Latest CVE Feed
-
5.0
MEDIUMCVE-2000-1050
Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request (aka the "extra leading slash").... Read more
Affected Products : jrun- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1020
Heap overflow in Worldclient in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.... Read more
Affected Products : mdaemon- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1008
PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device to decrypt the password and gain access to the device.... Read more
Affected Products : palm_os- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1073
csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory.... Read more
Affected Products : iplanet_ical- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1026
Multiple buffer overflows in LBNL tcpdump allow remote attackers to execute arbitrary commands.... Read more
Affected Products : tcpdump- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1063
Buffer overflow in the Telnet service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.... Read more
Affected Products : jetdirect- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1049
Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of "." characters.... Read more
Affected Products : jrun- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1030
CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.... Read more
Affected Products : corporatetime_for_the_web- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1057
Vulnerabilities in database configuration scripts in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows local users to gain privileges, possibly via insecure permissions.... Read more
Affected Products : openview_network_node_manager- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1025
eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which invokes the ServletExec servlet and causes an exception if the servlet is alre... Read more
Affected Products : ewave_servletexec- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1015
The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode privileges and possibly execute arbitrary commands.... Read more
Affected Products : slashcode- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1007
I-gear 3.5.7 and earlier does not properly process log entries in which a URL is longer than 255 characters, which allows an attacker to cause reporting errors.... Read more
Affected Products : i-gear- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1028
Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.... Read more
Affected Products : hp-ux- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1027
Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established.... Read more
Affected Products : pix_firewall_software- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1075
Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.... Read more
- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1072
iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.... Read more
Affected Products : iplanet_ical- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1040
Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service.... Read more
- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1055
Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet.... Read more
Affected Products : secure_access_control_server- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1029
Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query.... Read more
Affected Products : bind- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1066
The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname.... Read more
Affected Products : freebsd- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025