7.5
    High

    CVE-2000-0446

    Last Modified: 20 Jul 2012

    Buffer overflow in MDBMS database server allows remote attackers to execute arbitrary commands via a long string.

    Source:HaCk-13 TeaM
    Published:24 May 2000
    5
    Medium

    CVE-2000-0444

    Last Modified: 20 Jul 2012

    HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000.

    Source:Ussr Labs
    Published:24 May 2000
    7.5
    High

    CVE-2000-0443

    Last Modified: 19 Jul 2012

    The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

    Source:Ussr Labs
    Published:24 May 2000
    7.5
    High

    CVE-2000-0442

    Last Modified: 19 Jul 2012

    Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.

    Source:Prizm
    Published:24 May 2000
    5
    Medium

    CVE-2000-0440

    Last Modified: 17 Jul 2012

    NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.

    Source:y3t1
    Published:1 May 2000
    7.2
    High

    CVE-2000-0438

    Last Modified: 19 Jul 2012

    Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long mountpoint parameter.

    Source:Paulo Ribeiro
    Published:22 May 2000
    10
    Critical

    CVE-2000-0437

    Last Modified: 16 Apr 2026

    Buffer overflow in the CyberPatrol daemon "cyberdaemon" used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute arbitrary commands.

    Published:18 May 2000
    5
    Medium

    CVE-2000-0436

    Last Modified: 19 Jul 2012

    MetaProducts Offline Explorer 1.2 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) attack.

    Source:Wyzewun
    Published:19 May 2000
    7.5
    High

    CVE-2000-0432

    Last Modified: 18 Jul 2012

    The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters.

    Source:suid
    Published:16 May 2000
    5
    Medium

    CVE-2000-0430

    Last Modified: 22 Jul 2012

    Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request.

    Source:cassius
    Published:3 May 2000
    7.5
    High

    CVE-2000-0429

    Last Modified: 16 Jul 2012

    A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands.

    Source:Cerberus Security Team
    Published:27 Apr 2000
    4.6
    Medium

    CVE-2000-0427

    Last Modified: 22 Jul 2012

    The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM.

    Source:kingpin
    Published:4 May 2000
    5
    Medium

    CVE-2000-0426

    Last Modified: 17 Jul 2012

    UltraBoard 1.6 and other versions allow remote attackers to cause a denial of service by referencing UltraBoard in the Session parameter, which causes UltraBoard to fork copies of itself.

    Source:Juan M. Bello Rivas
    Published:5 May 2000
    10
    Critical

    CVE-2000-0425

    Last Modified: 17 Jul 2012

    Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.

    Source:David Litchfield
    Published:3 May 2000
    7.5
    High

    CVE-2000-0424

    Last Modified: 18 Jul 2012

    The CGI counter 4.0.7 by George Burgyan allows remote attackers to execute arbitrary commands via shell metacharacters.

    Source:Howard M. Kash III
    Published:15 May 2000
    5
    Medium

    CVE-2000-0423

    Last Modified: 22 Jul 2012

    Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag.

    Source:Joey__
    Published:5 May 2000
    5
    Medium

    CVE-2000-0418

    Last Modified: 23 Oct 2017

    The Cayman 3220-H DSL router allows remote attackers to cause a denial of service via oversized ICMP echo (ping) requests.

    Source:anonymous
    Published:23 May 2000
    5
    Medium

    CVE-2000-0417

    Last Modified: 18 Jul 2012

    The HTTP administration interface to the Cayman 3220-H DSL router allows remote attackers to cause a denial of service via a long username or password.

    Source:cassius
    Published:17 May 2000
    5
    Medium

    CVE-2000-0413

    Last Modified: 17 Jul 2012

    The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.

    Source:Frankie Zie
    Published:6 May 2000
    7.5
    High

    CVE-2000-0412

    Last Modified: 17 Jul 2012

    The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.

    Source:no_maam
    Published:1 May 1999
    5
    Medium

    CVE-2000-0411

    Last Modified: 17 Jul 2012

    Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter.

    Source:Black Watch Labs
    Published:10 May 2000
    3.7
    Low

    CVE-2000-0409

    Last Modified: 18 Jul 2012

    Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.

    Source:foo
    Published:10 May 2000
    5
    Medium

    CVE-2000-0408

    Last Modified: 1 Oct 2012

    IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.

    Source:Ussr Labs
    Published:11 May 2000
    7.2
    High

    CVE-2000-0407

    Last Modified: 18 Jul 2012

    Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.

    Source:ADM
    Published:12 May 2000
    10
    Critical

    CVE-2000-0405

    Last Modified: 18 Jul 2012

    Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.

