Latest CVE Feed
-
6.4
MEDIUMCVE-2000-0940
Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.... Read more
Affected Products : pagelog.cgi- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1212
Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.... Read more
Affected Products : zope- Published: Dec. 18, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1211
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.... Read more
Affected Products : zope- Published: Dec. 16, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1579
The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on the ... Read more
Affected Products : windows_nt- Published: Dec. 14, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1042
Buffer overflow in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.... Read more
Affected Products : mandrake_linux- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1023
The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name information via the nsManager.cgi CGI program.... Read more
Affected Products : control_panel- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1051
Directory traversal vulnerability in Allaire JRun 2.3 server allows remote attackers to read arbitrary files via the SSIFilter servlet.... Read more
Affected Products : jrun- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1021
Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.... Read more
Affected Products : mdaemon- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1056
CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.... Read more
Affected Products : secure_access_control_server- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1034
Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability.... Read more
Affected Products : windows_2000- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1044
Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges.... Read more
Affected Products : suse_linux- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1074
csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.... Read more
Affected Products : iplanet_ical- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1033
Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords of other users.... Read more
Affected Products : serv-u- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1071
The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges.... Read more
Affected Products : iplanet_ical- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1017
Webteachers Webdata allows remote attackers with valid Webdata accounts to read arbitrary files by posting a request to import the file into the WebData database.... Read more
Affected Products : webdata- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1062
Buffer overflow in the FTP service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.... Read more
Affected Products : jetdirect- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1048
Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GET request that uses encoded characters in the URL.... Read more
Affected Products : wingate- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1038
The web administration interface for IBM AS/400 Firewall allows remote attackers to cause a denial of service via an empty GET request.... Read more
Affected Products : as400_firewall- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1013
The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.... Read more
Affected Products : freebsd- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1065
Vulnerability in IP implementation of HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service (printer crash) via a malformed packet.... Read more
Affected Products : jetdirect- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025