Latest CVE Feed
-
6.4
MEDIUMCVE-2000-0862
Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information.... Read more
Affected Products : spectra- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2000-0845
kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.... Read more
Affected Products : unix- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0834
The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client... Read more
Affected Products : windows_2000- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2000-0864
Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileges, via a symlink attack.... Read more
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0853
YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack.... Read more
Affected Products : yabb- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0855
SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline.... Read more
Affected Products : xs4all_data_sunftp- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0812
The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ ta... Read more
Affected Products : java_system_web_server- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0804
Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass the directionality check via fragmented TCP connection requests or reopening closed TCP connection requests, aka "One-way Connection Enforcement Bypass."... Read more
Affected Products : firewall-1- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0813
Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to redirect FTP connections to other servers ("FTP Bounce") via invalid FTP commands that are processed improperly by FireWall-1, aka "FTP Connection Enforcement Bypass."... Read more
Affected Products : firewall-1- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0854
When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same dir... Read more
Affected Products : office- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0835
search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.... Read more
Affected Products : sambar_server- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0870
Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string.... Read more
Affected Products : eftp- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0867
Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.... Read more
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0868
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.... Read more
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1080
Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.... Read more
- Published: Nov. 01, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1219
The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows.... Read more
- Published: Nov. 01, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0678
PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypte... Read more
Affected Products : pgp- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0728
xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : xpdf- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0688
Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter.... Read more
Affected Products : subscribe_me_lite- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0782
netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.... Read more
Affected Products : netauth- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025