    Source:Hugo Breton
    Published:16 May 2000
    2.1
    Low

    CVE-2000-0402

    Last Modified: 9 Mar 2011

    The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.

    Source:Metasploit
    Published:30 May 2000
    7.5
    High

    CVE-2000-0400

    Last Modified: 18 Jul 2012

    The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post.

    Source:http-equiv
    Published:13 May 2000
    5
    Medium

    CVE-2000-0397

    Last Modified: 18 Jul 2012

    The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.

    Source:Pierre Benoit
    Published:15 May 2000
    5
    Medium

    CVE-2000-0396

    Last Modified: 19 Jul 2012

    The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files.

    Source:Cerberus Security Team
    Published:24 May 2000
    5
    Medium

    CVE-2000-0395

    Last Modified: 18 Jul 2012

    Buffer overflow in CProxy 3.3 allows remote users to cause a denial of service via a long HTTP request.

    Source:HaCk-13 TeaM
    Published:16 May 2000
    5
    Medium

    CVE-2000-0394

    Last Modified: 19 Jul 2012

    NetProwler 3.0 allows remote attackers to cause a denial of service by sending malformed IP packets that trigger NetProwler's Man-in-the-Middle signature.

    Source:rain forest puppy
    Published:18 May 2000
    7.2
    High

    CVE-2000-0393

    Last Modified: 22 Jul 2012

    The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.

    Source:Sebastian
    Published:16 May 2000
    10
    Critical

    CVE-2000-0389

    Last Modified: 18 Jul 2012

    Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.

    Source:duke
    Published:16 May 2000
    10
    Critical

    CVE-2000-0384

    Last Modified: 1 Oct 2012

    NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC address, which could allow remote attackers to gain root access.

    Source:Stake Inc
    Published:8 May 2000
    6.4
    Medium

    CVE-2000-0381

    Last Modified: 17 Jul 2012

    The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existing database in the db parameter.

    Source:Black Watch Labs
    Published:5 May 2000
    7.1
    High

    CVE-2000-0380

    Last Modified: 15 Jun 2017

    The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.

    Source:Keith Woodworth
    Published:26 Apr 2000
    3.6
    Low

    CVE-2000-0379

    Last Modified: 15 Nov 2017

    The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so.

    Source:Stephen Friedl
    Published:16 May 2000
    7.2
    High

    CVE-2000-0378

    Last Modified: 22 Nov 2017

    The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.

    Source:Michal Zalewski
    Published:3 May 2000
    5
    Medium

    CVE-2000-0377

    Last Modified: 21 Jul 2012

    The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability.

    Source:Renaud Deraison
    Published:8 Jun 2000
    7.2
    High

    CVE-2000-0362

    Last Modified: 22 Nov 2017

    Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.

    Source:Brock Tellier
    Published:22 Oct 1999
    5
    Medium

    CVE-2000-0350

    Last Modified: 18 Jul 2012

    A debugging feature in NetworkICE ICEcap 2.0.23 and earlier is enabled, which allows a remote attacker to bypass the weak authentication and post unencrypted events.

    Source:rain forest puppy
    Published:17 May 2000
    5
    Medium

    CVE-2000-0347

    Last Modified: 17 Jul 2012

    Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name.

    Source:rain forest puppy
    Published:2 May 2000
    10
    Critical

    CVE-2000-0343

    Last Modified: 16 Jul 2012

    Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary commands via a long MAIL FROM mail header.

    Source:FuSyS
    Published:2 May 2000
    7.5
    High

    CVE-2000-0342

    Last Modified: 16 Jul 2012

    Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."

    Source:Bennett Haselton
    Published:28 Apr 2000
    5
    Medium

    CVE-2000-0341

    Last Modified: 16 Jul 2012

    ATRIUM Cassandra NNTP Server 1.10 allows remote attackers to cause a denial of service via a long login name.

    Source:Ussr Labs
    Published:1 May 2000
    7.2
    High

    CVE-2000-0340

    Last Modified: 16 Jul 2012

    Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environmental variable.

    Source:bladi
    Published:29 Apr 2000
    7.5
    High

    CVE-2000-0339

    Last Modified: 16 Jul 2012

    ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.

    Source:Wally Whacker
    Published:24 Apr 2000
    5.5
    Medium

    CVE-2000-0338

    Last Modified: 16 Jul 2012

    Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.

    Source:Michal Szymanski
    Published:23 Apr 2000
    7.2
    High

    CVE-2000-0337

    Last Modified: 16 Jul 2012

    Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.

    Source:DiGiT
    Published:24 Apr 2000
    2.1
    Low

    CVE-2000-0336

    Last Modified: 19 Jul 2012

    Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.

    Source:anonymous
    Published:13 Apr 2000