LiveActive security incident?Get immediate response
CVE archive

2001 CVE Archive

Browse CVE records published in 2001 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1537 matching CVEs · Page 10 of 31.

Unknown · CVSS Not scored

CVE-2001-1129: Format string vulnerabilities in (1) _probuild, (2) _dbutil, (3) _mprosrv, (4) _mprshut, (5) _proapsv, (6)...

Format string vulnerabilities in (1) _probuild, (2) _dbutil, (3) _mprosrv, (4) _mprshut, (5) _proapsv, (6) _progres, (7) _proutil, (8) _rfutil and (9) prolib in Progress database 9.1C allows a local user to execute arbitrary code via format string specifiers in the file used by the PROMSGS environment variable.

Published Mar 15, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2001-1078: Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain...

Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.

Published Feb 2, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2001-1088: Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I...

Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.

Published Jun 25, 2002 · Updated Aug 8, 2024