Search
Total
25555 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2000-1176 | 1 Yabb | 1 Yabb | 2008-09-05 | 7.5 HIGH | N/A |
| Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field. | |||||
| CVE-2000-0893 | 1 Sgi | 1 Irix | 2008-09-05 | 5.0 MEDIUM | N/A |
| The presence of the Distributed GL Daemon (dgld) service on port 5232 on SGI IRIX systems allows remote attackers to identify the target host as an SGI system. | |||||
| CVE-2000-1161 | 1 Adcycle | 1 Adcycle | 2008-09-05 | 7.5 HIGH | N/A |
| The installation of AdCycle banner management system leaves the build.cgi program in a web-accessible directory, which allows remote attackers to execute the program and view passwords or delete databases. | |||||
| CVE-2000-1046 | 1 Lotus | 1 Domino | 2008-09-05 | 10.0 HIGH | N/A |
| Multiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via long (1) "RCPT TO," (2) "SAML FROM," or (3) "SOML FROM" commands. | |||||
| CVE-2000-0998 | 1 Freebsd | 1 Freebsd | 2008-09-05 | 7.2 HIGH | N/A |
| Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function. | |||||
| CVE-2000-0882 | 1 Intel | 4 Express 510t, Express 520t, Express 550f and 1 more | 2008-09-05 | 5.0 MEDIUM | N/A |
| Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash. | |||||
| CVE-2000-1175 | 1 Jan Hubicka | 1 Koules | 2008-09-05 | 7.2 HIGH | N/A |
| Buffer overflow in Koules 1.4 allows local users to execute arbitrary commands via a long command line argument. | |||||
| CVE-2000-1232 | 1 Phorum | 1 Phorum | 2008-09-05 | 5.0 MEDIUM | N/A |
| upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method. | |||||
| CVE-2000-1173 | 1 Microsys | 1 Cyberpatrol | 2008-09-05 | 5.0 MEDIUM | N/A |
| Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information. | |||||
| CVE-2000-1230 | 1 Phorum | 1 Phorum | 2008-09-05 | 5.0 MEDIUM | N/A |
| Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman". | |||||
| CVE-2000-1229 | 1 Phorum | 1 Phorum | 2008-09-05 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3. | |||||
| CVE-2000-0985 | 1 Nevis Systems | 1 All-mail | 2008-09-05 | 10.0 HIGH | N/A |
| Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command. | |||||
| CVE-2000-0976 | 1 Xfree86 Project | 1 Xlib | 2008-09-05 | 4.6 MEDIUM | N/A |
| Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter. | |||||
| CVE-2000-1185 | 1 Itserv Incorporated | 1 Ridewaypn | 2008-09-05 | 5.0 MEDIUM | N/A |
| The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests. | |||||
| CVE-2000-0931 | 1 David Harris | 1 Pegasus Mail | 2008-09-05 | 7.5 HIGH | N/A |
| Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data. | |||||
| CVE-2000-0918 | 1 Kde | 1 Kvt | 2008-09-05 | 7.2 HIGH | N/A |
| Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters. | |||||
| CVE-2000-0916 | 1 Freebsd | 1 Freebsd | 2008-09-05 | 7.5 HIGH | N/A |
| FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections. | |||||
| CVE-2000-1160 | 1 Network Associates | 1 Sniffer Agent | 2008-09-05 | 5.0 MEDIUM | N/A |
| NAI Sniffer Agent allows remote attackers to cause a denial of service (crash) by sending a large number of login requests. | |||||
| CVE-2000-0907 | 1 Etype | 1 Eserv | 2008-09-05 | 7.5 HIGH | N/A |
| EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands. | |||||
| CVE-2000-0905 | 1 Qnx | 1 Voyager | 2008-09-05 | 5.0 MEDIUM | N/A |
| QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page. | |||||
| CVE-2000-1159 | 1 Network Associates | 1 Sniffer Agent | 2008-09-05 | 7.5 HIGH | N/A |
| NAI Sniffer Agent allows remote attackers to gain privileges on the agent by sniffing the initial UDP authentication packets and spoofing commands. | |||||
| CVE-2000-0904 | 1 Qnx | 1 Voyager | 2008-09-05 | 5.0 MEDIUM | N/A |
| Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information. | |||||
| CVE-2000-1158 | 1 Network Associates | 1 Sniffer Agent | 2008-09-05 | 7.5 HIGH | N/A |
| NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords. | |||||
| CVE-2000-0843 | 2 Dave Airlie, Luke Kenneth Casson Leighton | 2 Pam Smb, Pam Ntdom | 2008-09-05 | 10.0 HIGH | N/A |
| Buffer overflow in pam_smb and pam_ntdom pluggable authentication modules (PAM) allow remote attackers to execute arbitrary commands via a login with a long user name. | |||||
| CVE-2000-0856 | 1 Xs4all Data | 1 Xs4all Data Sunftp | 2008-09-05 | 7.5 HIGH | N/A |
