7.5
    High

    CVE-2000-0342

    Last Modified: 16 Jul 2012

    Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."

    Source:Bennett Haselton
    Published:28 Apr 2000
    5
    Medium

    CVE-2000-0341

    Last Modified: 16 Jul 2012

    ATRIUM Cassandra NNTP Server 1.10 allows remote attackers to cause a denial of service via a long login name.

    Source:Ussr Labs
    Published:1 May 2000
    7.2
    High

    CVE-2000-0340

    Last Modified: 16 Jul 2012

    Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environmental variable.

    Source:bladi
    Published:29 Apr 2000
    7.5
    High

    CVE-2000-0339

    Last Modified: 16 Jul 2012

    ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.

    Source:Wally Whacker
    Published:24 Apr 2000
    5.5
    Medium

    CVE-2000-0338

    Last Modified: 16 Jul 2012

    Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.

    Source:Michal Szymanski
    Published:23 Apr 2000
    7.2
    High

    CVE-2000-0337

    Last Modified: 16 Jul 2012

    Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.

    Source:DiGiT
    Published:24 Apr 2000
    2.1
    Low

    CVE-2000-0336

    Last Modified: 19 Jul 2012

    Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.

    Source:anonymous
    Published:13 Apr 2000
    5
    Medium

    CVE-2000-0333

    Last Modified: 17 Jul 2012

    tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet.

    Source:Hugo Breton
    Published:31 May 1999
    5
    Medium

    CVE-2000-0332

    Last Modified: 17 Jul 2012

    UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a dot dot (..) and ends with a null byte.

    Source:Rudi Carell
    Published:3 May 2000
    7.6
    High

    CVE-2000-0330

    Last Modified: 5 Jul 2012

    The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability.

    Source:UNYUN
    Published:12 Nov 1999
    5.1
    Medium

    CVE-2000-0329

    Last Modified: 5 Jul 2012

    A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.

    Source:Mukund
    Published:11 Nov 1999
    7.2
    High

    CVE-2000-0325

    Last Modified: 16 Oct 2017

    The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.

    Source:BrootForce
    Published:20 Aug 1999
    5
    Medium

    CVE-2000-0324

    Last Modified: 16 Jul 2012

    pcAnywhere 8.x and 9.0 allows remote attackers to cause a denial of service via a TCP SYN scan, e.g. by nmap.

    Source:Vacuum
    Published:25 Apr 2000
    10
    Critical

    CVE-2000-0322

    Last Modified: 20 Oct 2017

    The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary commands via shell metacharacters.

    Source:Metasploit
    Published:24 Apr 2000
    7.2
    High

    CVE-2000-0317

    Last Modified: 16 Jul 2012

    Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.

    Source:DiGiT
    Published:24 Apr 2000
    7.2
    High

    CVE-2000-0316

    Last Modified: 16 Jul 2012

    Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.

    Source:DiGiT
    Published:24 Apr 2000
    10
    Critical

    CVE-2000-0306

    Last Modified: 18 Aug 2012

    Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.

    Source:Leshka Zakharoff
    Published:12 Mar 2001
    7.8
    High

    CVE-2000-0305

    Last Modified: 16 Apr 2026

    Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.

    Source:phonix
    Published:19 May 2000
    5
    Medium

    CVE-2000-0302

    Last Modified: 14 Jul 2012

    Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.

    Source:David Litchfield
    Published:31 Mar 2000
    10
    Critical

    CVE-2000-0300

    Last Modified: 14 Jul 2012

    The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts.

    Source:Pascal Longpre
    Published:6 Apr 2000
    5
    Medium

    CVE-2000-0299

    Last Modified: 9 Aug 2012

    Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept.

    Source:Bruce Potter
    Published:4 Apr 2000
    10
    Critical

    CVE-2000-0295

    Last Modified: 16 Jul 2012

    Buffer overflow in LCDproc allows remote attackers to gain root privileges via the screen_add command.

    Source:Andrew Hobgood
    Published:21 Apr 2000
    2.1
    Low

    CVE-2000-0293

    Last Modified: 16 Jul 2012

    aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa_base when it deletes expired files from the /tmp directory.

    Source:Peter_M
    Published:26 Apr 2000
    10
    Critical

    CVE-2000-0287

    Last Modified: 15 Jul 2012

    The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter.

    Source:PErfecto Technology
    Published:12 Apr 2000
    2.1
    Low

    CVE-2000-0286

    Last Modified: 15 Jul 2012

    X fontserver xfs allows local users to cause a denial of service via malformed input to the server.

