CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 115178 CVEs

CVE ID Severity Description EPSS Published
N/A

ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.

0.6% 2000-03-01
N/A

Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.

13.0% 2000-02-29
N/A

The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch.

6.7% 2000-02-29
N/A

Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.

8.2% 2000-02-29
N/A

The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.

0.8% 2000-02-29
N/A

The Trend Micro OfficeScan client allows remote attackers to cause a denial of service by making 5 connections to port 12345, which raises CPU utilization to 100%.

5.2% 2000-02-28
N/A

The Trend Micro OfficeScan client tmlisten.exe allows remote attackers to cause a denial of service via malformed data to port 12345.

0.8% 2000-02-28
N/A

Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message.

1.3% 2000-02-28
N/A

Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.

0.1% 2000-02-28
N/A

HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555.

10.5% 2000-02-28
N/A

ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions.

0.6% 2000-02-28
N/A

Buffer overflow in Lynx 2.x allows remote attackers to crash Lynx and possibly execute commands via a long URL in a malicious web page.

3.1% 2000-02-27
N/A

EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.

2.5% 2000-02-27
N/A

EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.

13.4% 2000-02-27
N/A

Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.

0.2% 2000-02-26
N/A

The Nautica Marlin bridge allows remote attackers to cause a denial of service via a zero length UDP packet to the SNMP port.

4.0% 2000-02-25
N/A

ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event.

0.6% 2000-02-24
N/A

The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.

0.6% 2000-02-24
N/A

FTP Explorer uses weak encryption for storing the username, password, and profile of FTP sites.

0.2% 2000-02-24
N/A

InterAccess TelnetD Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client configuration information.

4.0% 2000-02-24
N/A

setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverrc file.

0.1% 2000-02-24
N/A

buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters.

0.1% 2000-02-24
N/A

Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt.

0.4% 2000-02-23
N/A

The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters.

7.4% 2000-02-23
N/A

The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerability.

26.6% 2000-02-23
N/A

iPlanet Web Server 4.1 allows remote attackers to cause a denial of service via a large number of GET commands, which consumes memory and causes a kernel panic.

0.2% 2000-02-23
N/A

The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary files.

0.2% 2000-02-21
N/A

Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login name.

6.6% 2000-02-21
N/A

asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file.

0.2% 2000-02-21
N/A

The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.

10.3% 2000-02-21
N/A

The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords.

0.0% 2000-02-20
N/A

The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.

1.5% 2000-02-18
N/A

Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands.

8.4% 2000-02-18
N/A

Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.

1.7% 2000-02-18
N/A

HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges.

0.7% 2000-02-17
N/A

Buffer overflow in MMDF server allows remote attackers to gain privileges via a long MAIL FROM command to the SMTP daemon.

0.9% 2000-02-16
N/A

Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability.

17.5% 2000-02-16
N/A

The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.

0.3% 2000-02-16
N/A

procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.

0.4% 2000-02-16
N/A

ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.

0.3% 2000-02-15
N/A

The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs.

33.1% 2000-02-15
N/A

IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.

0.2% 2000-02-15
N/A

The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.

0.4% 2000-02-14
N/A

Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.

0.5% 2000-02-12
N/A

The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP.

0.1% 2000-02-11
N/A

The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417.

5.7% 2000-02-11
N/A

Infopop Ultimate Bulletin Board (UBB) allows remote attackers to execute commands via shell metacharacters in the topic hidden field.

2.5% 2000-02-11
N/A

Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service via a large number of connections.

0.7% 2000-02-10
N/A

Vulnerability in SCO cu program in UnixWare 7.x allows local users to gain privileges.

0.1% 2000-02-08
N/A

Zeus web server allows remote attackers to view the source code for CGI programs via a null character (%00) at the end of a URL.

4.7% 2000-02-08