Latest CVE Feed
-
10.0
HIGHCVE-2000-0999
Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges.... Read more
Affected Products : openssh- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-1003
NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash.... Read more
- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1022
The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands.... Read more
Affected Products : pix_firewall_software- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1009
dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.... Read more
- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1049
Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of "." characters.... Read more
Affected Products : jrun- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1222
AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.... Read more
Affected Products : aix- Published: Dec. 10, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1224
Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others.... Read more
Affected Products : resin- Published: Nov. 23, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1217
Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited... Read more
Affected Products : windows_2000- Published: Nov. 21, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1223
quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request.... Read more
Affected Products : quikstore- Published: Nov. 20, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0850
Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested URL.... Read more
Affected Products : siteminder- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0881
The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.... Read more
Affected Products : lpplus- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0883
The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.... Read more
Affected Products : mandrake_linux- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0831
Buffer overflow in Fastream FTP++ 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long username.... Read more
Affected Products : ftp\+\+_server- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0871
Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server.... Read more
Affected Products : eftp- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2000-0862
Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information.... Read more
Affected Products : spectra- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0874
Eudora mail client includes the absolute path of the sender's host within a virtual card (VCF).... Read more
Affected Products : eudora- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0859
The web configuration server for NTMail V5 and V6 allows remote attackers to cause a denial of service via a series of partial HTTP requests.... Read more
Affected Products : ntmail- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0824
The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environ... Read more
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0851
Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the "Still Image Service Privilege Escalation" vulnerability.... Read more
Affected Products : windows_2000- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0869
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.... Read more
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025