Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0371 1 Kde 1 Kde 2008-09-10 1.2 LOW N/A
The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack.
CVE-2000-0358 1 Redhat 1 Linux 2008-09-10 5.0 MEDIUM N/A
ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.
CVE-2000-0357 1 Redhat 1 Linux 2008-09-10 7.5 HIGH N/A
ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.
CVE-2000-0350 1 Networkice 1 Icecap Manager 2008-09-10 5.0 MEDIUM N/A
A debugging feature in NetworkICE ICEcap 2.0.23 and earlier is enabled, which allows a remote attacker to bypass the weak authentication and post unencrypted events.
CVE-2000-0356 1 Redhat 1 Linux 2008-09-10 4.6 MEDIUM N/A
Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disabled NIS accounts.
CVE-2000-0497 1 Ibm 1 Websphere Application Server 2008-09-10 5.0 MEDIUM N/A
IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
CVE-2000-0476 4 Michael Jennings, Putty, Rxvt and 1 more 4 Eterm, Putty, Rxvt and 1 more 2008-09-10 5.0 MEDIUM N/A
xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized.
CVE-2000-0473 1 Analogx 1 Simpleserver Www 2008-09-10 7.5 HIGH N/A
Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory.
CVE-2000-0469 1 Selena Sol 1 Webbanner 2008-09-10 5.1 MEDIUM N/A
Selena Sol WebBanner 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2000-0468 1 Hp 1 Hp-ux 2008-09-10 4.6 MEDIUM N/A
man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.
CVE-2000-0462 1 Netbsd 1 Netbsd 2008-09-10 2.1 LOW N/A
ftpd in NetBSD 1.4.2 does not properly parse entries in /etc/ftpchroot and does not chroot the specified users, which allows those users to access other files outside of their home directory.
CVE-2000-0461 2 Freebsd, Netbsd 2 Freebsd, Netbsd 2008-09-10 2.1 LOW N/A
The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.
CVE-2000-0460 1 Kde 1 Kde 2008-09-10 7.2 HIGH N/A
Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable.
CVE-2000-0447 1 Network Associates 1 Webshield 2008-09-10 7.5 HIGH N/A
Buffer overflow in WebShield SMTP 4.5.44 allows remote attackers to execute arbitrary commands via a long configuration parameter to the WebShield remote management service.
CVE-2000-0446 1 Marty Bochane 1 Mdbms 2008-09-10 7.5 HIGH N/A
Buffer overflow in MDBMS database server allows remote attackers to execute arbitrary commands via a long string.
CVE-2000-0445 1 Pgp 1 Pgp 2008-09-10 2.1 LOW N/A
The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may produce predictable keys.
CVE-2000-0444 1 Hp 1 Jetadmin 2008-09-10 5.0 MEDIUM N/A
HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000.
CVE-2000-0443 1 Hp 1 Jetadmin 2008-09-10 7.5 HIGH N/A
The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2000-0437 1 Network Associates 3 Gauntlet Firewall, Webshield, Webshield E-ppliance 2008-09-10 10.0 HIGH N/A
Buffer overflow in the CyberPatrol daemon "cyberdaemon" used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute arbitrary commands.
CVE-2000-0436 1 Metaproducts 1 Offline Explorer 2008-09-10 5.0 MEDIUM N/A
MetaProducts Offline Explorer 1.2 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) attack.
CVE-2000-0435 1 Matthew Redman 1 Allmanage 2008-09-10 7.5 HIGH N/A
The allmanageup.pl file upload CGI script in the Allmanage Website administration software 2.6 can be called directly by remote attackers, which allows them to modify user accounts or web pages.
CVE-2000-0434 1 Matthew Redman 1 Allmanage 2008-09-10 7.5 HIGH N/A
The administrative password for the Allmanage web site administration software is stored in plaintext in a file which could be accessed by remote attackers.
CVE-2000-0433 1 Suse 1 Suse Linux 2008-09-10 4.6 MEDIUM N/A
The SuSE aaa_base package installs some system accounts with home directories set to /tmp, which allows local users to gain privileges to those accounts by creating standard user startup scripts such as profiles.
CVE-2000-0432 1 Matt Kruse 1 Calendar Script 2008-09-10 7.5 HIGH N/A
The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters.
CVE-2000-0431 1 Sun 2 Cobalt Raq 2, Cobalt Raq 3i 2008-09-10 7.5 HIGH N/A
Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files.
CVE-2000-0448 1 Network Associates 1 Webshield 2008-09-10 5.0 MEDIUM N/A
The WebShield SMTP Management Tool version 4.5.44 does not properly restrict access to the management port when an IP address does not resolve to a hostname, which allows remote attackers to access the configuration via the GET_CONFIG command.
