CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2000-0816

    Last Modified: 16 Apr 2026

    Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters.

    Published: 6 Oct 2000
    7.2
    High

    CVE-2000-0948

    Last Modified: 16 Apr 2026

    GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.

    Published: 2 Oct 2000
    7.2
    High

    CVE-2000-1207

    Last Modified: 16 Apr 2026

    userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).

    Published: 30 Sept 2000
    5
    Medium

    CVE-2000-0913

    Last Modified: 16 Apr 2026

    mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.

    Published: 29 Sept 2000
    7.2
    High

    CVE-2000-0949

    Last Modified: 16 Apr 2026

    Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.

    Published: 28 Sept 2000
    10
    Critical

    CVE-2000-0917

    Last Modified: 16 Apr 2026

    Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.

    Published: 25 Sept 2000
    7.5
    High

    CVE-2000-0909

    Last Modified: 16 Apr 2026

    Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.

    Published: 22 Sept 2000
    5
    Medium

    CVE-2000-0686

    Last Modified: 16 Apr 2026

    Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.

    Published: 21 Sept 2000
    10
    Critical

    CVE-2000-0687

    Last Modified: 16 Apr 2026

    Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0692

    Last Modified: 16 Apr 2026

    ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.

    Published: 21 Sept 2000
    7.2
    High

    CVE-2000-0695

    Last Modified: 16 Apr 2026

    Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line options.

    Published: 21 Sept 2000
    7.5
    High

    CVE-2000-0696

    Last Modified: 16 Apr 2026

    The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0709

    Last Modified: 16 Apr 2026

    The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0710

    Last Modified: 16 Apr 2026

    The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.

    Published: 21 Sept 2000
    6.2
    Medium

    CVE-2000-0719

    Last Modified: 16 Apr 2026

    VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program.

    Published: 21 Sept 2000
    6.2
    Medium

    CVE-2000-0721

    Last Modified: 16 Apr 2026

    The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0734

    Last Modified: 16 Apr 2026

    eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0735

    Last Modified: 16 Apr 2026

    Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message.

    Published: 21 Sept 2000
    7.2
    High

    CVE-2000-0752

    Last Modified: 16 Apr 2026

    Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.

    Published: 21 Sept 2000
    6.4
    Medium

    CVE-2000-0759

    Last Modified: 16 Apr 2026

    Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.

    Published: 21 Sept 2000
    6.4
    Medium

    CVE-2000-0760

    Last Modified: 16 Apr 2026

    The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.

    Published: 21 Sept 2000
    7.5
    High

    CVE-2000-0769

    Last Modified: 16 Apr 2026

    O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe.

    Published: 21 Sept 2000
    7.5
    High

    CVE-2000-0775

    Last Modified: 16 Apr 2026

    Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or execute arbitrary commands via a long HTTP GET request, or long Unless-Modified-Since, If-Range, or If-Modified-Since headers.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0774

    Last Modified: 16 Apr 2026

    The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root.

    Published: 21 Sept 2000
    10
    Critical

    CVE-2000-0784

    Last Modified: 16 Apr 2026

    sshd program in the Rapidstream 2.1 Beta VPN appliance has a hard-coded "rsadmin" account with a null password, which allows remote attackers to execute arbitrary commands via ssh.

    Published: 21 Sept 2000
    4.6
    Medium

    CVE-2000-0789

    Last Modified: 16 Apr 2026

    WinU 5.x and earlier uses weak encryption to store its configuration password, which allows local users to decrypt the password and gain privileges.

    Published: 21 Sept 2000
    4.6
    Medium

    CVE-2000-0791

    Last Modified: 16 Apr 2026

    Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.

    Published: 21 Sept 2000
    7.2
    High

    CVE-2000-0801

    Last Modified: 16 Apr 2026

    Buffer overflow in bdf program in HP-UX 11.00 may allow local users to gain root privileges via a long -t option.

    Published: 21 Sept 2000
    10
    Critical

    CVE-2000-0690

    Last Modified: 16 Apr 2026

    Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.

    Published: 21 Sept 2000
    1.2
    Low

    CVE-2000-0723

    Last Modified: 16 Apr 2026

    Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config.

    Published: 21 Sept 2000
    6.2
    Medium

    CVE-2000-0724

    Last Modified: 16 Apr 2026

    The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0736

    Last Modified: 16 Apr 2026

    Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message.

    Published: 21 Sept 2000
    4.6
    Medium

    CVE-2000-0748

    Last Modified: 16 Apr 2026

    OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse.

    Published: 21 Sept 2000
    4.6
    Medium

    CVE-2000-0755

    Last Modified: 16 Apr 2026

    Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0756

    Last Modified: 16 Apr 2026

    Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.

    Published: 21 Sept 2000
    7.2
    High

    CVE-2000-0794

    Last Modified: 16 Apr 2026

    Buffer overflow in IRIX libgl.so library allows local users to gain root privileges via a long HOME variable to programs such as (1) gmemusage and (2) gr_osview.

    Published: 21 Sept 2000
    10
    Critical

    CVE-2000-0798

    Last Modified: 16 Apr 2026

    The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete the contents of arbitrary files.

    Published: 21 Sept 2000
    10
    Critical

    CVE-2000-0800

    Last Modified: 16 Apr 2026

    String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.

    Published: 21 Sept 2000
    7.2
    High

    CVE-2000-0680

    Last Modified: 16 Apr 2026

    The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action.

    Published: 21 Sept 2000
    7.5
    High

    CVE-2000-0689

    Last Modified: 16 Apr 2026

    Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0785

    Last Modified: 16 Apr 2026

    WircSrv IRC Server 5.07s allows IRC operators to read arbitrary files via the importmotd command, which sets the Message of the Day (MOTD) to the specified file.

    Published: 21 Sept 2000
    7.5
    High

    CVE-2000-0772

    Last Modified: 16 Apr 2026

    The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account "sa" with no password.

    Published: 21 Sept 2000
    10
    Critical

    CVE-2000-0793

    Last Modified: 16 Apr 2026

    Norton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after the first user has logged off of the system.

    Published: 21 Sept 2000
    3.6
    Low

    CVE-2000-0802

    Last Modified: 16 Apr 2026

    The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain access to the menu by modifying the registry key that starts BAIR.

    Published: 21 Sept 2000
    7.5
    High

    CVE-2000-0746

    Last Modified: 16 Apr 2026

    Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.

    Published: 21 Sept 2000
    7.5
    High

    CVE-2000-0688

    Last Modified: 16 Apr 2026

    Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter.

    Published: 21 Sept 2000
    10
    Critical

    CVE-2000-0697

    Last Modified: 16 Apr 2026

    The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.

    Published: 21 Sept 2000
    10
    Critical

    CVE-2000-0704

    Last Modified: 16 Apr 2026

    Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO commands.

    Published: 21 Sept 2000
    7.6
    High

    CVE-2000-0713

    Last Modified: 16 Apr 2026

    Buffer overflow in Adobe Acrobat 4.05, Reader, Business Tools, and Fill In products that handle PDF files allows attackers to execute arbitrary commands via a long /Registry or /Ordering specifier.

    Published: 21 Sept 2000
    6.2
    Medium

    CVE-2000-0722

    Last Modified: 16 Apr 2026

    Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages.

    Published: 21 Sept 2000