| Buffer overflow in SunFTP build 9(1) allows remote attackers to cause a denial of service or possibly execute arbitrary commands via a long GET request. | |||||
| CVE-2000-0842 | 1 Sco | 1 Unixware | 2008-09-05 | 5.0 MEDIUM | N/A |
| The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |||||
| CVE-2000-0845 | 1 Digital | 1 Unix | 2008-09-05 | 6.4 MEDIUM | N/A |
| kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet. | |||||
| CVE-2000-1237 | 1 Floosietek | 1 Ftgate | 2008-09-05 | 5.0 MEDIUM | N/A |
| The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing. | |||||
| CVE-2000-0855 | 1 Xs4all Data | 1 Xs4all Data Sunftp | 2008-09-05 | 5.0 MEDIUM | N/A |
| SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline. | |||||
| CVE-2000-0792 | 1 Alan Cox | 1 Gnome-lokkit | 2008-09-05 | 7.5 HIGH | N/A |
| Gnome Lokkit firewall package before 0.41 does not properly restrict access to some ports, even if a user does not make any services available. | |||||
| CVE-2000-0681 | 1 Bea | 1 Weblogic Server | 2008-09-05 | 10.0 HIGH | N/A |
| Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension. | |||||
| CVE-2000-0682 | 1 Bea | 1 Weblogic Server | 2008-09-05 | 5.0 MEDIUM | N/A |
| BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet. | |||||
| CVE-2000-0741 | 1 Network Associates | 1 Net Tools Pki Server | 2008-09-05 | 7.5 HIGH | N/A |
| Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension. | |||||
| CVE-2000-0724 | 1 Helix Code | 1 Go-gnome Pre-installer | 2008-09-05 | 6.2 MEDIUM | N/A |
| The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files. | |||||
| CVE-2000-0723 | 1 Helix Code | 1 Gnome Installer | 2008-09-05 | 1.2 LOW | N/A |
| Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config. | |||||
| CVE-2000-0683 | 1 Bea | 1 Weblogic Server | 2008-09-05 | 5.0 MEDIUM | N/A |
| BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet. | |||||
| CVE-2000-0795 | 1 Sgi | 1 Irix | 2008-09-05 | 7.2 HIGH | N/A |
| Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long -n option. | |||||
| CVE-2000-0793 | 2 Novell, Symantec | 2 Client, Norton Antivirus | 2008-09-05 | 10.0 HIGH | N/A |
| Norton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after the first user has logged off of the system. | |||||
| CVE-2000-0722 | 1 Helix Code | 1 Gnome Updater | 2008-09-05 | 6.2 MEDIUM | N/A |
| Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages. | |||||
| CVE-2000-0736 | 1 Rimarts Inc. | 1 Becky Internet Mail | 2008-09-05 | 5.0 MEDIUM | N/A |
| Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message. | |||||
| CVE-2000-0801 | 1 Hp | 1 Hp-ux | 2008-09-05 | 7.2 HIGH | N/A |
| Buffer overflow in bdf program in HP-UX 11.00 may allow local users to gain root privileges via a long -t option. | |||||
| CVE-2000-0719 | 1 Varicad | 1 Varicad | 2008-09-05 | 6.2 MEDIUM | N/A |
| VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program. | |||||
| CVE-2000-0657 | 1 Analogx | 1 Proxy | 2008-09-05 | 5.0 MEDIUM | N/A |
| Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long HELO command in the SMTP protocol. | |||||
| CVE-2000-0563 | 1 Apple | 1 Mac Os Runtime For Java | 2008-09-05 | 10.0 HIGH | N/A |
| The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model. | |||||
| CVE-2000-0798 | 1 Sgi | 1 Irix | 2008-09-05 | 10.0 HIGH | N/A |
| The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete the contents of arbitrary files. | |||||
| CVE-2000-0775 | 1 Robtex | 1 Viking Server | 2008-09-05 | 7.5 HIGH | N/A |
| Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or execute arbitrary commands via a long HTTP GET request, or long Unless-Modified-Since, If-Range, or If-Modified-Since headers. | |||||
| CVE-2000-0712 | 1 Lids | 1 Lids | 2008-09-05 | 7.2 HIGH | N/A |
| Linux Intrusion Detection System (LIDS) 0.9.7 allows local users to gain root privileges when LIDS is disabled via the security=0 boot option. | |||||
| CVE-2000-0774 | 1 Bajie | 1 Java Http Server | 2008-09-05 | 5.0 MEDIUM | N/A |
| The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root. | |||||
| CVE-2000-0831 | 1 Fastream | 1 Ftp\+\+ Server | 2008-09-05 | 7.5 HIGH | N/A |
| Buffer overflow in Fastream FTP++ 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long username. | |||||
| CVE-2000-0760 | 1 Apache | 1 Tomcat | 2008-09-05 | 6.4 MEDIUM | N/A |
| The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension. | |||||