CVE-2000-0428 1 Trend Micro 1 Interscan Viruswall 2008-09-10 10.0 HIGH N/A
Buffer overflow in the SMTP gateway for InterScan Virus Wall 3.32 and earlier allows a remote attacker to execute arbitrary commands via a long filename for a uuencoded attachment.
CVE-2000-0427 1 Aladdin Knowledge Systems 1 Etoken 2008-09-10 4.6 MEDIUM N/A
The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM.
CVE-2000-0425 1 Lsoft 1 Listserv 2008-09-10 10.0 HIGH N/A
Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.
CVE-2000-0420 1 Microsoft 1 Windows 2000 2008-09-10 7.2 HIGH N/A
The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data.
CVE-2000-0418 1 Cayman 2 3220-h Dsl Router, Gatorsurf 2008-09-10 5.0 MEDIUM N/A
The Cayman 3220-H DSL router allows remote attackers to cause a denial of service via oversized ICMP echo (ping) requests.
CVE-2000-0417 1 Cayman 2 3220-h Dsl Router, Gatorsurf 2008-09-10 5.0 MEDIUM N/A
The HTTP administration interface to the Cayman 3220-H DSL router allows remote attackers to cause a denial of service via a long username or password.
CVE-2000-0416 1 Microsoft 1 Windows 2000 2008-09-10 5.0 MEDIUM N/A
NTMail 5.x allows network users to bypass the NTMail proxy restrictions by redirecting their requests to NTMail's web configuration server.
CVE-2000-0412 1 Napster 1 Knapster 2008-09-10 7.5 HIGH N/A
The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.
CVE-2000-0406 1 Netscape 1 Communicator 2008-09-10 2.6 LOW N/A
Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability.
CVE-2000-0405 1 Atstake 1 Antisniff 2008-09-10 10.0 HIGH N/A
Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.
CVE-2000-0387 1 Alexander Siegel 1 Golddig 2008-09-10 2.1 LOW N/A
The makelev program in the golddig game from the FreeBSD ports collection allows local users to overwrite arbitrary files.
CVE-2000-0386 1 Filemaker 1 Filemaker 2008-09-10 7.5 HIGH N/A
FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email.
CVE-2000-0385 1 Filemaker 1 Filemaker 2008-09-10 5.0 MEDIUM N/A
FileMaker Pro 5 Web Companion allows remote attackers to bypass Field-Level database security restrictions via the XML publishing or email capabilities.
CVE-2000-0383 1 Aol 1 Instant Messenger 2008-09-10 5.0 MEDIUM N/A
The file transfer component of AOL Instant Messenger (AIM) reveals the physical path of the transferred file to the remote recipient.
CVE-2000-0178 1 Foundrynet 1 Serveriron 2008-09-10 7.5 HIGH N/A
ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions.
CVE-2000-0229 4 Alessandro Rubini, Debian, Redhat and 1 more 4 Gpm, Debian Linux, Linux and 1 more 2008-09-10 7.2 HIGH N/A
gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root.
CVE-2000-0179 1 Hp 1 Openview Omniback Ii 2008-09-10 5.0 MEDIUM N/A
HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555.
CVE-2000-0257 1 Novell 1 Netware 2008-09-10 7.5 HIGH N/A
Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long URL.
CVE-2000-0181 1 Checkpoint 1 Firewall-1 2008-09-10 5.0 MEDIUM N/A
Firewall-1 3.0 and 4.0 leaks packets with private IP address information, which could allow remote attackers to determine the real IP address of the host that is making the connection.
CVE-2000-0182 1 Iplanet 1 Iplanet Web Server 2008-09-10 5.0 MEDIUM N/A
iPlanet Web Server 4.1 allows remote attackers to cause a denial of service via a large number of GET commands, which consumes memory and causes a kernel panic.
CVE-2000-0183 1 Michael Sandrof 1 Ircii 2008-09-10 5.1 MEDIUM N/A
Buffer overflow in ircII 4.4 IRC client allows remote attackers to execute commands via the DCC chat capability.
CVE-2000-0184 2 Mandrakesoft, Redhat 2 Mandrake Linux, Linux 2008-09-10 2.1 LOW N/A
Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.
CVE-2000-0196 3 Nmh, Redhat, Turbolinux 3 Nmh, Linux, Turbolinux 2008-09-10 7.5 HIGH N/A
Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message.
CVE-2000-0197 1 Microsoft 1 Windows Nt 2008-09-10 4.6 MEDIUM N/A
The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.