Latest CVE Feed
-
10.0
HIGHCVE-2000-1071
The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges.... Read more
Affected Products : iplanet_ical- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1041
Buffer overflow in ypbind 3.3 possibly allows an attacker to gain root privileges.... Read more
Affected Products : ypbind- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1005
Directory traversal vulnerability in html_web_store.cgi and web_store.cgi CGI programs in eXtropia WebStore allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.... Read more
Affected Products : extropia_webstore- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1016
The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages UR... Read more
Affected Products : suse_linux- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1047
Buffer overflow in SMTP service of Lotus Domino 5.0.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long ENVID keyword in the "MAIL FROM" command.... Read more
- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1049
Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of "." characters.... Read more
Affected Products : jrun- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1222
AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.... Read more
Affected Products : aix- Published: Dec. 10, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1224
Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others.... Read more
Affected Products : resin- Published: Nov. 23, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1217
Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited... Read more
Affected Products : windows_2000- Published: Nov. 21, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1223
quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request.... Read more
Affected Products : quikstore- Published: Nov. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0854
When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same dir... Read more
Affected Products : office- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0835
search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.... Read more
Affected Products : sambar_server- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0878
The mailto CGI script allows remote attacker to execute arbitrary commands via shell metacharacters in the emailadd form field.... Read more
Affected Products : mailto_cgi_script- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0827
Buffer overflow in the web authorization form of Mobius DocumentDirect for the Internet 1.2 allows remote attackers to cause a denial of service or execute arbitrary commands via a long username.... Read more
Affected Products : documentdirect_for_the_internet- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0848
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.... Read more
Affected Products : websphere_application_server- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0844
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.... Read more
Affected Products : debian_linux aix solaris sunos suse_linux linux linux mandrake_linux slackware_linux secure_linux +6 more products- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0882
Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash.... Read more
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0872
explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.... Read more
Affected Products : phpphotoalbum- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0812
The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ ta... Read more
Affected Products : java_system_web_server- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0841
Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long APOP command.... Read more
Affected Products : xmail- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025