Latest CVE Feed
-
5.0
MEDIUMCVE-2000-1228
Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.... Read more
Affected Products : phorum- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2000-1239
The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data fi... Read more
Affected Products : tivoli_management_framework- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1230
Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".... Read more
Affected Products : phorum- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1227
Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.... Read more
- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2000-1242
The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access.... Read more
Affected Products : powerchute- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1231
code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string.... Read more
Affected Products : phorum- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1243
Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product developers.... Read more
Affected Products : shopping_cart- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1244
Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the "From" field, which allows remote attackers to bypass virus protection.... Read more
Affected Products : inoculateit_agent_for_exchange- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1234
violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters.... Read more
Affected Products : phorum- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-0307
Buffer overflow in HP-UX cstm program allows local users to gain root privileges.... Read more
Affected Products : hp-ux- Published: Dec. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0803
GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff.... Read more
Affected Products : groff- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0913
mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.... Read more
Affected Products : http_server- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0977
mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.... Read more
Affected Products : mail_file- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0920
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."... Read more
Affected Products : boa_webserver- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0922
Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter.... Read more
Affected Products : web_shopper- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0975
Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack.... Read more
Affected Products : foundation_directory- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0982
Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Crede... Read more
Affected Products : internet_explorer- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0817
Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability.... Read more
Affected Products : network_monitor- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0993
Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.... Read more
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0810
Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.... Read more
Affected Products : auction_weaver- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025