CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2000-0749

    Last Modified: 16 Apr 2026

    Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system.

    Published: 20 Oct 2000
    7.5
    High

    CVE-2000-0766

    Last Modified: 16 Apr 2026

    Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileges via a long HTTP GET request.

    Published: 20 Oct 2000
    5
    Medium

    CVE-2000-0773

    Last Modified: 16 Apr 2026

    Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack.

    Published: 20 Oct 2000
    10
    Critical

    CVE-2000-0788

    Last Modified: 16 Apr 2026

    The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.

    Published: 20 Oct 2000
    4.6
    Medium

    CVE-2000-0790

    Last Modified: 16 Apr 2026

    The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option for the first file that is listed in the folder.

    Published: 20 Oct 2000
    5
    Medium

    CVE-2000-0742

    Last Modified: 16 Apr 2026

    The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability.

    Published: 20 Oct 2000
    10
    Critical

    CVE-2000-0747

    Last Modified: 16 Apr 2026

    The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.

    Published: 20 Oct 2000
    10
    Critical

    CVE-2000-0762

    Last Modified: 16 Apr 2026

    The default installation of eTrust Access Control (formerly SeOS) uses a default encryption key, which allows remote attackers to spoof the eTrust administrator and gain privileges.

    Published: 20 Oct 2000
    5
    Medium

    CVE-2000-0764

    Last Modified: 16 Apr 2026

    Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed IP packet.

    Published: 20 Oct 2000
    7.5
    High

    CVE-2000-0776

    Last Modified: 16 Apr 2026

    Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request.

    Published: 20 Oct 2000
    5
    Medium

    CVE-2000-0698

    Last Modified: 16 Apr 2026

    Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via a symlink attack.

    Published: 20 Oct 2000
    10
    Critical

    CVE-2000-0699

    Last Modified: 16 Apr 2026

    Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strings in the PASS command.

    Published: 20 Oct 2000
    2.1
    Low

    CVE-2000-0729

    Last Modified: 16 Apr 2026

    FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.

    Published: 20 Oct 2000
    2.1
    Low

    CVE-2000-0679

    Last Modified: 16 Apr 2026

    The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files.

    Published: 20 Oct 2000
    10
    Critical

    CVE-2000-0828

    Last Modified: 16 Apr 2026

    Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agent parameter.

    Published: 18 Oct 2000
    5
    Medium

    CVE-2000-0832

    Last Modified: 16 Apr 2026

    Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter.

    Published: 18 Oct 2000
    10
    Critical

    CVE-2000-0833

    Last Modified: 16 Apr 2026

    Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command.

    Published: 18 Oct 2000
    10
    Critical

    CVE-2000-0827

    Last Modified: 16 Apr 2026

    Buffer overflow in the web authorization form of Mobius DocumentDirect for the Internet 1.2 allows remote attackers to cause a denial of service or execute arbitrary commands via a long username.

    Published: 18 Oct 2000
    10
    Critical

    CVE-2000-0840

    Last Modified: 16 Apr 2026

    Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long USER command.

    Published: 18 Oct 2000
    10
    Critical

    CVE-2000-0841

    Last Modified: 16 Apr 2026

    Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long APOP command.

    Published: 18 Oct 2000
    5
    Medium

    CVE-2000-0842

    Last Modified: 16 Apr 2026

    The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.

    Published: 18 Oct 2000
    6.4
    Medium

    CVE-2000-0845

    Last Modified: 16 Apr 2026

    kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.

    Published: 18 Oct 2000
    5
    Medium

    CVE-2000-0855

    Last Modified: 16 Apr 2026

    SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline.

    Published: 18 Oct 2000
    7.5
    High

    CVE-2000-0857

    Last Modified: 16 Apr 2026

    The logging capability in muh 2.05d IRC server does not properly cleanse user-injected format strings, which allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed nickname.

    Published: 18 Oct 2000
    2.1
    Low

    CVE-2000-0866

    Last Modified: 16 Apr 2026

    Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes.

    Published: 18 Oct 2000
    5
    Medium

    CVE-2000-0882

    Last Modified: 16 Apr 2026

    Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash.

