| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2001-0676 | 0.00 | — | 0.01 | Sep 20, 2001 | Directory traversal vulnerability in Rit Research Labs The Bat! 1.48f and earlier allows a remote attacker to create arbitrary files via a "dot dot" attack in the filename for an attachment. | |||
| CVE-2001-0677 | 0.00 | — | 0.01 | Sep 20, 2001 | Eudora 5.0.2 allows a remote attacker to read arbitrary files via an email with the path of the target file in the "Attachment Converted" MIME header, which sends the file when the email is forwarded to the attacker by the user. | |||
| CVE-2001-0678 | 0.00 | — | 0.01 | Sep 20, 2001 | A buffer overflow in reggo.dll file used by Trend Micro InterScan VirusWall prior to 3.51 build 1349 for Windows NT 3.5 and InterScan WebManager 1.2 allows a local attacker to execute arbitrary code. | |||
| CVE-2001-0680 | 0.00 | — | 0.06 | Sep 20, 2001 | Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a "dot dot" attack in a LIST (ls) command. | |||
| CVE-2001-0681 | 0.00 | — | 0.01 | Sep 20, 2001 | Buffer overflow in ftpd in QPC QVT/Net 5.0 and QVT/Term 5.0 allows a remote attacker to cause a denial of service via a long (1) username or (2) password. | |||
| CVE-2001-0683 | 0.00 | — | 0.01 | Sep 20, 2001 | Memory leak in Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service (memory exhaustion) by repeatedly sending approximately 5K of data to TCP port 5238. | |||
| CVE-2001-0684 | 0.00 | — | 0.02 | Sep 20, 2001 | Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service by sending seven or more characters to TCP port 5239. | |||
| CVE-2001-0685 | 0.03 | — | 0.01 | Sep 20, 2001 | Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file. | |||
| CVE-2001-0686 | 0.00 | — | 0.00 | Sep 20, 2001 | Buffer overflow in mail included with SunOS 5.8 for x86 allows a local user to gain privileges via a long HOME environment variable. | |||
| CVE-2001-0687 | 0.00 | — | 0.02 | Sep 20, 2001 | Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS command, (2) specifying arbitrary paths in the UNC format (\\computername\sharename). | |||
| CVE-2001-0688 | 0.03 | — | 0.05 | Sep 20, 2001 | Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command. | |||
| CVE-2001-0689 | 0.00 | — | 0.01 | Sep 20, 2001 | Vulnerability in TrendMicro Virus Control System 1.8 allows a remote attacker to view configuration files and change the configuration via a certain CGI program. | |||
| CVE-2001-0690 | 0.04 | — | 0.12 | Sep 20, 2001 | Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers. | |||
| CVE-2001-0691 | 0.00 | — | 0.01 | Sep 20, 2001 | Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations. | |||
| CVE-2001-0692 | 0.00 | — | 0.02 | Sep 20, 2001 | SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and 4.6 allows a remote attacker to bypass firewall filtering via a base64 MIME encoded email attachment whose boundary name ends in two dashes. | |||
| CVE-2001-0693 | 0.03 | — | 0.03 | Sep 20, 2001 | WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20). | |||
| CVE-2001-0694 | 0.00 | — | 0.02 | Sep 20, 2001 | Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command. | |||
| CVE-2001-0695 | 0.00 | — | 0.01 | Sep 20, 2001 | WFTPD 3.00 R5 allows a remote attacker to cause a denial of service by making repeated requests to cd to the floppy drive (A:\). | |||
| CVE-2001-0696 | 0.00 | — | 0.03 | Sep 20, 2001 | NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con. | |||
| CVE-2001-0697 | 0.04 | — | 0.07 | Sep 20, 2001 | NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command. | |||
| CVE-2001-0698 | 0.00 | — | 0.02 | Sep 20, 2001 | Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command. | |||
| CVE-2001-0699 | 0.00 | — | 0.00 | Sep 20, 2001 | Buffer overflow in cb_reset in the System Service Processor (SSP) package of SunOS 5.8 allows a local user to execute arbitrary code via a long argument. | |||
| CVE-2001-0700 | 0.04 | — | 0.13 | Sep 20, 2001 | Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header. | |||
| CVE-2001-0701 | 0.03 | — | 0.01 | Sep 20, 2001 | Buffer overflow in ptexec in the Sun Validation Test Suite 4.3 and earlier allows a local user to gain privileges via a long -o argument. | |||
