272801
|
7.5 |
HIGH
|
zope
|
zope
|
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activ…
|
NVD-CWE-Other
|
CVE-2000-1211
|
2008-09-6 05:22 |
2000-12-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272802
|
7.5 |
HIGH
|
gnu
|
g\+\+ gcc
|
The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows.
|
NVD-CWE-Other
|
CVE-2000-1219
|
2008-09-6 05:22 |
2000-11-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272803
|
7.5 |
HIGH
|
i-soft
|
quikstore
|
quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request.
|
NVD-CWE-Other
|
CVE-2000-1223
|
2008-09-6 05:22 |
2000-11-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272804
|
5.0 |
MEDIUM
|
imatix
|
xitami
|
Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the progr…
|
NVD-CWE-Other
|
CVE-2000-1225
|
2008-09-6 05:22 |
2000-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272805
|
5.0 |
MEDIUM
|
snort
|
snort
|
Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending …
|
NVD-CWE-Other
|
CVE-2000-1226
|
2008-09-6 05:22 |
2000-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272806
|
5.0 |
MEDIUM
|
phorum
|
phorum
|
Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.
|
NVD-CWE-Other
|
CVE-2000-1228
|
2008-09-6 05:22 |
2000-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272807
|
5.0 |
MEDIUM
|
phorum
|
phorum
|
Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings a…
|
NVD-CWE-Other
|
CVE-2000-1229
|
2008-09-6 05:22 |
2000-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272808
|
5.0 |
MEDIUM
|
phorum
|
phorum
|
Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".
|
NVD-CWE-Other
|
CVE-2000-1230
|
2008-09-6 05:22 |
2000-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272809
|
5.0 |
MEDIUM
|
phorum
|
phorum
|
code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string.
|
NVD-CWE-Other
|
CVE-2000-1231
|
2008-09-6 05:22 |
2000-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272810
|
5.0 |
MEDIUM
|
phorum
|
phorum
|
upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method.
|
NVD-CWE-Other
|
CVE-2000-1232
|
2008-09-6 05:22 |
2000-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272811
|
7.5 |
HIGH
|
phorum
|
phorum
|
SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the sSQL parameter.
|
NVD-CWE-Other
|
CVE-2000-1233
|
2008-09-6 05:22 |
2000-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272812
|
5.0 |
MEDIUM
|
phorum
|
phorum
|
violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters.
|
NVD-CWE-Other
|
CVE-2000-1234
|
2008-09-6 05:22 |
2000-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272813
|
5.0 |
MEDIUM
|
oracle
|
application_server
|
The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via H…
|
NVD-CWE-Other
|
CVE-2000-1235
|
2008-09-6 05:22 |
2000-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272814
|
5.0 |
MEDIUM
|
floosietek
|
ftgate
|
The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessi…
|
NVD-CWE-Other
|
CVE-2000-1237
|
2008-09-6 05:22 |
2000-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272815
|
7.2 |
HIGH
|
ibm
|
aix
|
AIX cdmount allows local users to gain root privileges via shell metacharacters.
|
NVD-CWE-Other
|
CVE-2000-0466
|
2008-09-6 05:21 |
2000-06-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272816
|
5.0 |
MEDIUM
|
analogx
|
proxy
|
Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long HELO command in the SMTP protocol.
|
NVD-CWE-Other
|
CVE-2000-0657
|
2008-09-6 05:21 |
2000-07-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272817
|
2.1 |
LOW
|
cvs
|
cvs
|
The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files.
|
NVD-CWE-Other
|
CVE-2000-0679
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272818
|
7.2 |
HIGH
|
cvs
|
cvs
|
The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with …
|
NVD-CWE-Other
|
CVE-2000-0680
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272819
|
10.0 |
HIGH
|
bea
|
weblogic_server
|
Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.
|
NVD-CWE-Other
|
CVE-2000-0681
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272820
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet.
|
NVD-CWE-Other
|
CVE-2000-0682
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272821
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet.
|
NVD-CWE-Other
|
CVE-2000-0683
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272822
|
5.0 |
MEDIUM
|
cgi_script_center
|
auction_weaver
|
Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.
|
NVD-CWE-Other
|
CVE-2000-0686
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272823
|
10.0 |
HIGH
|
cgi_script_center
|
auction_weaver
|
Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter.
|
NVD-CWE-Other
|
CVE-2000-0687
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272824
|
2.1 |
LOW
|
gert_doering
|
mgetty
|
The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the tar…
|
NVD-CWE-Other
|
CVE-2000-0691
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272825
|
5.0 |
MEDIUM
|
iss
|
realsecure
|
ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.
