10
    Critical

    CVE-2000-1220

    Last Modified: 16 Apr 2026

    The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.

    Source:Vadim Kolontsov
    Published:8 Jan 2000
    10
    Critical

    CVE-2000-1209

    Last Modified: 9 Mar 2011

    The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.

    Source:Metasploit
    Published:10 Aug 2002
    4.6
    Medium

    CVE-2000-1199

    Last Modified: 16 Jul 2012

    PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.

    Source:Robert van der Meulen
    Published:31 Aug 2001
    5.5
    Medium

    CVE-2000-1198

    Last Modified: 16 Jul 2012

    qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.

    Source:Alex Mottram
    Published:31 Aug 2001
    5
    Medium

    CVE-2000-1196

    Last Modified: 31 Aug 2012

    PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.

    Source:\x00\x00
    Published:31 Aug 2001
    5
    Medium

    CVE-2000-1193

    Last Modified: 21 Sept 2012

    Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port.

    Source:Marcelo Magnasco
    Published:31 Aug 2001
    7.5
    High

    CVE-2000-1186

    Last Modified: 16 Apr 2026

    Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a long MIME header.

    Source:proton
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-1181

    Last Modified: 10 Aug 2012

    Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including sensitive information, by accessing the /admin/includes/ URL.

    Source:CORE-SDI
    Published:9 Jan 2001
    4.6
    Medium

    CVE-2000-1180

    Last Modified: 10 Aug 2012

    Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument.

    Source:anonymous
    Published:9 Jan 2001
    5
    Medium

    CVE-2000-1177

    Last Modified: 10 Aug 2012

    bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine the existence of files and user ID's by specifying the target file in the HISTFILE parameter.

    Source:f8 Research Labs
    Published:19 Dec 2000
    7.5
    High

    CVE-2000-1176

    Last Modified: 7 Nov 2017

    Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field.

    Source:rpc
    Published:19 Dec 2000
    7.2
    High

    CVE-2000-1175

    Last Modified: 16 Oct 2017

    Buffer overflow in Koules 1.4 allows local users to execute arbitrary commands via a long command line argument.

    Source:Synnergy.net
    Published:19 Dec 2000
    7.5
    High

    CVE-2000-1174

    Last Modified: 10 Aug 2012

    Multiple buffer overflows in AFS ACL parser for Ethereal 0.8.13 and earlier allows remote attackers to execute arbitrary commands via a packet with a long username.

    Source:mat
    Published:18 Nov 2000
    5
    Medium

    CVE-2000-1173

    Last Modified: 11 Aug 2012

    Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information.

    Source:Joey Maier
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-1171

    Last Modified: 10 Aug 2012

    Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot dot) attack in the "thesection" parameter.

    Source:zorgon
    Published:9 Jan 2001
    5
    Medium

    CVE-2000-1154

    Last Modified: 10 Aug 2012

    RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.

    Source:Vort-fu
    Published:19 Dec 2000
    4.6
    Medium

    CVE-2000-1147

    Last Modified: 13 Aug 2012

    Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a script tag.

    Source:Marc Maiffret
    Published:19 Dec 2000
    2.1
    Low

    CVE-2000-1144

    Last Modified: 6 Sept 2016

    Recourse ManTrap 1.6 sets up a chroot environment to hide the fact that it is running, but the inode number for the resulting "/" file system is higher than normal, which allows attackers to determine that they are in a chroot environment.

    Source:f8labs
    Published:9 Jan 2001
    2.1
    Low

    CVE-2000-1140

    Last Modified: 9 Aug 2012

    Recourse ManTrap 1.6 does not properly hide processes from attackers, which could allow attackers to determine that they are in a honeypot system by comparing the results from kill commands with the process listing in the /proc filesystem.

    Source:f8labs
    Published:9 Jan 2001
    7.2
    High

    CVE-2000-1134

    Last Modified: 16 Nov 2017

    Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.

    Source:t--zen
    Published:28 Oct 2000
    6.4
    Medium

    CVE-2000-1132

    Last Modified: 16 Oct 2017

    DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" variable.

    Source:steeLe
    Published:9 Jan 2001
    5
    Medium

    CVE-2000-1129

    Last Modified: 11 Aug 2012

    McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.

    Source:Jari Helenius
    Published:19 Dec 2000
    3.6
    Low

    CVE-2000-1127

    Last Modified: 9 Aug 2012

    registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable.

