Latest CVE Feed
-
7.5
HIGHCVE-2000-0792
Gnome Lokkit firewall package before 0.41 does not properly restrict access to some ports, even if a user does not make any services available.... Read more
Affected Products : gnome-lokkit- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0757
The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.... Read more
Affected Products : totalbill- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0360
Buffer overflow in INN 2.2.1 and earlier allows remote attackers to cause a denial of service via a maliciously formatted article.... Read more
Affected Products : inn- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0686
Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.... Read more
Affected Products : auction_weaver- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0779
Checkpoint Firewall-1 with the RSH/REXEC setting enabled allows remote attackers to bypass access restrictions and connect to a RSH/REXEC client via malformed connection requests.... Read more
Affected Products : firewall-1- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0755
Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.... Read more
Affected Products : openview_network_node_manager- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0731
Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack.... Read more
Affected Products : worm_webserver- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0740
Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port.... Read more
Affected Products : net_tools_pki_server- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0680
The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a... Read more
Affected Products : cvs- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0706
Buffer overflows in ntop running in web mode allows remote attackers to execute arbitrary commands.... Read more
Affected Products : ntop- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0737
The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability.... Read more
Affected Products : windows_2000- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0359
Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.... Read more
Affected Products : thttpd- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0704
Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO commands.... Read more
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0730
Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.... Read more
Affected Products : hp-ux- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0725
Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.... Read more
Affected Products : zope- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0682
BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet.... Read more
Affected Products : weblogic_server- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0739
Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server.... Read more
Affected Products : net_tools_pki_server- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0711
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.... Read more
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0698
Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via a symlink attack.... Read more
Affected Products : minicom- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0768
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.... Read more
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025