LiveActive security incident?Get immediate response
CVE archive

2001 CVE Archive

Browse CVE records published in 2001 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1537 matching CVEs · Page 9 of 31.

Unknown · CVSS Not scored

CVE-2001-1211: Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user ali...

Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain.

Published Mar 15, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2001-1184: wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of se...

wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a negative number, which causes a connection attempt to that port and all ports below 1024, and (2) in 2.21.00, a port number of 1024.

Published Mar 15, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2001-1159: load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize ce...

load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary code by using options_order.php to upload a message that could be interpreted as PHP.

Published Mar 15, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2001-1130: Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading...

Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using a .. in the HTTP referer (from the HTTP_REFERER variable) to point to the directory that contains the keylist.txt file.

Published Jun 25, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2001-1152: Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypa...

Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file is in the parentdir, (3) a /./, or (4) URL-encoded characters.

Published Mar 15, 2002 · Updated Aug 8, 2024