Show filters
486 Total Results
Displaying 441-450 of 486
Sort by:
Attacker Value
Unknown
CVE-2001-1342
Disclosure Date: May 12, 2001 (last updated February 22, 2025)
Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
0
Attacker Value
Unknown
CVE-2001-0307
Disclosure Date: May 03, 2001 (last updated February 22, 2025)
Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.
0
Attacker Value
Unknown
CVE-2001-0308
Disclosure Date: May 03, 2001 (last updated February 22, 2025)
UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.
0
Attacker Value
Unknown
CVE-2001-0286
Disclosure Date: May 03, 2001 (last updated February 22, 2025)
Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.
0
Attacker Value
Unknown
CVE-2001-0285
Disclosure Date: May 03, 2001 (last updated February 22, 2025)
Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.
0
Attacker Value
Unknown
CVE-2001-0122
Disclosure Date: March 13, 2001 (last updated February 22, 2025)
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
0
Attacker Value
Unknown
CVE-2001-0925
Disclosure Date: March 12, 2001 (last updated February 22, 2025)
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
0
Attacker Value
Unknown
CVE-2001-0131
Disclosure Date: March 12, 2001 (last updated February 22, 2025)
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
0
Attacker Value
Unknown
CVE-2001-0042
Disclosure Date: February 16, 2001 (last updated February 22, 2025)
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.
0
Attacker Value
Unknown
CVE-2000-0898
Disclosure Date: January 09, 2001 (last updated February 22, 2025)
Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file.
0