Latest CVE Feed
-
7.2
HIGHCVE-2000-0995
Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.... Read more
Affected Products : openbsd- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0954
Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server.... Read more
Affected Products : shambala_server- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0921
Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.... Read more
Affected Products : shopping_cart- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0901
Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters in the vbell_msg initialization variable.... Read more
Affected Products : weigert_screen- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0907
EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands.... Read more
Affected Products : eserv- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0941
Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.... Read more
Affected Products : kootenay_web_inc_whois- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0960
The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.... Read more
Affected Products : messaging_server- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0952
global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters.... Read more
Affected Products : global- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0948
GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.... Read more
Affected Products : gnorpm- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0917
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.... Read more
Affected Products : linux secure_linux openlinux openlinux_ebuilder openlinux_edesktop openlinux_eserver- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0886
IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.... Read more
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0911
IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment.... Read more
Affected Products : imp- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0987
Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.... Read more
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0989
Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute commands via a long username.... Read more
Affected Products : inbusiness_email_station- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0887
named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the "zxfr bug."... Read more
Affected Products : bind- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0947
Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.... Read more
Affected Products : cfengine- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0922
Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter.... Read more
Affected Products : web_shopper- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0920
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."... Read more
Affected Products : boa_webserver- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0977
mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.... Read more
Affected Products : mail_file- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2000-0940
Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.... Read more
Affected Products : pagelog.cgi- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025