CVE Feed

    Dashboard / CVE

    9
    Critical

    CVE-2000-1242

    Last Modified: 16 Apr 2026

    The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access.

    Published: 31 Dec 2000
    5
    Medium

    CVE-2000-1243

    Last Modified: 16 Apr 2026

    Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product developers.

    Published: 31 Dec 2000
    5
    Medium

    CVE-2000-1240

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive information via unknown attack vectors, which reveal the absolute path. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 31 Dec 2000
    5
    Medium

    CVE-2000-1228

    Last Modified: 16 Apr 2026

    Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.

    Published: 31 Dec 2000
    7.5
    High

    CVE-2000-1233

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the sSQL parameter.

    Published: 31 Dec 2000
    5
    Medium

    CVE-2000-1226

    Last Modified: 16 Apr 2026

    Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan.

    Published: 31 Dec 2000
    9
    Critical

    CVE-2000-1239

    Last Modified: 16 Apr 2026

    The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data files via an unspecified manipulation of log files.

    Published: 31 Dec 2000
    5
    Medium

    CVE-2000-1227

    Last Modified: 16 Apr 2026

    Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.

    Published: 31 Dec 2000
    5
    Medium

    CVE-2000-1230

    Last Modified: 16 Apr 2026

    Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".

    Published: 31 Dec 2000
    5
    Medium

    CVE-2000-1234

    Last Modified: 16 Apr 2026

    violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters.

    Published: 31 Dec 2000
    5
    Medium

    CVE-2000-1235

    Last Modified: 16 Apr 2026

    The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.

    Published: 31 Dec 2000
    7.5
    High

    CVE-2000-1244

    Last Modified: 16 Apr 2026

    Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the "From" field, which allows remote attackers to bypass virus protection.

    Published: 31 Dec 2000
    5
    Medium

    CVE-2000-1229

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.

    Published: 31 Dec 2000
    5
    Medium

    CVE-2000-1237

    Last Modified: 16 Apr 2026

    The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing.

    Published: 31 Dec 2000
    7.5
    High

    CVE-2000-1238

    Last Modified: 16 Apr 2026

    BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.

    Published: 31 Dec 2000
    7.5
    High

    CVE-2000-1236

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.

    Published: 31 Dec 2000
    10
    Critical

    CVE-2001-0101

    Last Modified: 16 Apr 2026

    Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.

    Published: 27 Dec 2000
    7.5
    High

    CVE-2000-1116

    Last Modified: 16 Apr 2026

    Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long command.

    Published: 19 Dec 2000
    10
    Critical

    CVE-2000-1126

    Last Modified: 16 Apr 2026

    Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service.

    Published: 19 Dec 2000
    4.6
    Medium

    CVE-2000-1128

    Last Modified: 16 Apr 2026

    The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:\Program Files directory.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-1129

    Last Modified: 16 Apr 2026

    McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-1133

    Last Modified: 16 Apr 2026

    Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory.

    Published: 19 Dec 2000
    3.6
    Low

    CVE-2000-1156

    Last Modified: 16 Apr 2026

    StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-1173

    Last Modified: 16 Apr 2026

    Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information.

    Published: 19 Dec 2000
    7.5
    High

    CVE-2000-0886

    Last Modified: 16 Apr 2026

    IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.

    Published: 19 Dec 2000
    10
    Critical

    CVE-2000-0945

    Last Modified: 16 Apr 2026

    The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0960

    Last Modified: 16 Apr 2026

    The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.

    Published: 19 Dec 2000
    10
    Critical

    CVE-2000-0968

    Last Modified: 16 Apr 2026

    Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.

    Published: 19 Dec 2000
    7.2
    High

    CVE-2000-0981

    Last Modified: 16 Apr 2026

    MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.

    Published: 19 Dec 2000
    7.5
    High

    CVE-2000-0810

    Last Modified: 16 Apr 2026

    Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.

    Published: 19 Dec 2000
    10
    Critical

    CVE-2000-0818

    Last Modified: 16 Apr 2026

    The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0899

    Last Modified: 16 Apr 2026

    Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests.

    Published: 19 Dec 2000
    7.5
    High

    CVE-2000-0900

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0898

    Last Modified: 16 Apr 2026

    Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file.

    Published: 19 Dec 2000
    4.6
    Medium

    CVE-2000-0910

    Last Modified: 16 Apr 2026

    Horde library 1.02 allows attackers to execute arbitrary commands via shell metacharacters in the "from" address.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0911

    Last Modified: 16 Apr 2026

    IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0912

    Last Modified: 16 Apr 2026

    MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0919

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0920

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0921

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0915

    Last Modified: 16 Apr 2026

    fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0930

    Last Modified: 16 Apr 2026

    Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.

    Published: 19 Dec 2000
    7.2
    High

    CVE-2000-0935

    Last Modified: 16 Apr 2026

    Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0929

    Last Modified: 16 Apr 2026

    Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.

    Published: 19 Dec 2000
    10
    Critical

    CVE-2000-0941

    Last Modified: 16 Apr 2026

    Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.

    Published: 19 Dec 2000
    5.1
    Medium

    CVE-2000-0942

    Last Modified: 16 Apr 2026

    The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.

    Published: 19 Dec 2000
    7.5
    High

    CVE-2000-0943

    Last Modified: 16 Apr 2026

    Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0938

    Last Modified: 16 Apr 2026

    Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0951

    Last Modified: 16 Apr 2026

    A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.

    Published: 19 Dec 2000
    5
    Medium

    CVE-2000-0953

    Last Modified: 16 Apr 2026

    Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection.

    Published: 19 Dec 2000