Latest CVE Feed
-
9.8
CRITICALCVE-2000-1218
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to po... Read more
- Published: Apr. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0254
The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.... Read more
Affected Products : dansie_shopping_cart- Published: Apr. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0282
TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program.... Read more
Affected Products : web\+- Published: Apr. 12, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0259
The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users.... Read more
- Published: Apr. 12, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0258
IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.... Read more
- Published: Apr. 12, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0261
The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.... Read more
Affected Products : ken- Published: Apr. 12, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0262
The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request.... Read more
Affected Products : ken- Published: Apr. 12, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0288
Infonautics getdoc.cgi allows remote attackers to bypass the payment phase for accessing documents via a modified form variable.... Read more
Affected Products :- Published: Apr. 12, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0287
The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter.... Read more
Affected Products : technology_bizdb- Published: Apr. 12, 2000
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2000-0283
The default installation of IRIX Performance Copilot allows remote attackers to access sensitive system information via the pmcd daemon.... Read more
Affected Products : irix- Published: Apr. 12, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0252
The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable.... Read more
Affected Products : dansie_shopping_cart- Published: Apr. 11, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-0699
The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs.... Read more
Affected Products : sapphire_web- Published: Apr. 11, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-0701
After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.... Read more
Affected Products : windows_nt- Published: Apr. 11, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-0979
The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into _init before the privileged process is executed.... Read more
Affected Products : unixware- Published: Apr. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0253
The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields.... Read more
Affected Products : dansie_shopping_cart- Published: Apr. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-0695
The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack.... Read more
Affected Products : powerdynamo- Published: Apr. 11, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0274
The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name.... Read more
Affected Products : linux_trustees- Published: Apr. 10, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0275
CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.... Read more
Affected Products : cryptoadmin- Published: Apr. 10, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0276
BeOS 4.5 and 5.0 allow local users to cause a denial of service via malformed direct system calls using interrupt 37.... Read more
Affected Products : beos- Published: Apr. 10, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0294
Buffer overflow in healthd for FreeBSD allows local users to gain root privileges.... Read more
Affected Products : healthd- Published: Apr. 10, 2000
- Modified: Apr. 03, 2025