| CVE-2001-0702 | 0.04 | — | 0.10 | Sep 20, 2001 | Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) password, or (3) PASV command. | |||
| CVE-2001-0703 | 0.04 | — | 0.07 | Sep 20, 2001 | tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with an MS-DOS device name in the template parameter. | |||
| CVE-2001-0704 | 0.03 | — | 0.03 | Sep 20, 2001 | tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist. | |||
| CVE-2001-0705 | 0.04 | — | 0.08 | Sep 20, 2001 | Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument. | |||
| CVE-2001-0706 | 0.03 | — | 0.01 | Sep 20, 2001 | Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies a large number of sub-folders. | |||
| CVE-2001-0707 | 0.00 | — | 0.01 | Sep 20, 2001 | Denicomp RSHD 2.18 and earlier allows a remote attacker to cause a denial of service (crash) via a long string to port 514. | |||
| CVE-2001-0708 | 0.00 | — | 0.02 | Sep 20, 2001 | Denicomp REXECD 1.05 and earlier allows a remote attacker to cause a denial of service (crash) via a long string. | |||
| CVE-2001-0709 | 0.03 | — | 0.36 | Sep 20, 2001 | Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode. | |||
| CVE-2001-0710 | 0.00 | — | 0.02 | Sep 20, 2001 | NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool. | |||
| CVE-2001-0963 | 0.00 | — | 0.02 | Sep 20, 2001 | Directory traversal vulnerability in SpoonFTP 1.1 allows local and sometimes remote attackers to access files outside of the FTP root via a ... (modified dot dot) in the CD (CWD) command. | |||
| CVE-2001-0964 | 0.00 | — | 0.02 | Sep 20, 2001 | Buffer overflow in client for Half-Life 1.1.0.8 and earlier allows malicious remote servers to execute arbitrary code via a long console command. | |||
| CVE-2001-1018 | 0.00 | — | 0.02 | Sep 20, 2001 | Lotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that contains a long sequence of / (slash) characters. | |||
| CVE-2001-1029 | 0.03 | — | 0.01 | Sep 20, 2001 | libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome… | |||
| CVE-2000-1215 | 0.00 | — | 0.02 | Sep 19, 2001 | The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information. | |||
| CVE-2001-0962 | 0.00 | — | 0.02 | Sep 19, 2001 | IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing. | |||
| CVE-2001-0961 | 0.00 | — | 0.06 | Sep 18, 2001 | Buffer overflow in tab expansion capability of the most program allows local or remote attackers to execute arbitrary code via a malformed file that is viewed with most. | |||
| CVE-2001-1353 | 0.00 | — | 0.00 | Sep 18, 2001 | ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled. | |||
| CVE-2001-0959 | 0.00 | — | 0.03 | Sep 15, 2001 | Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 creates a hidden share named ARCSERVE$, which allows remote attackers to obtain sensitive information and overwrite critical files. | |||
| CVE-2001-0960 | 0.00 | — | 0.03 | Sep 15, 2001 | Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows local and remote attackers to gain privileges. | |||
| CVE-2001-1014 | 0.00 | — | 0.02 | Sep 15, 2001 | eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter. | |||
| CVE-2001-0986 | 0.07 | — | 0.48 | Sep 14, 2001 | SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2)… | |||
| CVE-2001-0984 | 0.00 | — | 0.00 | Sep 13, 2001 | Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options enabled, which could allow… | |||
| CVE-2001-1136 | 0.00 | — | 0.01 | Sep 13, 2001 | The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service. | |||
| CVE-2001-0958 | 0.00 | — | 0.05 | Sep 12, 2001 | Buffer overflows in eManager plugin for Trend Micro InterScan VirusWall for NT 3.51 and 3.51J allow remote attackers to execute arbitrary code via long arguments to the CGI programs (1) register.dll, (2) ContentFilter.dll, (3) SFNofitication.dll, (4) register.dll, (5) TOP10.dll,… | |||
| CVE-2001-0999 | 0.01 | — | 0.12 | Sep 12, 2001 | Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script. | |||
| CVE-2001-1013 | 0.08 | — | 0.66 | Sep 12, 2001 | Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server. |
- CVE-2001-0676Sep 20, 2001risk 0.00cvss —epss 0.01
Directory traversal vulnerability in Rit Research Labs The Bat! 1.48f and earlier allows a remote attacker to create arbitrary files via a "dot dot" attack in the filename for an attachment.
