Latest CVE Feed
-
4.6
MEDIUMCVE-2000-1180
Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument.... Read more
Affected Products : oracle8i- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2000-1164
WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to read and modify sensitive information such as passwords and gain access to the system.... Read more
Affected Products : winvnc- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1187
Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.... Read more
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1088
The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which a... Read more
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1086
The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which ... Read more
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2000-1127
registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the per... Read more
Affected Products : hp-ux- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1103
rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.... Read more
Affected Products : bsd_os- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1106
Trend Micro InterScan VirusWall creates an "Intscan" share to the "InterScan" directory with permissions that grant Full Control permissions to the Everyone group, which allows attackers to gain privileges by modifying the VirusWall programs.... Read more
Affected Products : interscan_viruswall- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1168
IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.... Read more
Affected Products : http_server- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1148
The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the server administrator passwords in plaintext, which allows local users to gain privileges on the server.... Read more
Affected Products : volanochatpro- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1185
The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests.... Read more
Affected Products : ridewaypn- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1167
ppp utility in FreeBSD 4.1.1 and earlier does not properly restrict access as specified by the "nat deny_incoming" command, which allows remote attackers to connect to the target system.... Read more
Affected Products : freebsd- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0897
Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is co... Read more
Affected Products : small_http_server- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1092
loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.... Read more
Affected Products : ezshopper- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2000-1099
Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities.... Read more
Affected Products : jdk- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1114
Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".... Read more
Affected Products : ewave_servletexec- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1081
The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allo... Read more
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1186
Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a long MIME header.... Read more
Affected Products : phf- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1173
Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive informatio... Read more
Affected Products : cyberpatrol- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1158
NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords.... Read more
Affected Products : sniffer_agent- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025