Latest CVE Feed
-
5.0
MEDIUMCVE-2000-0977
mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.... Read more
Affected Products : mail_file- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0929
Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.... Read more
Affected Products : windows_media_player- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0970
IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking"... Read more
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2000-0979
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of ... Read more
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0955
Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.... Read more
Affected Products : virtual_central_office_4000- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0990
cmd5checkpw 0.21 and earlier allows remote attackers to cause a denial of service via an "SMTP AUTH" command with an unknown username.... Read more
Affected Products : cmd5checkpw- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0930
Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.... Read more
Affected Products : pegasus_mail- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0980
NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network.... Read more
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0973
Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.... Read more
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0933
The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Reco... Read more
Affected Products : windows_2000- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0906
Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the category or format parameters.... Read more
Affected Products : cached_feed.cgi_script- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0818
The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands.... Read more
Affected Products : listener- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0888
named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the "srv bug."... Read more
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0803
GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff.... Read more
Affected Products : groff- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0947
Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.... Read more
Affected Products : cfengine- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0921
Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.... Read more
Affected Products : shopping_cart- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0901
Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters in the vbell_msg initialization variable.... Read more
Affected Products : weigert_screen- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0954
Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server.... Read more
Affected Products : shambala_server- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0907
EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands.... Read more
Affected Products : eserv- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0935
Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.... Read more
Affected Products : samba- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025