CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2000-1060

    Last Modified: 16 Apr 2026

    The default configuration of XFCE 3.5.1 bypasses the Xauthority access control mechanism with an "xhost + localhost" command in the xinitrc program, which allows local users to sniff X Windows traffic and gain privileges.

    Published: 11 Dec 2000
    5.1
    Medium

    CVE-2000-1061

    Last Modified: 16 Apr 2026

    Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX controls, which allows a remote attacker to bypass Internet Explorer's security settings and execute arbitrary commands via a malicious web page or email, aka the "Microsoft VM ActiveX Component" vulnerability.

    Published: 11 Dec 2000
    10
    Critical

    CVE-2000-1068

    Last Modified: 16 Apr 2026

    pollit.cgi in Poll It 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the poll_options parameter.

    Published: 11 Dec 2000
    5
    Medium

    CVE-2000-1032

    Last Modified: 16 Apr 2026

    The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall.

    Published: 11 Dec 2000
    6.4
    Medium

    CVE-2000-1069

    Last Modified: 16 Apr 2026

    pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by specifying the same value to the entered_password and admin_password parameters.

    Published: 11 Dec 2000
    5
    Medium

    CVE-2000-1049

    Last Modified: 16 Apr 2026

    Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of "." characters.

    Published: 11 Dec 2000
    5
    Medium

    CVE-2000-1058

    Last Modified: 16 Apr 2026

    Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, in the SNMP service (snmp.exe), aka the "Java SNMP MIB Browser Object ID parsing problem."

    Published: 11 Dec 2000
    5
    Medium

    CVE-2001-0026

    Last Modified: 16 Apr 2026

    rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option.

    Published: 11 Dec 2000
    7.2
    High

    CVE-2000-1222

    Last Modified: 16 Apr 2026

    AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.

    Published: 10 Dec 2000
    1.2
    Low

    CVE-2001-0036

    Last Modified: 16 Apr 2026

    KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.

    Published: 8 Dec 2000
    10
    Critical

    CVE-2001-0050

    Last Modified: 16 Apr 2026

    Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address that resolves to a long DNS hostname or domain name.

    Published: 7 Dec 2000
    7.2
    High

    CVE-2000-1189

    Last Modified: 16 Apr 2026

    Buffer overflow in pam_localuser PAM module in Red Hat Linux 7.x and 6.x allows attackers to gain privileges.

    Published: 1 Dec 2000
    7.5
    High

    CVE-2000-1023

    Last Modified: 16 Apr 2026

    The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name information via the nsManager.cgi CGI program.

    Published: 29 Nov 2000
    7.5
    High

    CVE-2000-0817

    Last Modified: 16 Apr 2026

    Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability.

    Published: 29 Nov 2000
    7.5
    High

    CVE-2000-0885

    Last Modified: 16 Apr 2026

    Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates.

    Published: 29 Nov 2000
    5
    Medium

    CVE-2000-0902

    Last Modified: 16 Apr 2026

    getalbum.php in PhotoAlbum before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

    Published: 29 Nov 2000
    5
    Medium

    CVE-2000-0903

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

    Published: 29 Nov 2000
    7.2
    High

    CVE-2000-0918

    Last Modified: 16 Apr 2026

    Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.

    Published: 29 Nov 2000
    7.5
    High

    CVE-2000-0916

    Last Modified: 16 Apr 2026

    FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.

    Published: 29 Nov 2000
    6.4
    Medium

    CVE-2000-0940

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.

    Published: 29 Nov 2000
    5
    Medium

    CVE-2000-0939

    Last Modified: 16 Apr 2026

    Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart.

    Published: 29 Nov 2000
    7.2
    High

    CVE-2000-0950

    Last Modified: 16 Apr 2026

    Format string vulnerability in x-gw in TIS Firewall Toolkit (FWTK) allows local users to execute arbitrary commands via a malformed display name.

    Published: 29 Nov 2000
    7.5
    High

    CVE-2000-0955

    Last Modified: 16 Apr 2026

    Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.

    Published: 29 Nov 2000
    10
    Critical

    CVE-2000-0985

    Last Modified: 16 Apr 2026

    Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command.

