|
346351
|
2.1 |
LOW
|
kirk_bauer conectiva
|
diskcheck linux
|
DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symlink attack on a temporary file.
|
CWE-59
Link Following
|
CVE-2000-0715
|
2008-09-11 04:05 |
2000-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346352
|
7.2 |
HIGH
|
zope
|
zope
|
Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.
|
NVD-CWE-Other
|
CVE-2000-0725
|
2008-09-11 04:05 |
2000-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346353
|
7.5 |
HIGH
|
netbsd openbsd redhat
|
netbsd openbsd linux
|
Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.
|
NVD-CWE-Other
|
CVE-2000-0750
|
2008-09-11 04:05 |
2000-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346354
|
7.5 |
HIGH
|
checkpoint
|
firewall-1
|
Checkpoint Firewall-1 with the RSH/REXEC setting enabled allows remote attackers to bypass access restrictions and connect to a RSH/REXEC client via malformed connection requests.
|
NVD-CWE-Other
|
CVE-2000-0779
|
2008-09-11 04:05 |
2000-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346355
|
7.5 |
HIGH
|
xchat
|
xchat
|
IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser.
|
NVD-CWE-Other
|
CVE-2000-0787
|
2008-09-11 04:05 |
2000-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346356
|
10.0 |
HIGH
|
suse
|
suse_linux
|
String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.
|
NVD-CWE-Other
|
CVE-2000-0800
|
2008-09-11 04:05 |
2000-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346357
|
6.4 |
MEDIUM
|
sgi
|
irix
|
The default installation of IRIX Performance Copilot allows remote attackers to access sensitive system information via the pmcd daemon.
|
NVD-CWE-Other
|
CVE-2000-0283
|
2008-09-11 04:04 |
2000-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346358
|
7.5 |
HIGH
|
university_of_washington
|
imap
|
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.
|
NVD-CWE-Other
|
CVE-2000-0284
|
2008-09-11 04:04 |
2000-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346359
|
7.2 |
HIGH
|
xfree86_project
|
x11r6
|
Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter.
|
NVD-CWE-Other
|
CVE-2000-0285
|
2008-09-11 04:04 |
2000-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346360
|
2.1 |
LOW
|
redhat
|
linux
|
X fontserver xfs allows local users to cause a denial of service via malformed input to the server.
|
NVD-CWE-Other
|
CVE-2000-0286
|
2008-09-11 04:04 |
2000-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346361
|
10.0 |
HIGH
|
cnc
|
technology_bizdb
|
The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter.
|
NVD-CWE-Other
|
CVE-2000-0287
|
2008-09-11 04:04 |
2000-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346362
|
5.0 |
MEDIUM
|
-
|
-
|
Infonautics getdoc.cgi allows remote attackers to bypass the payment phase for accessing documents via a modified form variable.
|
NVD-CWE-Other
|
CVE-2000-0288
|
2008-09-11 04:04 |
2000-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346363
|
5.0 |
MEDIUM
|
debian linux redhat
|
debian_linux linux_kernel linux
|
IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established…
|
NVD-CWE-Other
|
CVE-2000-0289
|
2008-09-11 04:04 |
2000-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346364
|
4.6 |
MEDIUM
|
sun
|
staroffice
|
Buffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a document.
|
NVD-CWE-Other
|
CVE-2000-0291
|
2008-09-11 04:04 |
2000-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346365
|
2.1 |
LOW
|
suse
|
suse_linux
|
aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa…
|
NVD-CWE-Other
|
CVE-2000-0293
|
2008-09-11 04:04 |
2000-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346366
|
7.2 |
HIGH
|
jim_housley
|
healthd
|
Buffer overflow in healthd for FreeBSD allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2000-0294
|
2008-09-11 04:04 |
2000-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346367
|
7.2 |
HIGH
|
michael_a._gumienny
|
fcheck
|
fcheck allows local users to gain privileges by embedding shell metacharacters into file names that are processed by fcheck.
