Total
29527 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2000-0918 | 1 Kde | 1 Kvt | 2008-09-05 | 7.2 HIGH | N/A |
Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters. | |||||
CVE-2000-0998 | 1 Freebsd | 1 Freebsd | 2008-09-05 | 7.2 HIGH | N/A |
Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function. | |||||
CVE-2000-1226 | 1 Snort | 1 Snort | 2008-09-05 | 5.0 MEDIUM | N/A |
Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan. | |||||
CVE-2000-1114 | 1 Unify | 1 Ewave Servletexec | 2008-09-05 | 5.0 MEDIUM | N/A |
Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20". | |||||
CVE-2000-1102 | 1 Ptlink | 2 Ptlink Irc Services, Ptlink Ircd | 2008-09-05 | 5.0 MEDIUM | N/A |
PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode +owgscfxeb" and "oper" commands. | |||||
CVE-2000-0843 | 2 Dave Airlie, Luke Kenneth Casson Leighton | 2 Pam Smb, Pam Ntdom | 2008-09-05 | 10.0 HIGH | N/A |
Buffer overflow in pam_smb and pam_ntdom pluggable authentication modules (PAM) allow remote attackers to execute arbitrary commands via a login with a long user name. | |||||
CVE-2000-1232 | 1 Phorum | 1 Phorum | 2008-09-05 | 5.0 MEDIUM | N/A |
upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method. | |||||
CVE-2000-1128 | 1 Mcafee | 1 Virusscan | 2008-09-05 | 4.6 MEDIUM | N/A |
The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:\Program Files directory. | |||||
CVE-2000-0905 | 1 Qnx | 1 Voyager | 2008-09-05 | 5.0 MEDIUM | N/A |
QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page. | |||||
CVE-2000-0882 | 1 Intel | 4 Express 510t, Express 520t, Express 550f and 1 more | 2008-09-05 | 5.0 MEDIUM | N/A |
Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash. | |||||
CVE-2000-1100 | 1 Trlinux | 1 Postaci Webmail | 2008-09-05 | 7.5 HIGH | N/A |
The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request. | |||||
CVE-2000-1173 | 1 Microsys | 1 Cyberpatrol | 2008-09-05 | 5.0 MEDIUM | N/A |
Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information. | |||||
CVE-2000-1101 | 1 Texas Imperial Software | 1 Wftpd | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack. | |||||
CVE-2000-1008 | 1 Palm | 1 Palm Os | 2008-09-05 | 4.6 MEDIUM | N/A |
PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device to decrypt the password and gain access to the device. | |||||
CVE-2000-1013 | 1 Freebsd | 1 Freebsd | 2008-09-05 | 7.2 HIGH | N/A |
The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable. | |||||
CVE-2000-0718 | 1 Mandrakesoft | 1 Mandrake Linux | 2008-09-05 | 1.2 LOW | N/A |
A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed. | |||||
CVE-2000-0735 | 1 Rimarts Inc. | 1 Becky Internet Mail | 2008-09-05 | 5.0 MEDIUM | N/A |
Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message. | |||||
CVE-2000-0831 | 1 Fastream | 1 Ftp\+\+ Server | 2008-09-05 | 7.5 HIGH | N/A |
Buffer overflow in Fastream FTP++ 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long username. | |||||
CVE-2000-0730 | 1 Hp | 1 Hp-ux | 2008-09-05 | 4.6 MEDIUM | N/A |
Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges. | |||||
CVE-2000-0700 | 1 Cisco | 4 Gigabit Switch Router 12008, Gigabit Switch Router 12012, Gigabit Switch Router 12016 and 1 more | 2008-09-05 | 5.0 MEDIUM | N/A |
Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the interface to stop forwarding packets. |