Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0197 1 Microsoft 1 Windows Nt 2008-09-10 4.6 MEDIUM N/A
The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.
CVE-2000-0196 3 Nmh, Redhat, Turbolinux 3 Nmh, Linux, Turbolinux 2008-09-10 7.5 HIGH N/A
Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message.
CVE-2000-0195 1 Corel 1 Linux 2008-09-10 7.2 HIGH N/A
setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverrc file.
CVE-2000-0194 1 Corel 1 Linux 2008-09-10 7.2 HIGH N/A
buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters.
CVE-2000-0145 1 Debian 1 Debian Linux 2008-09-10 7.5 HIGH N/A
The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions.
CVE-2000-0193 1 Corel 1 Linux 2008-09-10 7.2 HIGH N/A
The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain privileges.
CVE-2000-0192 1 Caldera 1 Openlinux 2008-09-10 5.0 MEDIUM N/A
The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are installed on the system.
CVE-2000-0282 1 Talentsoft 1 Web\+ 2008-09-10 5.0 MEDIUM N/A
TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program.
CVE-2000-0191 1 Axis 1 Storpoint Cd 2008-09-10 10.0 HIGH N/A
Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.
CVE-2000-0190 1 Aol 1 Instant Messenger 2008-09-10 5.0 MEDIUM N/A
AOL Instant Messenger (AIM) client allows remote attackers to cause a denial of service via a message with a malformed ASCII value.
CVE-2000-0189 1 Allaire 1 Coldfusion Server 2008-09-10 5.0 MEDIUM N/A
ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.
CVE-2000-0188 1 Alex Heiphetz Group 1 Ezshopper 2008-09-10 7.5 HIGH N/A
EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.
CVE-2000-0187 1 Alex Heiphetz Group 1 Ezshopper 2008-09-10 7.5 HIGH N/A
EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.
CVE-2000-0186 4 Freebsd, Mandrakesoft, Redhat and 1 more 4 Freebsd, Mandrake Linux, Linux and 1 more 2008-09-10 7.2 HIGH N/A
Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.
CVE-2000-0185 1 Realnetworks 2 Realserver, Realserver G2 2008-09-10 5.0 MEDIUM N/A
RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private.
CVE-2000-0184 2 Mandrakesoft, Redhat 2 Mandrake Linux, Linux 2008-09-10 2.1 LOW N/A
Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.
CVE-2000-0183 1 Michael Sandrof 1 Ircii 2008-09-10 5.1 MEDIUM N/A
Buffer overflow in ircII 4.4 IRC client allows remote attackers to execute commands via the DCC chat capability.
CVE-2000-0182 1 Iplanet 1 Iplanet Web Server 2008-09-10 5.0 MEDIUM N/A
iPlanet Web Server 4.1 allows remote attackers to cause a denial of service via a large number of GET commands, which consumes memory and causes a kernel panic.
CVE-2000-0181 1 Checkpoint 1 Firewall-1 2008-09-10 5.0 MEDIUM N/A
Firewall-1 3.0 and 4.0 leaks packets with private IP address information, which could allow remote attackers to determine the real IP address of the host that is making the connection.
CVE-2000-0179 1 Hp 1 Openview Omniback Ii 2008-09-10 5.0 MEDIUM N/A
HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555.
CVE-2000-0178 1 Foundrynet 1 Serveriron 2008-09-10 7.5 HIGH N/A
ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions.
CVE-2000-0177 1 Dnstools Software 1 Dnstools 2008-09-10 10.0 HIGH N/A
DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters.
CVE-2000-0176 1 Cat Soft 1 Serv-u 2008-09-10 5.0 MEDIUM N/A
The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.
CVE-2000-0175 1 Sun 1 Staroffice 2008-09-10 10.0 HIGH N/A
Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.
CVE-2000-0174 1 Sun 1 Staroffice 2008-09-10 5.0 MEDIUM N/A
StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2000-0173 1 Sco 1 Unixware 2008-09-10 5.0 MEDIUM N/A
Vulnerability in the EELS system in SCO UnixWare 7.1.x allows remote attackers to cause a denial of service.
CVE-2000-0172 2 Matt Kimball And Roger Wolff, Turbolinux 2 Mtr, Turbolinux 2008-09-10 7.2 HIGH N/A
The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges.
CVE-2000-0171 1 At Computing 1 Atsar Linux 2008-09-10 7.2 HIGH N/A
atsadc in the atsar package for Linux does not properly check the permissions of an output file, which allows local users to gain root privileges.
CVE-2000-0170 2 Redhat, Turbolinux 2 Linux, Turbolinux 2008-09-10 7.2 HIGH N/A
Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.
CVE-2000-0169 1 Oracle 1 Application Server 2008-09-10 7.5 HIGH N/A
Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'.
CVE-2000-0168 1 Microsoft 3 Windows 95, Windows 98, Windows 98se 2008-09-10 5.0 MEDIUM N/A
Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability.
CVE-2000-0167 1 Microsoft 1 Internet Information Server 2008-09-10 2.1 LOW N/A
IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.
CVE-2000-0164 1 Sun 1 Solaris Isp Server 2008-09-10 7.2 HIGH N/A
The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords.
CVE-2000-0114 1 Microsoft 1 Internet Information Server 2008-09-10 5.0 MEDIUM N/A
Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.
CVE-2000-0079 1 W3c 1 Cern Httpd 2008-09-10 7.5 HIGH N/A
The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.
CVE-2000-0086 1 Netopia 1 Timbuktu Pro 2008-09-10 5.0 MEDIUM N/A
Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.
CVE-2000-0110 1 Baron Consulting Group 1 Websitetool 2008-09-10 7.5 HIGH N/A
The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2000-0109 1 Comstock 1 Multicsp 2008-09-10 10.0 HIGH N/A
The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords.
CVE-2000-0083 1 Hp 1 Hp-ux 2008-09-10 4.6 MEDIUM N/A
HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.
CVE-2000-0085 1 Microsoft 1 Hotmail 2008-09-10 7.5 HIGH N/A
Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.
CVE-2000-0084 1 Globalscape 1 Cuteftp 2008-09-10 5.0 MEDIUM N/A
CuteFTP uses weak encryption to store password information in its tree.dat file.
CVE-1999-1552 1 Ibm 1 Aix 2008-09-10 7.2 HIGH N/A
dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.
CVE-2000-0101 1 Make-a-store 1 Orderpage 2008-09-10 7.5 HIGH N/A
The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2000-0102 1 Salescart 1 Salescart 2008-09-10 7.5 HIGH N/A
The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2000-0103 1 Netsmart 1 Smartcart 2008-09-10 7.5 HIGH N/A
The SmartCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2000-0096 1 Qualcomm 1 Qpopper 2008-09-10 7.2 HIGH N/A
Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command.
CVE-2000-0095 1 Hp 1 Hp-ux 2008-09-10 5.0 MEDIUM N/A
The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier.
CVE-2000-0104 1 Web Express 1 Shoptron 2008-09-10 7.5 HIGH N/A
The Shoptron shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2000-0062 1 Zope 1 Zope 2008-09-10 10.0 HIGH N/A
The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.
CVE-2000-0063 1 Nortel 1 Contivity 2008-09-10 5.0 MEDIUM N/A
cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to read arbitrary files by specifying the filename in a parameter to the script.