- CVE-2001-0677Sep 20, 2001risk 0.00cvss —epss 0.01
Eudora 5.0.2 allows a remote attacker to read arbitrary files via an email with the path of the target file in the "Attachment Converted" MIME header, which sends the file when the email is forwarded to the attacker by the user.
- CVE-2001-0678Sep 20, 2001risk 0.00cvss —epss 0.01
A buffer overflow in reggo.dll file used by Trend Micro InterScan VirusWall prior to 3.51 build 1349 for Windows NT 3.5 and InterScan WebManager 1.2 allows a local attacker to execute arbitrary code.
- CVE-2001-0680Sep 20, 2001risk 0.00cvss —epss 0.06
Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a "dot dot" attack in a LIST (ls) command.
- CVE-2001-0681Sep 20, 2001risk 0.00cvss —epss 0.01
Buffer overflow in ftpd in QPC QVT/Net 5.0 and QVT/Term 5.0 allows a remote attacker to cause a denial of service via a long (1) username or (2) password.
- CVE-2001-0683Sep 20, 2001risk 0.00cvss —epss 0.01
Memory leak in Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service (memory exhaustion) by repeatedly sending approximately 5K of data to TCP port 5238.
- CVE-2001-0684Sep 20, 2001risk 0.00cvss —epss 0.02
Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service by sending seven or more characters to TCP port 5239.
- CVE-2001-0685Sep 20, 2001risk 0.03cvss —epss 0.01
Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file.
- CVE-2001-0686Sep 20, 2001risk 0.00cvss —epss 0.00
Buffer overflow in mail included with SunOS 5.8 for x86 allows a local user to gain privileges via a long HOME environment variable.
- CVE-2001-0687Sep 20, 2001risk 0.00cvss —epss 0.02
Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS command, (2) specifying arbitrary paths in the UNC format (\\computername\sharename).
- CVE-2001-0688Sep 20, 2001risk 0.03cvss —epss 0.05
Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command.
- CVE-2001-0689Sep 20, 2001risk 0.00cvss —epss 0.01
Vulnerability in TrendMicro Virus Control System 1.8 allows a remote attacker to view configuration files and change the configuration via a certain CGI program.
- CVE-2001-0690Sep 20, 2001risk 0.04cvss —epss 0.12
Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers.
- CVE-2001-0691Sep 20, 2001risk 0.00cvss —epss 0.01
Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.
- CVE-2001-0692Sep 20, 2001risk 0.00cvss —epss 0.02
SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and 4.6 allows a remote attacker to bypass firewall filtering via a base64 MIME encoded email attachment whose boundary name ends in two dashes.
- CVE-2001-0693Sep 20, 2001risk 0.03cvss —epss 0.03
WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).
- CVE-2001-0694Sep 20, 2001risk 0.00cvss —epss 0.02
Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.
- CVE-2001-0695Sep 20, 2001risk 0.00cvss —epss 0.01
WFTPD 3.00 R5 allows a remote attacker to cause a denial of service by making repeated requests to cd to the floppy drive (A:\).
- CVE-2001-0696Sep 20, 2001risk 0.00cvss —epss 0.03
NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con.
- CVE-2001-0697Sep 20, 2001risk 0.04cvss —epss 0.07
NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.
- CVE-2001-0698Sep 20, 2001risk 0.00cvss —epss 0.02
Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command.
- CVE-2001-0699Sep 20, 2001risk 0.00cvss —epss 0.00
Buffer overflow in cb_reset in the System Service Processor (SSP) package of SunOS 5.8 allows a local user to execute arbitrary code via a long argument.
