Vulnerabilities (CVE)

Total 304758 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0208 1 Htdig 1 Htdig 2008-09-10 5.0 MEDIUM N/A
The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch.
CVE-2000-0171 1 At Computing 1 Atsar Linux 2008-09-10 7.2 HIGH N/A
atsadc in the atsar package for Linux does not properly check the permissions of an output file, which allows local users to gain root privileges.
CVE-2000-0223 1 Sam Hawker 1 Wmcdplay 2008-09-10 7.2 HIGH N/A
Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges via a long parameter.
CVE-2000-0178 1 Foundrynet 1 Serveriron 2008-09-10 7.5 HIGH N/A
ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions.
CVE-2000-0132 1 Microsoft 1 Virtual Machine 2008-09-10 2.6 LOW N/A
Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.
CVE-2000-0267 1 Cisco 1 Catos 2008-09-10 4.6 MEDIUM N/A
Cisco Catalyst 5.4.x allows a user to gain access to the "enable" mode without a password.
CVE-2000-0167 1 Microsoft 1 Internet Information Server 2008-09-10 2.1 LOW N/A
IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.
CVE-2000-0237 1 Netscape 1 Enterprise Server 2008-09-10 6.4 MEDIUM N/A
Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories.
CVE-2000-0170 2 Redhat, Turbolinux 2 Linux, Turbolinux 2008-09-10 7.2 HIGH N/A
Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.
CVE-2000-0197 1 Microsoft 1 Windows Nt 2008-09-10 4.6 MEDIUM N/A
The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.
CVE-2000-0217 2 Openbsd, Ssh 3 Openssh, Ssh, Ssh2 2008-09-10 5.1 MEDIUM N/A
The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.
CVE-2000-0218 2 Caldera, Suse 2 Openlinux, Suse Linux 2008-09-10 7.2 HIGH N/A
Buffer overflow in Linux mount and umount allows local users to gain root privileges via a long relative pathname.
CVE-2000-0194 1 Corel 1 Linux 2008-09-10 7.2 HIGH N/A
buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters.
CVE-2000-0248 1 Redhat 1 Linux 2008-09-10 10.0 HIGH N/A
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.
CVE-2000-0206 1 Oracle 1 Oracle8i 2008-09-10 6.2 MEDIUM N/A
The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local users to gain privileges.
CVE-2000-0230 2 Halloween, Redhat 2 Halloween Linux, Linux 2008-09-10 7.2 HIGH N/A
Buffer overflow in imwheel allows local users to gain root privileges via the imwheel-solo script and a long HOME environmental variable.
CVE-2000-0163 1 Freebsd 1 Freebsd 2008-09-10 4.6 MEDIUM N/A
asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file.
CVE-2000-0278 1 Saleslogix 1 Corporation Eviewer 2008-09-10 5.0 MEDIUM N/A
The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does not authenticate the user.
CVE-2000-0144 1 Axis 1 700 Network Document Server 2008-09-10 7.5 HIGH N/A
Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack.
CVE-2000-0174 1 Sun 1 Staroffice 2008-09-10 5.0 MEDIUM N/A
StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.