10
    Critical

    CVE-2000-0941

    Last Modified: 9 Aug 2012

    Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.

    Source:Mark Stratman
    Published:19 Dec 2000
    7.5
    High

    CVE-2000-0937

    Last Modified: 6 Sept 2017

    Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks.

    Source:dodeca-T
    Published:19 Dec 2000
    2.1
    Low

    CVE-2000-0936

    Last Modified: 6 Sept 2017

    Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords.

    Source:miah
    Published:19 Dec 2000
    7.2
    High

    CVE-2000-0935

    Last Modified: 2 Dec 2016

    Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.

    Source:Optyx
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-0930

    Last Modified: 5 Aug 2012

    Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.

    Source:Imran Ghory
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-0929

    Last Modified: 5 Aug 2012

    Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.

    Source:Ussr Labs
    Published:19 Dec 2000
    7.5
    High

    CVE-2000-0926

    Last Modified: 4 Aug 2012

    SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable.

    Source:Delphis Consulting
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-0925

    Last Modified: 5 Aug 2012

    The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.

    Source:DCIST
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-0924

    Last Modified: 6 Aug 2012

    Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catigory" parameter.

    Source:pestilence
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-0922

    Last Modified: 25 Nov 2016

    Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter.

    Source:f0bic
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-0921

    Last Modified: 7 Oct 2017

    Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.

    Source:f0bic
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-0920

    Last Modified: 9 Apr 2015

    Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."

    Source:llmora
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-0919

    Last Modified: 6 Aug 2012

    Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.

    Source:Synnergy.net
    Published:19 Dec 2000
    10
    Critical

    CVE-2000-0917

    Last Modified: 5 Dec 2016

    Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.

    Source:DiGiT
    Published:25 Sept 2000
    7.5
    High

    CVE-2000-0916

    Last Modified: 2 Jul 2012

    FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.

    Source:Stealth & S. Krahmer
    Published:29 Nov 2000
    5
    Medium

    CVE-2000-0914

    Last Modified: 5 Aug 2012

    OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.

    Source:skyper
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-0912

    Last Modified: 24 Oct 2012

    MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter.

    Source:Niels Heinen
    Published:19 Dec 2000
    7.5
    High

    CVE-2000-0909

    Last Modified: 4 Aug 2012

    Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.

    Source:Arkane
    Published:22 Sept 2000
    5
    Medium

    CVE-2000-0908

    Last Modified: 4 Aug 2012

    BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Authorization or Referer MIME headers in the HTTP request.

    Source:Delphis Consulting
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-0906

    Last Modified: 5 Aug 2012

    Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the category or format parameters.

    Source:CDI
    Published:29 Nov 2000
    5
    Medium

    CVE-2000-0904

    Last Modified: 3 Aug 2012

    Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information.

    Source:neonbunny
    Published:29 Nov 2000
    5
    Medium

    CVE-2000-0903

    Last Modified: 3 Aug 2012

    Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

    Source:neonbunny
    Published:29 Nov 2000
    4.6
    Medium

    CVE-2000-0901

    Last Modified: 2 Aug 2012

    Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters in the vbell_msg initialization variable.

    Source:IhaQueR@IRCnet
    Published:5 Sept 2000
    5
    Medium

    CVE-2000-0897

    Last Modified: 10 Aug 2012

    Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is completed.

    Source:403-security team
    Published:9 Jan 2001
    5
    Medium

    CVE-2000-0887

    Last Modified: 8 Sept 2017

    named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the "zxfr bug."

    Source:Fabio Pietrosanti
    Published:7 Nov 2000
    7.5
    High

    CVE-2000-0886

    Last Modified: 9 Aug 2012

    IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.

    Source:Nsfocus
    Published:19 Dec 2000
    7.5
    High

    CVE-2000-0884

    Last Modified: 7 Aug 2012

    IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.

    Source:Gabriel Maggiotti
    Published:19 Dec 2000
    5
    Medium

    CVE-2000-0883

    Last Modified: 3 Aug 2012

    The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.