    Source:Michal Zalewski
    Published:16 Apr 2000
    7.5
    High

    CVE-2000-0284

    Last Modified: 16 Apr 2026

    Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.

    Source:teleh0r
    Published:16 Apr 2000
    5
    Medium

    CVE-2000-0282

    Last Modified: 15 Jul 2012

    TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program.

    Source:John P. McNeely
    Published:12 Apr 2000
    2.6
    Low

    CVE-2000-0280

    Last Modified: 14 Jul 2012

    Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of service via a long Location URL.

    Source:Adam Muntner
    Published:3 Apr 2000
    5
    Medium

    CVE-2000-0279

    Last Modified: 15 Jul 2012

    BeOS allows remote attackers to cause a denial of service via malformed packets whose length field is less than the length of the headers.

    Source:Tim Newsham
    Published:7 Apr 2000
    5
    Medium

    CVE-2000-0278

    Last Modified: 14 Jul 2012

    The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does not authenticate the user.

    Source:Todd Beebe
    Published:3 Aug 2000
    2.1
    Low

    CVE-2000-0276

    Last Modified: 1 Oct 2012

    BeOS 4.5 and 5.0 allow local users to cause a denial of service via malformed direct system calls using interrupt 37.

    Source:Konstantin Boldyshev
    Published:10 Apr 2000
    2.1
    Low

    CVE-2000-0275

    Last Modified: 15 Jul 2012

    CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.

    Source:kingpin
    Published:10 Apr 2000
    2.1
    Low

    CVE-2000-0274

    Last Modified: 15 Jul 2012

    The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name.

    Source:Andrey E. Lerman
    Published:10 Apr 2000
    7.8
    High

    CVE-2000-0272

    Last Modified: 22 Jul 2012

    RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070.

    Source:Ussr Labs
    Published:20 Apr 2000
    2.1
    Low

    CVE-2000-0264

    Last Modified: 22 Jul 2012

    Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file or using other methods.

    Source:Zan
    Published:17 Apr 2000
    2.1
    Low

    CVE-2000-0263

    Last Modified: 15 Jul 2012

    The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.

    Source:Michal Zalewski
    Published:16 Apr 2000
    5
    Medium

    CVE-2000-0262

    Last Modified: 11 Jul 2017

    The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request.

    Source:eAX
    Published:12 Apr 2000
    7.5
    High

    CVE-2000-0260

    Last Modified: 15 Jul 2012

    Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link View Server-Side Component" vulnerability.

    Source:rain forest puppy
    Published:14 Apr 2000
    7.5
    High

    CVE-2000-0257

    Last Modified: 15 Jul 2012

    Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long URL.

    Source:Michal Zalewski
    Published:19 Apr 2000
    7.5
    High

    CVE-2000-0256

    Last Modified: 15 Jul 2012

    Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability.

    Source:Narrow
    Published:19 Apr 2000
    5
    Medium

    CVE-2000-0254

    Last Modified: 4 Oct 2016

    The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.

    Source:tombow & Randy Janinda
    Published:14 Apr 2000
    7.2
    High

    CVE-2000-0250

    Last Modified: 15 Nov 2017

    The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.

    Source:Sean
    Published:14 Apr 2000
    10
    Critical

    CVE-2000-0248

    Last Modified: 27 Oct 2016

    The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.

    Source:Max Vision
    Published:24 Apr 2000
    5
    Medium

    CVE-2000-0246

    Last Modified: 14 Jul 2012

    IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.

    Source:Adam Coyne
    Published:30 Mar 2000
    10
    Critical

    CVE-2000-0245

    Last Modified: 14 Jul 2012

    Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts.

    Source:Last Stage of Delirium
    Published:27 Mar 2000
    10
    Critical

    CVE-2000-0244

    Last Modified: 14 Jul 2012

    The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.

    Source:Dug Song
    Published:29 Mar 2000
    5
    Medium

    CVE-2000-0243

    Last Modified: 14 Jul 2012

    AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request to cgi-bin.

    Source:Presto Chango
    Published:25 Mar 2000
    5
    Medium

    CVE-2000-0242

    Last Modified: 14 Jul 2012

    WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters.

    Source:Quan Peng
    Published:25 Mar 2000
    5
    Medium

    CVE-2000-0240

    Last Modified: 14 Jul 2012

    vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a .. (dot dot) attack.

    Source:Johan Nilsson
    Published:21 Mar 2000
    5
    Medium

    CVE-2000-0239

    Last Modified: 16 Jul 2012

    Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET request.

    Source:Ussr Labs
    Published:15 Mar 2000