Latest CVE Feed
-
7.5
HIGHCVE-2000-0779
Checkpoint Firewall-1 with the RSH/REXEC setting enabled allows remote attackers to bypass access restrictions and connect to a RSH/REXEC client via malformed connection requests.... Read more
Affected Products : firewall-1- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0788
The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.... Read more
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0677
Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to execute arbitrary commands via a long PATH_INFO environmental variable.... Read more
Affected Products : net.data- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0684
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.... Read more
Affected Products : weblogic_server- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0702
The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.... Read more
Affected Products : hp-ux- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0790
The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a d... Read more
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0707
PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allows remote attackers to obtain sensitive information such as the administrative password.... Read more
Affected Products : mysqldatabase_admin_tool- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0746
Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to t... Read more
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0749
Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system.... Read more
Affected Products : freebsd- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2000-0770
IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalizat... Read more
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2000-0780
The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (dot dot) attack.... Read more
Affected Products : imail- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0768
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.... Read more
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0781
uagentsetup in ARCServeIT Client Agent 6.62 does not properly check for the existence or ownership of a temporary file which is moved to the agent.cfg configuration file, which allows local users to execute arbitrary commands by modifying the temporary fi... Read more
Affected Products : arcserve_backup- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2000-0031
The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.... Read more
Affected Products : linux- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0797
Buffer overflow in gr_osview in IRIX 6.2 and 6.3 allows local users to gain privileges via a long -D option.... Read more
Affected Products : irix- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0754
Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.... Read more
Affected Products : openview_network_node_manager- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0787
IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser.... Read more
Affected Products : xchat- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0796
Buffer overflow in dmplay in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long command line option.... Read more
Affected Products : irix- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0783
Watchguard Firebox II allows remote attackers to cause a denial of service by sending a malformed URL to the authentication service on port 4100.... Read more
Affected Products : firebox- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0698
Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via a symlink attack.... Read more
Affected Products : minicom- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025