Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.0

    HIGH
    CVE-2000-1164

    WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to read and modify sensitive information such as passwords and gain access to the system.... Read more

    Affected Products : winvnc
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2000-1121

    Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.... Read more

    Affected Products : aix
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2000-1148

    The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the server administrator passwords in plaintext, which allows local users to gain privileges on the server.... Read more

    Affected Products : volanochatpro
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2000-1168

    IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.... Read more

    Affected Products : http_server
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2000-1157

    Buffer overflow in NAI Sniffer Agent allows remote attackers to execute arbitrary commands via a long SNMP community name.... Read more

    Affected Products : sniffer_agent
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2000-1106

    Trend Micro InterScan VirusWall creates an "Intscan" share to the "InterScan" directory with permissions that grant Full Control permissions to the Everyone group, which allows attackers to gain privileges by modifying the VirusWall programs.... Read more

    Affected Products : interscan_viruswall
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2000-1103

    rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.... Read more

    Affected Products : bsd_os
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 3.6

    LOW
    CVE-2000-1127

    registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the per... Read more

    Affected Products : hp-ux
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2000-1088

    The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which a... Read more

    Affected Products : sql_server sql_server data_engine
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2000-1187

    Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.... Read more

    Affected Products : navigator communicator
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2000-1104

    Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back t... Read more

    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1155

    RHDaemon in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.... Read more

    Affected Products : robinhood
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1154

    RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.... Read more

    Affected Products : robinhood
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2000-1132

    DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" variable.... Read more

    Affected Products : dcforum
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2000-1128

    The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:\Program Files directory.... Read more

    Affected Products : virusscan
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2000-1180

    Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument.... Read more

    Affected Products : oracle8i
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1101

    Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack.... Read more

    Affected Products : wftpd
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2000-1166

    Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.... Read more

    Affected Products : twig
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2000-1089

    Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.... Read more

    Affected Products : windows_2000 windows_nt
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1165

    Balabit syslog-ng allows remote attackers to cause a denial of service (application crash) via a malformed log message that does not have a closing > in the priority specifier.... Read more

    Affected Products : syslog-ng
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 293344 Results