Latest CVE Feed
-
7.5
HIGHCVE-2000-0807
The OPSEC communications authentication mechanism (fwn1) in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to spoof connections, aka the "OPSEC Authentication Vulnerability."... Read more
Affected Products : firewall-1- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0876
WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname.... Read more
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0842
The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.... Read more
Affected Products : unixware- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0869
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.... Read more
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2000-0845
kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.... Read more
Affected Products : unix- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2000-0862
Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information.... Read more
Affected Products : spectra- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0874
Eudora mail client includes the absolute path of the sender's host within a virtual card (VCF).... Read more
Affected Products : eudora- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0824
The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environ... Read more
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0859
The web configuration server for NTMail V5 and V6 allows remote attackers to cause a denial of service via a series of partial HTTP requests.... Read more
Affected Products : ntmail- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2000-0851
Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the "Still Image Service Privilege Escalation" vulnerability.... Read more
Affected Products : windows_2000- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0883
The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.... Read more
Affected Products : mandrake_linux- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0881
The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.... Read more
Affected Products : lpplus- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0860
The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.... Read more
Affected Products : php- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0868
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.... Read more
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0835
search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.... Read more
Affected Products : sambar_server- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0855
SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline.... Read more
Affected Products : xs4all_data_sunftp- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0839
WinCOM LPD 1.00.90 allows remote attackers to cause a denial of service via a large number of LPD options to the LPD port (515).... Read more
Affected Products : wincom_lpd- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0836
Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorization header.... Read more
Affected Products : camshot_webcam- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0844
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.... Read more
Affected Products : debian_linux aix solaris sunos suse_linux linux linux mandrake_linux slackware_linux secure_linux +6 more products- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0848
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.... Read more
Affected Products : websphere_application_server- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025