    Source:anonymous
    Published:14 Nov 2000
    2.1
    Low

    CVE-2000-0881

    Last Modified: 2 Aug 2012

    The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.

    Source:Dixie Flatline
    Published:18 Oct 2000
    3.6
    Low

    CVE-2000-0880

    Last Modified: 2 Aug 2012

    LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file.

    Source:Dixie Flatline
    Published:18 Oct 2000
    2.1
    Low

    CVE-2000-0873

    Last Modified: 3 Aug 2012

    netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.

    Source:alex medvedev
    Published:14 Nov 2000
    5
    Medium

    CVE-2000-0872

    Last Modified: 3 Aug 2012

    explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

    Source:pestilence
    Published:18 Oct 2000
    5
    Medium

    CVE-2000-0869

    Last Modified: 3 Aug 2012

    The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.

    Source:Mnemonix
    Published:14 Nov 2000
    7.2
    High

    CVE-2000-0865

    Last Modified: 4 Aug 2012

    Buffer overflow in dvtermtype in Tridia Double Vision 3.07.00 allows local users to gain root privileges via a long terminal type argument.

    Source:Stephen J. Friedl
    Published:14 Nov 2000
    6.2
    Medium

    CVE-2000-0864

    Last Modified: 15 Nov 2017

    Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileges, via a symlink attack.

    Source:Kris Kennaway
    Published:31 Aug 2000
    10
    Critical

    CVE-2000-0854

    Last Modified: 4 Aug 2012

    When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.

    Source:Georgi Guninski
    Published:14 Nov 2000
    5
    Medium

    CVE-2000-0853

    Last Modified: 3 Aug 2012

    YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

    Source:pestilence
    Published:14 Nov 2000
    4.6
    Medium

    CVE-2000-0851

    Last Modified: 3 Aug 2012

    Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the "Still Image Service Privilege Escalation" vulnerability.

    Source:dildog
    Published:14 Nov 2000
    10
    Critical

    CVE-2000-0848

    Last Modified: 4 Aug 2012

    Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.

    Source:Rude Yak
    Published:14 Nov 2000
    7.5
    High

    CVE-2000-0846

    Last Modified: 1 Aug 2012

    Buffer overflow in Darxite 0.4 and earlier allows a remote attacker to execute arbitrary commands via a long username or password.

    Source:Scrippie
    Published:14 Nov 2000
    10
    Critical

    CVE-2000-0844

    Last Modified: 2 Aug 2012

    Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

    Source:Kil3r of Lam3rZ
    Published:4 Sept 2000
    7.5
    High

    CVE-2000-0836

    Last Modified: 3 Aug 2012

    Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorization header.

    Source:SecuriTeam
    Published:18 Oct 2000
    5
    Medium

    CVE-2000-0835

    Last Modified: 3 Aug 2012

    search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.

    Source:dethy
    Published:18 Oct 2000
    7.5
    High

    CVE-2000-0834

    Last Modified: 31 Mar 2017

    The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability.

    Source:@stake
    Published:14 Nov 2000
    10
    Critical

    CVE-2000-0833

    Last Modified: 3 Aug 2012

    Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command.

    Source:Guido Bakker
    Published:18 Oct 2000
    5
    Medium

    CVE-2000-0830

    Last Modified: 5 Aug 2012

    annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP packet to ports 22701 through 22705.

    Source:Smashstack
    Published:14 Nov 2000
    2.1
    Low

    CVE-2000-0829

    Last Modified: 15 Nov 2017

    The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a denial of service by creating deeply nested directories in /tmp or /var/tmp/.

    Source:zenith parsec
    Published:9 Sept 2000
    10
    Critical

    CVE-2000-0828

    Last Modified: 3 Aug 2012

    Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agent parameter.

    Source:wildcoyote
    Published:18 Oct 2000
    7.2
    High

    CVE-2000-0824

    Last Modified: 29 Aug 2017

    The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.

    Source:Tymm Twillman
    Published:17 Sept 1999
    2.1
    Low

    CVE-2000-0816

    Last Modified: 6 Aug 2012

    Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters.

    Source:X-Force
    Published:6 Oct 2000