|
NVD-CWE-Other
|
CVE-2000-0692
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272826
|
7.2 |
HIGH
|
tech-source
|
raptor_gfx_pgx32
|
pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the "cp" program, which allows local users to execute arbitrary commands by modifying their path to point…
|
NVD-CWE-Other
|
CVE-2000-0693
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272827
|
7.2 |
HIGH
|
tech-source
|
raptor_gfx_pgx32
|
pgxconfig in the Raptor GFX configuration tool allows local users to gain privileges via a symlink attack.
|
NVD-CWE-Other
|
CVE-2000-0694
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272828
|
7.2 |
HIGH
|
tech-source
|
raptor_gfx_pgx32
|
Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line options.
|
NVD-CWE-Other
|
CVE-2000-0695
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272829
|
10.0 |
HIGH
|
hp
|
hp-ux
|
Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strings in the PASS command.
|
NVD-CWE-Other
|
CVE-2000-0699
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272830
|
5.0 |
MEDIUM
|
cisco
|
ios gigabit_switch_router_12008 gigabit_switch_router_12012 gigabit_switch_router_12016
|
Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures…
|
NVD-CWE-Other
|
CVE-2000-0700
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272831
|
5.0 |
MEDIUM
|
pragma_systems
|
telnetserver
|
Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via a long series of null characters to the rexec port.
|
NVD-CWE-Other
|
CVE-2000-0708
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272832
|
5.0 |
MEDIUM
|
microsoft
|
frontpage
|
The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DO…
|
NVD-CWE-Other
|
CVE-2000-0709
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272833
|
7.2 |
HIGH
|
lids
|
lids
|
Linux Intrusion Detection System (LIDS) 0.9.7 allows local users to gain root privileges when LIDS is disabled via the security=0 boot option.
|
NVD-CWE-Other
|
CVE-2000-0712
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272834
|
7.6 |
HIGH
|
adobe
|
acrobat acrobat_business_tools acrobat_reader
|
Buffer overflow in Adobe Acrobat 4.05, Reader, Business Tools, and Fill In products that handle PDF files allows attackers to execute arbitrary commands via a long /Registry or /Ordering specifier.
|
NVD-CWE-Other
|
CVE-2000-0713
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272835
|
1.2 |
LOW
|
mandrakesoft
|
mandrake_linux
|
A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed.
|
NVD-CWE-Other
|
CVE-2000-0718
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272836
|
6.2 |
MEDIUM
|
varicad
|
varicad
|
VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program.
|
NVD-CWE-Other
|
CVE-2000-0719
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272837
|
6.2 |
MEDIUM
|
multisoft
|
flagship
|
The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses.
|
NVD-CWE-Other
|
CVE-2000-0721
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272838
|
6.2 |
MEDIUM
|
helix_code
|
go-gnome_pre-installer
|
The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files.
|
NVD-CWE-Other
|
CVE-2000-0724
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272839
|
4.6 |
MEDIUM
|
hp
|
hp-ux
|
Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2000-0730
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272840
|
10.0 |
HIGH
|
sgi
|
irix
|
Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-…
|
NVD-CWE-Other
|
CVE-2000-0733
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272841
|
5.0 |
MEDIUM
|
rimarts_inc.
|
becky_internet_mail
|
Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message.
|
NVD-CWE-Other
|
CVE-2000-0735
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272842
|
5.0 |
MEDIUM
|
rimarts_inc.
|
becky_internet_mail
|
Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message.
|
NVD-CWE-Other
|
CVE-2000-0736
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272843
|
7.5 |
HIGH
|
network_associates
|
net_tools_pki_server
|
Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.
|
NVD-CWE-Other
|
CVE-2000-0741
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272844
|
10.0 |
HIGH
|
university_of_minnesota
|
gopherd
|
Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.
|
NVD-CWE-Other
|
CVE-2000-0743
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272845
|
7.5 |
HIGH
|
francisco_burzi
|
php-nuke
|
admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd paramete…
|
NVD-CWE-Other
|
CVE-2000-0745
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272846
|
4.6 |
MEDIUM
|
openldap
|
openldap
|
OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse.
|
NVD-CWE-Other
|
CVE-2000-0748
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272847
|
7.5 |
HIGH
|
netbsd openbsd redhat
|
netbsd openbsd linux
|
mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-2000-0751
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272848
|
7.2 |
HIGH
|
freebsd
|
freebsd
|
Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.
|
NVD-CWE-Other
|
CVE-2000-0752
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272849
|
2.1 |
LOW
|
hp
|
openview_network_node_manager
|
Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.
|
NVD-CWE-Other
|
CVE-2000-0754
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
272850
|
4.6 |
MEDIUM
|
hp
|
openview_network_node_manager
|
Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2000-0755
|
2008-09-6 05:21 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|