    Published: 18 Oct 2000
    10
    Critical

    CVE-2000-0812

    Last Modified: 16 Apr 2026

    The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.

    Published: 18 Oct 2000
    10
    Critical

    CVE-2000-0826

    Last Modified: 16 Apr 2026

    Buffer overflow in ddicgi.exe program in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long GET request.

    Published: 18 Oct 2000
    5
    Medium

    CVE-2000-0835

    Last Modified: 16 Apr 2026

    search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.

    Published: 18 Oct 2000
    7.5
    High

    CVE-2000-0836

    Last Modified: 16 Apr 2026

    Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorization header.

    Published: 18 Oct 2000
    10
    Critical

    CVE-2000-0843

    Last Modified: 16 Apr 2026

    Buffer overflow in pam_smb and pam_ntdom pluggable authentication modules (PAM) allow remote attackers to execute arbitrary commands via a login with a long user name.

    Published: 18 Oct 2000
    5
    Medium

    CVE-2000-0872

    Last Modified: 16 Apr 2026

    explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

    Published: 18 Oct 2000
    2.1
    Low

    CVE-2000-0879

    Last Modified: 16 Apr 2026

    LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.

    Published: 18 Oct 2000
    3.6
    Low

    CVE-2000-0880

    Last Modified: 16 Apr 2026

    LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file.

    Published: 18 Oct 2000
    2.1
    Low

    CVE-2000-0881

    Last Modified: 16 Apr 2026

    The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.

    Published: 18 Oct 2000
    7.5
    High

    CVE-2000-0831

    Last Modified: 16 Apr 2026

    Buffer overflow in Fastream FTP++ 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long username.

    Published: 18 Oct 2000
    10
    Critical

    CVE-2000-1040

    Last Modified: 16 Apr 2026

    Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service.

    Published: 18 Oct 2000
    7.5
    High

    CVE-2000-1213

    Last Modified: 16 Apr 2026

    ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping's exposure to bugs that otherwise would occur at lower privileges.

    Published: 18 Oct 2000
    4.6
    Medium

    CVE-2000-1214

    Last Modified: 16 Apr 2026

    Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, may allow local users to gain privileges.

    Published: 18 Oct 2000
    5
    Medium

    CVE-1999-1563

    Last Modified: 16 Apr 2026

    Nachuatec D435 and D445 printer allows remote attackers to cause a denial of service via ICMP redirect storm.

    Published: 14 Oct 2000
    6.4
    Medium

    CVE-2000-0770

    Last Modified: 16 Apr 2026

    IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability.

    Published: 13 Oct 2000
    5
    Medium

    CVE-2000-0761

    Last Modified: 16 Apr 2026

    OS2/Warp 4.5 FTP server allows remote attackers to cause a denial of service via a long username.

    Published: 13 Oct 2000
    10
    Critical

    CVE-2000-0677

    Last Modified: 16 Apr 2026

    Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to execute arbitrary commands via a long PATH_INFO environmental variable.

    Published: 13 Oct 2000
    5
    Medium

    CVE-2000-0683

    Last Modified: 16 Apr 2026

    BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet.

    Published: 13 Oct 2000
    10
    Critical

    CVE-2000-0684

    Last Modified: 16 Apr 2026

    BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.

    Published: 13 Oct 2000
    5
    Medium

    CVE-2000-0708

    Last Modified: 16 Apr 2026

    Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via a long series of null characters to the rexec port.

    Published: 13 Oct 2000
    7.5
    High

    CVE-2000-0711

    Last Modified: 16 Apr 2026

    Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.

    Published: 13 Oct 2000
    7.2
    High

    CVE-2000-0712

    Last Modified: 16 Apr 2026

    Linux Intrusion Detection System (LIDS) 0.9.7 allows local users to gain root privileges when LIDS is disabled via the security=0 boot option.

    Published: 13 Oct 2000
    7.5
    High

    CVE-2000-0707

    Last Modified: 16 Apr 2026

    PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allows remote attackers to obtain sensitive information such as the administrative password.

    Published: 13 Oct 2000
    1.2
    Low

    CVE-2000-0718

    Last Modified: 16 Apr 2026

    A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed.

    Published: 13 Oct 2000