    Published: 29 Nov 2000
    4.6
    Medium

    CVE-2000-0986

    Last Modified: 16 Apr 2026

    Buffer overflow in Oracle 8.1.5 applications such as names, namesctl, onrsd, osslogin, tnslsnr, tnsping, trcasst, and trcroute possibly allow local users to gain privileges via a long ORACLE_HOME environmental variable.

    Published: 29 Nov 2000
    4.6
    Medium

    CVE-2000-0987

    Last Modified: 16 Apr 2026

    Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.

    Published: 29 Nov 2000
    7.2
    High

    CVE-2000-0988

    Last Modified: 16 Apr 2026

    WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access to its administrative interface and modify configuration.

    Published: 29 Nov 2000
    10
    Critical

    CVE-2000-0999

    Last Modified: 16 Apr 2026

    Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges.

    Published: 29 Nov 2000
    7.2
    High

    CVE-2000-1012

    Last Modified: 16 Apr 2026

    The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.

    Published: 29 Nov 2000
    7.2
    High

    CVE-2000-1013

    Last Modified: 16 Apr 2026

    The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.

    Published: 29 Nov 2000
    7.5
    High

    CVE-2000-1020

    Last Modified: 16 Apr 2026

    Heap overflow in Worldclient in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.

    Published: 29 Nov 2000
    7.5
    High

    CVE-2000-1021

    Last Modified: 16 Apr 2026

    Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.

    Published: 29 Nov 2000
    5
    Medium

    CVE-2000-1017

    Last Modified: 16 Apr 2026

    Webteachers Webdata allows remote attackers with valid Webdata accounts to read arbitrary files by posting a request to import the file into the WebData database.

    Published: 29 Nov 2000
    7.2
    High

    CVE-2000-1028

    Last Modified: 16 Apr 2026

    Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.

    Published: 29 Nov 2000
    10
    Critical

    CVE-2000-1029

    Last Modified: 16 Apr 2026

    Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query.

    Published: 29 Nov 2000
    5
    Medium

    CVE-2000-1030

    Last Modified: 16 Apr 2026

    CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.

    Published: 29 Nov 2000
    7.5
    High

    CVE-2000-1037

    Last Modified: 16 Apr 2026

    Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack.

    Published: 29 Nov 2000
    10
    Critical

    CVE-2000-1035

    Last Modified: 16 Apr 2026

    Buffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER, PASS, or CWD command.

    Published: 29 Nov 2000
    10
    Critical

    CVE-2000-1046

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via long (1) "RCPT TO," (2) "SAML FROM," or (3) "SOML FROM" commands.

    Published: 29 Nov 2000
    5
    Medium

    CVE-2000-1048

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GET request that uses encoded characters in the URL.

    Published: 29 Nov 2000
    5
    Medium

    CVE-2000-1052

    Last Modified: 16 Apr 2026

    Allaire JRun 2.3 server allows remote attackers to obtain source code for executable content by directly calling the SSIFilter servlet.

    Published: 29 Nov 2000
    5
    Medium

    CVE-2000-1063

    Last Modified: 16 Apr 2026

    Buffer overflow in the Telnet service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.

    Published: 29 Nov 2000
    5
    Medium

    CVE-2000-1064

    Last Modified: 16 Apr 2026

    Buffer overflow in the LPD service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.

    Published: 29 Nov 2000
    5
    Medium

    CVE-2000-1066

    Last Modified: 16 Apr 2026

    The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname.

    Published: 29 Nov 2000
    5
    Medium

    CVE-2000-0906

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the category or format parameters.

    Published: 29 Nov 2000
    7.5
    High

    CVE-2000-0907

    Last Modified: 16 Apr 2026

    EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands.

    Published: 29 Nov 2000
    7.5
    High

    CVE-2000-0931

    Last Modified: 16 Apr 2026

    Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data.

    Published: 29 Nov 2000
    5
    Medium

    CVE-2000-0905

    Last Modified: 16 Apr 2026

    QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page.

    Published: 29 Nov 2000
    7.2
    High

    CVE-2000-0998

    Last Modified: 16 Apr 2026

    Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function.

    Published: 29 Nov 2000
    7.5
    High

    CVE-2000-1015

    Last Modified: 16 Apr 2026

    The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode privileges and possibly execute arbitrary commands.

    Published: 29 Nov 2000