Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.6

    MEDIUM
    CVE-2000-1086

    The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which ... Read more

    Affected Products : sql_server sql_server data_engine
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1102

    PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode +owgscfxeb" and "oper" commands.... Read more

    Affected Products : ptlink_irc_services ptlink_ircd
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1039

    Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, ak... Read more

    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2000-1125

    restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.... Read more

    Affected Products : linux
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1151

    Baxter IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.... Read more

    Affected Products : baxter
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1097

    The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via a long username in the authentication page.... Read more

    Affected Products : soho_firewall
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-0899

    Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests.... Read more

    Affected Products : small_http_server
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2000-1083

    The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an at... Read more

    Affected Products : sql_server sql_server data_engine
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1098

    The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or POST request.... Read more

    Affected Products : soho_firewall
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1188

    Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter.... Read more

    Affected Products : quikstore
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2000-1109

    Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the command... Read more

    Affected Products : midnight_commander
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2000-1099

    Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities.... Read more

    Affected Products : jdk
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2000-1112

    Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.... Read more

    Affected Products : windows_media_player
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2000-1186

    Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a long MIME header.... Read more

    Affected Products : phf
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1173

    Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive informatio... Read more

    Affected Products : cyberpatrol
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2000-1158

    NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords.... Read more

    Affected Products : sniffer_agent
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2000-1118

    24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request.... Read more

    Affected Products : 24link
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1129

    McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.... Read more

    Affected Products : webshield_smtp
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1092

    loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.... Read more

    Affected Products : ezshopper
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1114

    Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".... Read more

    Affected Products : ewave_servletexec
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
Showing 20 of 293515 Results