Back
CVE-2001-0913
Format string vulnerability in Network Solutions Rwhoisd 1.5.7.2 and earlier, when using syslog, allows remote attackers to corrupt memory and possibly execute arbitrary code via a rwhois request that contains format specifiers.
Published: Nov 22, 2001
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (9)
| Vendor | Product | Version |
|---|---|---|
| network_solutions | rwhoisd | 1.5 |
| network_solutions | rwhoisd | 1.5.1a |
| network_solutions | rwhoisd | 1.5.2 |
| network_solutions | rwhoisd | 1.5.3 |
| network_solutions | rwhoisd | 1.5.5 |
| network_solutions | rwhoisd | 1.5.6 |
| network_solutions | rwhoisd | 1.5.7 |
| network_solutions | rwhoisd | 1.5.7.1 |
| network_solutions | rwhoisd | 1.5.7.2 |
GitHub Security Advisory GHSA-xr65-3229-qjf4
Format string vulnerability in Network Solutions Rwhoisd 1.5.7.2 and earlier, when using syslog,...
References (4)
- http://lists.research.netsol.com/pipermail/rwhois-announce/2001-November/000023.html Patch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=100655265508104&w=2
- http://lists.research.netsol.com/pipermail/rwhois-announce/2001-November/000023.html Patch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=100655265508104&w=2
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
2.90%
Top 14% most likely to be exploited
Threat Score
30.9 / 100
Data Sources
NVD
EPSS
GitHub