Latest CVE Feed
-
7.2
HIGHCVE-2000-0680
The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a... Read more
Affected Products : cvs- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0686
Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.... Read more
Affected Products : auction_weaver- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0737
The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability.... Read more
Affected Products : windows_2000- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0359
Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.... Read more
Affected Products : thttpd- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0704
Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO commands.... Read more
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2000-0031
The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.... Read more
Affected Products : linux- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0729
FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.... Read more
Affected Products : freebsd- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0762
The default installation of eTrust Access Control (formerly SeOS) uses a default encryption key, which allows remote attackers to spoof the eTrust administrator and gain privileges.... Read more
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0676
Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice.... Read more
Affected Products : communicator- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0741
Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.... Read more
Affected Products : net_tools_pki_server- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0740
Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port.... Read more
Affected Products : net_tools_pki_server- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0755
Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.... Read more
Affected Products : openview_network_node_manager- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0731
Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack.... Read more
Affected Products : worm_webserver- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0779
Checkpoint Firewall-1 with the RSH/REXEC setting enabled allows remote attackers to bypass access restrictions and connect to a RSH/REXEC client via malformed connection requests.... Read more
Affected Products : firewall-1- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0789
WinU 5.x and earlier uses weak encryption to store its configuration password, which allows local users to decrypt the password and gain privileges.... Read more
Affected Products : winu- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0684
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.... Read more
Affected Products : weblogic_server- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1213
ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping's exposure to bugs that otherwise would occur at lower privileges.... Read more
- Published: Oct. 18, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1214
Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, may allow local users to gain privileges.... Read more
- Published: Oct. 18, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1563
Nachuatec D435 and D445 printer allows remote attackers to cause a denial of service via ICMP redirect storm.... Read more
- Published: Oct. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1204
Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.... Read more
Affected Products : http_server- Published: Oct. 13, 2000
- Modified: Apr. 03, 2025