|
NVD-CWE-Other
|
CVE-2000-0296
|
2008-09-11 04:04 |
2000-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346368
|
6.4 |
MEDIUM
|
allaire
|
forums
|
Allaire Forums 2.0.5 allows remote attackers to bypass access restrictions to secure conferences via the rightAccessAllForums or rightModerateAllForums variables.
|
NVD-CWE-Other
|
CVE-2000-0297
|
2008-09-11 04:04 |
2000-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346369
|
5.0 |
MEDIUM
|
apple
|
webobjects
|
Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept.
|
NVD-CWE-Other
|
CVE-2000-0299
|
2008-09-11 04:04 |
2000-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346370
|
6.4 |
MEDIUM
|
id_software
|
quake_3_arena
|
Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.
|
NVD-CWE-Other
|
CVE-2000-0303
|
2008-09-11 04:04 |
2000-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346371
|
2.1 |
LOW
|
openbsd
|
openbsd
|
The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a denial of service.
|
NVD-CWE-Other
|
CVE-2000-0309
|
2008-09-11 04:04 |
2001-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346372
|
5.0 |
MEDIUM
|
openbsd
|
openbsd
|
IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets.
|
NVD-CWE-Other
|
CVE-2000-0310
|
2008-09-11 04:04 |
2001-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346373
|
4.6 |
MEDIUM
|
openbsd
|
openbsd
|
Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations.
|
NVD-CWE-Other
|
CVE-2000-0313
|
2008-09-11 04:04 |
2001-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346374
|
7.5 |
HIGH
|
atrium_software
|
mercur_mailserver
|
Atrium Mercur Mail Server 3.2 allows local attackers to read other user's email and create arbitrary files via a dot dot (..) attack.
|
NVD-CWE-Other
|
CVE-2000-0318
|
2008-09-11 04:04 |
2000-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346375
|
5.0 |
MEDIUM
|
icradius
|
icradius
|
Buffer overflow in IC Radius package allows a remote attacker to cause a denial of service via a long user name.
|
NVD-CWE-Other
|
CVE-2000-0321
|
2008-09-11 04:04 |
2000-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346376
|
5.0 |
MEDIUM
|
on_technology
|
meeting_maker
|
Meeting Maker uses weak encryption (a polyalphabetic substitution cipher) for passwords, which allows remote attackers to sniff and decrypt passwords for Meeting Maker accounts.
|
NVD-CWE-Other
|
CVE-2000-0326
|
2008-09-11 04:04 |
2000-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346377
|
2.1 |
LOW
|
allaire
|
spectra
|
The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the cont…
|
NVD-CWE-Other
|
CVE-2000-0334
|
2008-09-11 04:04 |
2000-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346378
|
7.5 |
HIGH
|
gnu isc
|
glibc bind
|
The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.
|
NVD-CWE-Other
|
CVE-2000-0335
|
2008-09-11 04:04 |
2000-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346379
|
2.1 |
LOW
|
openldap mandrakesoft redhat turbolinux
|
openldap mandrake_linux linux turbolinux
|
Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2000-0336
|
2008-09-11 04:04 |
2000-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346380
|
5.0 |
MEDIUM
|
networkice
|
icecap_manager
|
A debugging feature in NetworkICE ICEcap 2.0.23 and earlier is enabled, which allows a remote attacker to bypass the weak authentication and post unencrypted events.
|
NVD-CWE-Other
|
CVE-2000-0350
|
2008-09-11 04:04 |
2000-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346381
|
10.0 |
HIGH
|
university_of_washington
|
pine
|
Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.
|
NVD-CWE-Other
|
CVE-2000-0353
|
2008-09-11 04:04 |
1999-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346382
|
7.5 |
HIGH
|
bent_bagger redhat suse
|
pbpg linux suse_linux
|
pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.
