CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2000-0771

    Last Modified: 16 Apr 2026

    Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.

    Published: 13 Oct 2000
    4.6
    Medium

    CVE-2000-0786

    Last Modified: 16 Apr 2026

    GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access restrictions.

    Published: 13 Oct 2000
    5
    Medium

    CVE-2000-0678

    Last Modified: 16 Apr 2026

    PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate.

    Published: 13 Oct 2000
    2.1
    Low

    CVE-2000-0754

    Last Modified: 16 Apr 2026

    Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.

    Published: 13 Oct 2000
    5.1
    Medium

    CVE-2000-0765

    Last Modified: 16 Apr 2026

    Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.

    Published: 13 Oct 2000
    2.6
    Low

    CVE-2000-0768

    Last Modified: 16 Apr 2026

    A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.

    Published: 13 Oct 2000
    10
    Critical

    CVE-2000-0973

    Last Modified: 16 Apr 2026

    Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.

    Published: 13 Oct 2000
    10
    Critical

    CVE-2000-0967

    Last Modified: 16 Apr 2026

    PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.

    Published: 12 Oct 2000
    7.5
    High

    CVE-2000-0974

    Last Modified: 16 Apr 2026

    GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.

    Published: 11 Oct 2000
    7.2
    High

    CVE-2000-0963

    Last Modified: 16 Apr 2026

    Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.

    Published: 9 Oct 2000
    2.1
    Low

    CVE-2000-0816

    Last Modified: 16 Apr 2026

    Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters.

    Published: 6 Oct 2000
    7.2
    High

    CVE-2000-0948

    Last Modified: 16 Apr 2026

    GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.

    Published: 2 Oct 2000
    7.2
    High

    CVE-2000-1207

    Last Modified: 16 Apr 2026

    userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).

    Published: 30 Sept 2000
    5
    Medium

    CVE-2000-0913

    Last Modified: 16 Apr 2026

    mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.

    Published: 29 Sept 2000
    7.2
    High

    CVE-2000-0949

    Last Modified: 16 Apr 2026

    Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.

    Published: 28 Sept 2000
    10
    Critical

    CVE-2000-0917

    Last Modified: 16 Apr 2026

    Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.

    Published: 25 Sept 2000
    7.5
    High

    CVE-2000-0909

    Last Modified: 16 Apr 2026

    Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.

    Published: 22 Sept 2000
    5
    Medium

    CVE-2000-0686

    Last Modified: 16 Apr 2026

    Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.

    Published: 21 Sept 2000
    10
    Critical

    CVE-2000-0687

    Last Modified: 16 Apr 2026

    Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0692

    Last Modified: 16 Apr 2026

    ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.

    Published: 21 Sept 2000
    7.2
    High

    CVE-2000-0695

    Last Modified: 16 Apr 2026

    Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line options.

    Published: 21 Sept 2000
    7.5
    High

    CVE-2000-0696

    Last Modified: 16 Apr 2026

    The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0709

    Last Modified: 16 Apr 2026

    The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0710

    Last Modified: 16 Apr 2026

    The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.

    Published: 21 Sept 2000
    6.2
    Medium

    CVE-2000-0719

    Last Modified: 16 Apr 2026

    VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program.

    Published: 21 Sept 2000
    6.2
    Medium

    CVE-2000-0721

    Last Modified: 16 Apr 2026

    The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0734

    Last Modified: 16 Apr 2026

    eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0735

    Last Modified: 16 Apr 2026

    Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message.

    Published: 21 Sept 2000
    7.2
    High

    CVE-2000-0752

    Last Modified: 16 Apr 2026

    Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.

    Published: 21 Sept 2000
    6.4
    Medium

    CVE-2000-0759

    Last Modified: 16 Apr 2026

    Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.

    Published: 21 Sept 2000
    6.4
    Medium

    CVE-2000-0760

    Last Modified: 16 Apr 2026

    The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.

    Published: 21 Sept 2000
    7.5
    High

    CVE-2000-0769

    Last Modified: 16 Apr 2026

    O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe.

    Published: 21 Sept 2000
    7.5
    High

    CVE-2000-0775

    Last Modified: 16 Apr 2026

    Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or execute arbitrary commands via a long HTTP GET request, or long Unless-Modified-Since, If-Range, or If-Modified-Since headers.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0774

    Last Modified: 16 Apr 2026

    The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root.

    Published: 21 Sept 2000
    10
    Critical

    CVE-2000-0784

    Last Modified: 16 Apr 2026

    sshd program in the Rapidstream 2.1 Beta VPN appliance has a hard-coded "rsadmin" account with a null password, which allows remote attackers to execute arbitrary commands via ssh.

    Published: 21 Sept 2000
    4.6
    Medium

    CVE-2000-0789

    Last Modified: 16 Apr 2026

    WinU 5.x and earlier uses weak encryption to store its configuration password, which allows local users to decrypt the password and gain privileges.

    Published: 21 Sept 2000
    4.6
    Medium

    CVE-2000-0791

    Last Modified: 16 Apr 2026

    Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.

    Published: 21 Sept 2000
    7.2
    High

    CVE-2000-0801

    Last Modified: 16 Apr 2026

    Buffer overflow in bdf program in HP-UX 11.00 may allow local users to gain root privileges via a long -t option.

    Published: 21 Sept 2000
    10
    Critical

    CVE-2000-0690

    Last Modified: 16 Apr 2026

    Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.

    Published: 21 Sept 2000
    1.2
    Low

    CVE-2000-0723

    Last Modified: 16 Apr 2026

    Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config.

    Published: 21 Sept 2000
    6.2
    Medium

    CVE-2000-0724

    Last Modified: 16 Apr 2026

    The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0736

    Last Modified: 16 Apr 2026

    Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message.

    Published: 21 Sept 2000
    4.6
    Medium

    CVE-2000-0748

    Last Modified: 16 Apr 2026

    OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse.

    Published: 21 Sept 2000
    4.6
    Medium

    CVE-2000-0755

    Last Modified: 16 Apr 2026

    Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.

    Published: 21 Sept 2000
    5
    Medium

    CVE-2000-0756

    Last Modified: 16 Apr 2026

    Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.

    Published: 21 Sept 2000
    7.2
    High

    CVE-2000-0794

    Last Modified: 16 Apr 2026

    Buffer overflow in IRIX libgl.so library allows local users to gain root privileges via a long HOME variable to programs such as (1) gmemusage and (2) gr_osview.

    Published: 21 Sept 2000
    10
    Critical

    CVE-2000-0798

    Last Modified: 16 Apr 2026

    The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete the contents of arbitrary files.

    Published: 21 Sept 2000
    10
    Critical

    CVE-2000-0800

    Last Modified: 16 Apr 2026

    String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.

    Published: 21 Sept 2000
    7.2
    High

    CVE-2000-0680

    Last Modified: 16 Apr 2026

    The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action.

    Published: 21 Sept 2000
    7.5
    High

    CVE-2000-0689

    Last Modified: 16 Apr 2026

    Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter.

    Published: 21 Sept 2000