
CVE-2001-1072
https://notcve.org/view.php?id=CVE-2001-1072
31 Aug 2001 — Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail. • http://www.apacheweek.com/issues/02-02-01#security •

CVE-2001-1342
https://notcve.org/view.php?id=CVE-2001-1342
12 May 2001 — Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer. • http://bugs.apache.org/index.cgi/full/7522 •

CVE-2001-0285
https://notcve.org/view.php?id=CVE-2001-0285
04 Apr 2001 — Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request. • http://archives.neohapsis.com/archives/bugtraq/2001-02/0457.html •

CVE-2001-0286 – Robin Twombly A1 HTTP Server 1.0 - Directory Traversal
https://notcve.org/view.php?id=CVE-2001-0286
04 Apr 2001 — Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request. • https://www.exploit-db.com/exploits/20657 •

CVE-2001-0122 – IBM HTTP Server 1.3 - AfpaCache/WebSphereNet.Data Denial of Service
https://notcve.org/view.php?id=CVE-2001-0122
13 Mar 2001 — Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error. • https://www.exploit-db.com/exploits/20531 •

CVE-2001-0925 – Apache 1.3 - Artificially Long Slash Path Directory Listing
https://notcve.org/view.php?id=CVE-2001-0925
12 Mar 2001 — The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex. • https://www.exploit-db.com/exploits/20692 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2001-0042 – Apache 1.3 + PHP 3 - File Disclosure
https://notcve.org/view.php?id=CVE-2001-0042
16 Feb 2001 — PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences. • https://www.exploit-db.com/exploits/20466 •

CVE-2001-0131
https://notcve.org/view.php?id=CVE-2001-0131
14 Feb 2001 — htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack. • http://marc.info/?l=bugtraq&m=97916374410647&w=2 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVE-2000-0913
https://notcve.org/view.php?id=CVE-2000-0913
19 Dec 2000 — mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression. • http://archives.neohapsis.com/archives/bugtraq/2000-09/0352.html •

CVE-2000-1168
https://notcve.org/view.php?id=CVE-2000-1168
19 Dec 2000 — IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request. • http://marc.info/?l=bugtraq&m=97502498610979&w=2 •