Total
29527 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2000-1176 | 1 Yabb | 1 Yabb | 2008-09-05 | 7.5 HIGH | N/A |
Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field. | |||||
CVE-2000-1152 | 1 Be | 1 Beos | 2008-09-05 | 5.0 MEDIUM | N/A |
Browser IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL. | |||||
CVE-2000-1157 | 1 Network Associates | 1 Sniffer Agent | 2008-09-05 | 10.0 HIGH | N/A |
Buffer overflow in NAI Sniffer Agent allows remote attackers to execute arbitrary commands via a long SNMP community name. | |||||
CVE-2000-1161 | 1 Adcycle | 1 Adcycle | 2008-09-05 | 7.5 HIGH | N/A |
The installation of AdCycle banner management system leaves the build.cgi program in a web-accessible directory, which allows remote attackers to execute the program and view passwords or delete databases. | |||||
CVE-2000-1037 | 1 Checkpoint | 1 Firewall-1 | 2008-09-05 | 7.5 HIGH | N/A |
Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack. | |||||
CVE-2000-1098 | 1 Sonicwall | 1 Soho Firewall | 2008-09-05 | 5.0 MEDIUM | N/A |
The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or POST request. | |||||
CVE-2000-1229 | 1 Phorum | 1 Phorum | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3. | |||||
CVE-2000-1158 | 1 Network Associates | 1 Sniffer Agent | 2008-09-05 | 7.5 HIGH | N/A |
NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords. | |||||
CVE-2000-1231 | 1 Phorum | 1 Phorum | 2008-09-05 | 5.0 MEDIUM | N/A |
code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string. | |||||
CVE-2000-1228 | 1 Phorum | 1 Phorum | 2008-09-05 | 5.0 MEDIUM | N/A |
Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables. | |||||
CVE-2000-0976 | 1 Xfree86 Project | 1 Xlib | 2008-09-05 | 4.6 MEDIUM | N/A |
Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter. | |||||
CVE-2000-1211 | 1 Zope | 1 Zope | 2008-09-05 | 7.5 HIGH | N/A |
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities. | |||||
CVE-2000-1017 | 1 Webteacher | 1 Webdata | 2008-09-05 | 5.0 MEDIUM | N/A |
Webteachers Webdata allows remote attackers with valid Webdata accounts to read arbitrary files by posting a request to import the file into the WebData database. | |||||
CVE-2000-1129 | 1 Network Associates | 1 Webshield Smtp | 2008-09-05 | 5.0 MEDIUM | N/A |
McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field. | |||||
CVE-2000-1225 | 1 Imatix | 1 Xitami | 2008-09-05 | 5.0 MEDIUM | N/A |
Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program. | |||||
CVE-2000-1223 | 1 I-soft | 1 Quikstore | 2008-09-05 | 7.5 HIGH | N/A |
quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request. | |||||
CVE-2000-0842 | 1 Sco | 1 Unixware | 2008-09-05 | 5.0 MEDIUM | N/A |
The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |||||
CVE-2000-1230 | 1 Phorum | 1 Phorum | 2008-09-05 | 5.0 MEDIUM | N/A |
Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman". | |||||
CVE-2000-0916 | 1 Freebsd | 1 Freebsd | 2008-09-05 | 7.5 HIGH | N/A |
FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections. | |||||
CVE-2000-1130 | 1 Network Associates | 1 Webshield Smtp | 2008-09-05 | 7.5 HIGH | N/A |
McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment. |