Latest CVE Feed
-
5.0
MEDIUMCVE-2000-0897
Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is co... Read more
Affected Products : small_http_server- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1118
24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request.... Read more
Affected Products : 24link- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1081
The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allo... Read more
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1186
Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a long MIME header.... Read more
Affected Products : phf- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1129
McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.... Read more
Affected Products : webshield_smtp- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1158
NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords.... Read more
Affected Products : sniffer_agent- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1173
Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive informatio... Read more
Affected Products : cyberpatrol- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1114
Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".... Read more
Affected Products : ewave_servletexec- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2000-1162
ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.... Read more
Affected Products : ghostscript- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1171
Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot dot) attack in the "thesection" parameter.... Read more
Affected Products : cgiforum- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1188
Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter.... Read more
Affected Products : quikstore- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1109
Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the command... Read more
Affected Products : midnight_commander- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1169
OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent.... Read more
Affected Products : openssh- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1134
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a sy... Read more
Affected Products : hp-ux suse_linux linux linux mandrake_linux openlinux openlinux_edesktop openlinux_eserver immunix- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1125
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.... Read more
Affected Products : linux- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-1083
The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an at... Read more
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0899
Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests.... Read more
Affected Products : small_http_server- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1150
Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.... Read more
Affected Products : felix- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1166
Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.... Read more
Affected Products : twig- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1145
Recourse ManTrap 1.6 allows attackers who have gained root access to use utilities such as crash or fsdb to read /dev/mem and raw disk devices to identify ManTrap processes or modify arbitrary data files.... Read more
Affected Products : mantrap- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025