- CVE-2001-0700Sep 20, 2001risk 0.04cvss —epss 0.13
Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header.
- CVE-2001-0701Sep 20, 2001risk 0.03cvss —epss 0.01
Buffer overflow in ptexec in the Sun Validation Test Suite 4.3 and earlier allows a local user to gain privileges via a long -o argument.
- CVE-2001-0702Sep 20, 2001risk 0.04cvss —epss 0.10
Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) password, or (3) PASV command.
- CVE-2001-0703Sep 20, 2001risk 0.04cvss —epss 0.07
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with an MS-DOS device name in the template parameter.
- CVE-2001-0704Sep 20, 2001risk 0.03cvss —epss 0.03
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist.
- CVE-2001-0705Sep 20, 2001risk 0.04cvss —epss 0.08
Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument.
- CVE-2001-0706Sep 20, 2001risk 0.03cvss —epss 0.01
Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies a large number of sub-folders.
- CVE-2001-0707Sep 20, 2001risk 0.00cvss —epss 0.01
Denicomp RSHD 2.18 and earlier allows a remote attacker to cause a denial of service (crash) via a long string to port 514.
- CVE-2001-0708Sep 20, 2001risk 0.00cvss —epss 0.02
Denicomp REXECD 1.05 and earlier allows a remote attacker to cause a denial of service (crash) via a long string.
- CVE-2001-0709Sep 20, 2001risk 0.03cvss —epss 0.36
Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode.
- CVE-2001-0710Sep 20, 2001risk 0.00cvss —epss 0.02
NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool.
- CVE-2001-0963Sep 20, 2001risk 0.00cvss —epss 0.02
Directory traversal vulnerability in SpoonFTP 1.1 allows local and sometimes remote attackers to access files outside of the FTP root via a ... (modified dot dot) in the CD (CWD) command.
- CVE-2001-0964Sep 20, 2001risk 0.00cvss —epss 0.02
Buffer overflow in client for Half-Life 1.1.0.8 and earlier allows malicious remote servers to execute arbitrary code via a long console command.
- CVE-2001-1018Sep 20, 2001risk 0.00cvss —epss 0.02
Lotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that contains a long sequence of / (slash) characters.
- CVE-2001-1029Sep 20, 2001risk 0.03cvss —epss 0.01
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome…
- CVE-2000-1215Sep 19, 2001risk 0.00cvss —epss 0.02
The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information.
- CVE-2001-0962Sep 19, 2001risk 0.00cvss —epss 0.02
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
- CVE-2001-0961Sep 18, 2001risk 0.00cvss —epss 0.06
Buffer overflow in tab expansion capability of the most program allows local or remote attackers to execute arbitrary code via a malformed file that is viewed with most.
- CVE-2001-1353Sep 18, 2001risk 0.00cvss —epss 0.00
ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.
- CVE-2001-0959Sep 15, 2001risk 0.00cvss —epss 0.03
Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 creates a hidden share named ARCSERVE$, which allows remote attackers to obtain sensitive information and overwrite critical files.
- CVE-2001-0960Sep 15, 2001risk 0.00cvss —epss 0.03
Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows local and remote attackers to gain privileges.
- CVE-2001-1014Sep 15, 2001risk 0.00cvss —epss 0.02
eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter.
- CVE-2001-0986Sep 14, 2001risk 0.07cvss —epss 0.48
SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2)…
- CVE-2001-0984Sep 13, 2001risk 0.00cvss —epss 0.00
Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options enabled, which could allow…
- CVE-2001-1136Sep 13, 2001risk 0.00cvss —epss 0.01
The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.
- CVE-2001-0958Sep 12, 2001risk 0.00cvss —epss 0.05
Buffer overflows in eManager plugin for Trend Micro InterScan VirusWall for NT 3.51 and 3.51J allow remote attackers to execute arbitrary code via long arguments to the CGI programs (1) register.dll, (2) ContentFilter.dll, (3) SFNofitication.dll, (4) register.dll, (5) TOP10.dll,…
- CVE-2001-0999Sep 12, 2001risk 0.01cvss —epss 0.12
Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script.
- CVE-2001-1013Sep 12, 2001risk 0.08cvss —epss 0.66
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.