a denial of service.
- CVE-2001-13951 PoCUnknown vulnerability in sockfilter for Linux kernel before 2.2.19 related to "boundary cases," with unknown impact.
- CVE-2001-13961 PoCUnknown vulnerabilities in strnlen_user for Linux kernel before 2.2.19, with unknown impact.
- CVE-2001-13971 PoCThe System V (SYS5) shared memory implementation for Linux kernel before 2.2.19 could allow attackers to modify recently freed memory.
- CVE-2001-13981 PoCMasquerading code for Linux kernel before 2.2.19 does not fully check packet lengths in certain cases, which may lead to a vulnerability.
- CVE-2001-13991 PoCCertain operations in Linux kernel before 2.2.19 on the x86 architecture copy the wrong number of bytes, which might allow attackers to…
- CVE-2001-14001 PoCUnknown vulnerabilities in the UDP port allocation for Linux kernel before 2.2.19 could allow local users to cause a denial of service…
- CVE-2001-14081 PoCDirectory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a…
- CVE-2001-14101 PoCInternet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which…
- CVE-2001-14121 PoCnidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command…
- CVE-2001-14423 PoCsBuffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privileges via a long -c…
- CVE-2001-14601 PoCSQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user…
- CVE-2001-14711 PoCprefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which…
- CVE-2001-14721 PoCSQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and…
- CVE-2001-14731 PoCThe SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by…
- CVE-2001-14871 PoCpopauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user…
- CVE-2001-14891 PoCMicrosoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a…
- CVE-2001-14901 PoCMozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of…
- CVE-2001-14911 PoCOpera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of…
- CVE-2001-15011 PoCThe glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory…
- CVE-2001-15021 PoCwebcart.cgi in Mountain Network Systems WebCart 8.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the…
- CVE-2001-15181 PoCRunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service…
- CVE-2001-15191 PoCRunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext…
- CVE-2001-15242 PoCsCross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2001-15251 PoCDirectory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat,…
- CVE-2001-15281 PoCAmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which…
- CVE-2001-15461 PoCPathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the…
- CVE-2001-15491 PoCTiny Personal Firewall 1.0 and 2.0 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol…
- CVE-2001-15591 PoCThe uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the…
- CVE-2001-15601 PoCWin32k.sys (aka Graphics Device Interface (GDI)) in Windows 2000 and XP allows local users to cause a denial of service (system crash) by…
- CVE-2001-15611 PoCBuffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -T arguments.
- CVE-2001-15824 PoCsBuffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary code via a long…
- CVE-2001-15836 PoCslpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted…
- CVE-2001-15862 PoCsDirectory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded…