Latest CVE Feed
-
4.6
MEDIUMCVE-2000-0910
Horde library 1.02 allows attackers to execute arbitrary commands via shell metacharacters in the "from" address.... Read more
Affected Products : horde- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0905
QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page.... Read more
Affected Products : voyager- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0926
SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable.... Read more
Affected Products : cyberoffice_shopping_cart- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0989
Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute commands via a long username.... Read more
Affected Products : inbusiness_email_station- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0987
Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.... Read more
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0992
Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.... Read more
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0915
fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.... Read more
Affected Products : freebsd- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0977
mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.... Read more
Affected Products : mail_file- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0920
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."... Read more
Affected Products : boa_webserver- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0922
Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter.... Read more
Affected Products : web_shopper- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0925
The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.... Read more
Affected Products : cyberoffice_shopping_cart- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0996
Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.... Read more
Affected Products : openbsd- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0993
Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.... Read more
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0911
IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment.... Read more
Affected Products : imp- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0978
bbd server in Big Brother System and Network Monitor before 1.5c2 allows remote attackers to execute arbitrary commands via the "&" shell metacharacter.... Read more
Affected Products : big_brother_network_monitor- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0927
WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions.... Read more
Affected Products : quotaadvisor- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0810
Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.... Read more
Affected Products : auction_weaver- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0952
global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters.... Read more
Affected Products : global- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0937
Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks.... Read more
Affected Products : samba- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0886
IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.... Read more
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025