    Source:J.A. Gutierrez
    Published:19 Dec 2000
    7.2
    High

    CVE-2000-1125

    Last Modified: 27 Oct 2016

    restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.

    Source:fish
    Published:19 Dec 2000
    7.2
    High

    CVE-2000-1124

    Last Modified: 15 Nov 2017

    Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.

    Source:Last Stage of Delirium
    Published:9 Jan 2001
    7.2
    High

    CVE-2000-1121

    Last Modified: 12 Aug 2012

    Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.

    Source:watercloud
    Published:9 Jan 2001
    7.2
    High

    CVE-2000-1120

    Last Modified: 15 Nov 2017

    Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.

    Source:Last Stage of Delirium
    Published:9 Jan 2001
    4.6
    Medium

    CVE-2000-1119

    Last Modified: 15 Nov 2017

    Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.

    Source:Last Stage of Delirium
    Published:9 Jan 2001
    7.5
    High

    CVE-2000-1116

    Last Modified: 7 Jul 2012

    Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long command.

    Source:Ussr Labs
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-1114

    Last Modified: 10 Aug 2012

    Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".

    Source:Wojciech Woch
    Published:19 Dec 2000
    7.5
    High

    CVE-2000-1113

    Last Modified: 13 Aug 2012

    Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the ".ASX Buffer Overrun" vulnerability.

    Source:@stake
    Published:9 Jan 2001
    4.6
    Medium

    CVE-2000-1112

    Last Modified: 12 Jan 2017

    Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.

    Source:Sandro Gauci
    Published:9 Jan 2001
    5
    Medium

    CVE-2000-1110

    Last Modified: 11 Aug 2012

    document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.

    Source:Chad Kalmes
    Published:19 Dec 2000
    4.3
    Medium

    CVE-2000-1105

    Last Modified: 17 Oct 2017

    The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled.

    Source:Georgi Guninski
    Published:19 Dec 2000
    7.2
    High

    CVE-2000-1103

    Last Modified: 22 Nov 2017

    rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.

    Source:vade79
    Published:19 Dec 2000
    7.5
    High

    CVE-2000-1100

    Last Modified: 12 Aug 2012

    The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request.

    Source:Michael R. Rudel
    Published:19 Dec 2000
    3.7
    Low

    CVE-2000-1096

    Last Modified: 16 Mar 2016

    crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.

    Source:Michal Zalewski
    Published:9 Jan 2001
    7.2
    High

    CVE-2000-1095

    Last Modified: 16 Oct 2017

    modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.

    Source:Michal Zalewski
    Published:12 Nov 2000
    7.5
    High

    CVE-2000-1094

    Last Modified: 14 Aug 2012

    Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" command with a long "src" argument.

    Source:@stake
    Published:9 Jan 2001
    7.5
    High

    CVE-2000-1093

    Last Modified: 14 Aug 2012

    Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.

    Source:Joe Testa
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-1092

    Last Modified: 14 Aug 2012

    loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.

    Source:Nsfocus
    Published:19 Dec 2000
    10
    Critical

    CVE-2000-1089

    Last Modified: 7 Mar 2011

    Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.

    Source:Metasploit
    Published:9 Jan 2001
    4.6
    Medium

    CVE-2000-1085

    Last Modified: 12 Aug 2012

    The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.

    Source:@stake
    Published:19 Dec 2000
    2.1
    Low

    CVE-2000-1083

    Last Modified: 12 Aug 2012

    The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.

    Source:David Litchfield
    Published:19 Dec 2000
    4.6
    Medium

    CVE-2000-1081

    Last Modified: 12 Aug 2012

    The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.

    Source:David Litchfield
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-1078

    Last Modified: 24 Jul 2012

    ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.

    Source:Charles Chear
    Published:29 Nov 2000
    5
    Medium

    CVE-2000-1075

    Last Modified: 8 Aug 2012

    Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.

    Source:CORE-SDI
    Published:11 Dec 2000
    10
    Critical

    CVE-2000-1074

    Last Modified: 22 Nov 2017

    csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.

    Source:@stake
    Published:11 Dec 2000
    7.2
    High

    CVE-2000-1072

    Last Modified: 6 Aug 2012

    iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.

    Source:@stake
    Published:11 Dec 2000
    6.4
    Medium

    CVE-2000-1069

    Last Modified: 15 Nov 2017

    pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by specifying the same value to the entered_password and admin_password parameters.

    Source:keelis
    Published:11 Dec 2000