Latest CVE Feed
-
5.0
MEDIUMCVE-2000-1065
Vulnerability in IP implementation of HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service (printer crash) via a malformed packet.... Read more
Affected Products : jetdirect- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1071
The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges.... Read more
Affected Products : iplanet_ical- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1013
The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.... Read more
Affected Products : freebsd- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1074
csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.... Read more
Affected Products : iplanet_ical- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1078
ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.... Read more
Affected Products : icq_web_front- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1042
Buffer overflow in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.... Read more
Affected Products : mandrake_linux- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1023
The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name information via the nsManager.cgi CGI program.... Read more
Affected Products : control_panel- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1222
AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.... Read more
Affected Products : aix- Published: Dec. 10, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1224
Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others.... Read more
Affected Products : resin- Published: Nov. 23, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-1217
Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited... Read more
Affected Products : windows_2000- Published: Nov. 21, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1223
quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request.... Read more
Affected Products : quikstore- Published: Nov. 20, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0860
The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.... Read more
Affected Products : php- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0853
YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack.... Read more
Affected Products : yabb- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0867
Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.... Read more
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0870
Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string.... Read more
Affected Products : eftp- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0868
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.... Read more
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0854
When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same dir... Read more
Affected Products : office- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0813
Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to redirect FTP connections to other servers ("FTP Bounce") via invalid FTP commands that are processed improperly by FireWall-1, aka "FTP Connection Enforcement Bypass."... Read more
Affected Products : firewall-1- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0840
Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long USER command.... Read more
Affected Products : xmail- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0848
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.... Read more
Affected Products : websphere_application_server- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025