|
NVD-CWE-Other
|
CVE-2000-0355
|
2008-09-11 04:04 |
1999-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346383
|
4.6 |
MEDIUM
|
redhat
|
linux
|
Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disabled NIS accounts.
|
NVD-CWE-Other
|
CVE-2000-0356
|
2008-09-11 04:04 |
1999-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346384
|
7.5 |
HIGH
|
redhat
|
linux
|
ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.
|
NVD-CWE-Other
|
CVE-2000-0357
|
2008-09-11 04:04 |
1999-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346385
|
5.0 |
MEDIUM
|
redhat
|
linux
|
ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.
|
NVD-CWE-Other
|
CVE-2000-0358
|
2008-09-11 04:04 |
1999-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346386
|
10.0 |
HIGH
|
acme_labs
|
thttpd
|
Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.
|
NVD-CWE-Other
|
CVE-2000-0359
|
2008-09-11 04:04 |
2000-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346387
|
5.0 |
MEDIUM
|
isc
|
inn
|
Buffer overflow in INN 2.2.1 and earlier allows remote attackers to cause a denial of service via a maliciously formatted article.
|
NVD-CWE-Other
|
CVE-2000-0360
|
2008-09-11 04:04 |
2000-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346388
|
2.1 |
LOW
|
suse
|
suse_linux
|
The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password inform…
|
NVD-CWE-Other
|
CVE-2000-0361
|
2008-09-11 04:04 |
1999-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346389
|
7.2 |
HIGH
|
suse
|
suse_linux
|
Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2000-0362
|
2008-09-11 04:04 |
1999-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346390
|
6.2 |
MEDIUM
|
suse
|
suse_linux
|
Linux cdwtools 093 and earlier allows local users to gain root privileges via the /tmp directory.
|
NVD-CWE-Other
|
CVE-2000-0363
|
2008-09-11 04:04 |
1999-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346391
|
2.1 |
LOW
|
debian
|
debian_linux
|
dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.
|
NVD-CWE-Other
|
CVE-2000-0366
|
2008-09-11 04:04 |
1999-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346392
|
7.2 |
HIGH
|
michael_jennings
|
eterm
|
Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.
|
NVD-CWE-Other
|
CVE-2000-0367
|
2008-09-11 04:04 |
1999-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346393
|
5.0 |
MEDIUM
|
caldera
|
openlinux
|
The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows remote attackers to cause a denial of service.
|
NVD-CWE-Other
|
CVE-2000-0369
|
2008-09-11 04:04 |
1999-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346394
|
10.0 |
HIGH
|
caldera
|
openlinux
|
The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.
|
NVD-CWE-Other
|
CVE-2000-0370
|
2008-09-11 04:04 |
1999-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346395
|
1.2 |
LOW
|
kde
|
kde
|
The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2000-0371
|
2008-09-11 04:04 |
1999-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346396
|
2.1 |
LOW
|
freebsd
|
freebsd
|
The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files.
|
NVD-CWE-Other
|
CVE-2000-0375
|
2008-09-11 04:04 |
2001-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346397
|
10.0 |
HIGH
|
i-drive
|
filo
|
Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request.
|
NVD-CWE-Other
|
CVE-2000-0376
|
2008-09-11 04:04 |
2000-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346398
|
7.2 |
HIGH
|
redhat
|
linux
|
The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allow…
|
NVD-CWE-Other
|
CVE-2000-0378
|
2008-09-11 04:04 |
2000-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346399
|
2.6 |
LOW
|
allaire
|
clustercats
|
ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site.
|
NVD-CWE-Other
|
CVE-2000-0382
|
2008-09-11 04:04 |
2000-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346400
|
5.0 |
MEDIUM
|
filemaker
|
filemaker
|
FileMaker Pro 5 Web Companion allows remote attackers to bypass Field-Level database security restrictions via the XML publishing or email capabilities.
|
NVD-CWE-Other
|
CVE-2000-0385
|
2008-09-11 04:04 |
2000-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|