Latest CVE Feed
-
4.6
MEDIUMCVE-2000-1085
The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows... Read more
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1114
Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".... Read more
Affected Products : ewave_servletexec- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1081
The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allo... Read more
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1173
Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive informatio... Read more
Affected Products : cyberpatrol- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1092
loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.... Read more
Affected Products : ezshopper- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1129
McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.... Read more
Affected Products : webshield_smtp- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1186
Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a long MIME header.... Read more
Affected Products : phf- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1118
24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request.... Read more
Affected Products : 24link- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1158
NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords.... Read more
Affected Products : sniffer_agent- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1131
Bill Kendrick web site guestbook (GBook) allows remote attackers to execute arbitrary commands via shell metacharacters in the _MAILTO form variable.... Read more
Affected Products : gbook.cgi- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-1144
Recourse ManTrap 1.6 sets up a chroot environment to hide the fact that it is running, but the inode number for the resulting "/" file system is higher than normal, which allows attackers to determine that they are in a chroot environment.... Read more
Affected Products : mantrap- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0898
Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file.... Read more
Affected Products : small_http_server- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1113
Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the ".ASX Buffer Overrun" vulnerability.... Read more
Affected Products : windows_media_player- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1101
Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack.... Read more
Affected Products : wftpd- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1100
The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET reque... Read more
Affected Products : postaci_webmail- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2000-1105
The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled.... Read more
Affected Products : indexing_service- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1110
document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.... Read more
Affected Products : net.data- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1087
The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which ... Read more
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1082
The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows ... Read more
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1089
Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.... Read more
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025