|
312651
|
2.1 |
LOW
|
suse
|
suse_linux
|
aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa…
|
NVD-CWE-Other
|
CVE-2000-0293
|
2008-09-11 04:04 |
2000-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312652
|
7.2 |
HIGH
|
jim_housley
|
healthd
|
Buffer overflow in healthd for FreeBSD allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2000-0294
|
2008-09-11 04:04 |
2000-04-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312653
|
7.2 |
HIGH
|
michael_a._gumienny
|
fcheck
|
fcheck allows local users to gain privileges by embedding shell metacharacters into file names that are processed by fcheck.
|
NVD-CWE-Other
|
CVE-2000-0296
|
2008-09-11 04:04 |
2000-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312654
|
6.4 |
MEDIUM
|
allaire
|
forums
|
Allaire Forums 2.0.5 allows remote attackers to bypass access restrictions to secure conferences via the rightAccessAllForums or rightModerateAllForums variables.
|
NVD-CWE-Other
|
CVE-2000-0297
|
2008-09-11 04:04 |
2000-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312655
|
5.0 |
MEDIUM
|
apple
|
webobjects
|
Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept.
|
NVD-CWE-Other
|
CVE-2000-0299
|
2008-09-11 04:04 |
2000-04-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312656
|
6.4 |
MEDIUM
|
id_software
|
quake_3_arena
|
Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.
|
NVD-CWE-Other
|
CVE-2000-0303
|
2008-09-11 04:04 |
2000-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312657
|
2.1 |
LOW
|
openbsd
|
openbsd
|
The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a denial of service.
|
NVD-CWE-Other
|
CVE-2000-0309
|
2008-09-11 04:04 |
2001-03-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312658
|
5.0 |
MEDIUM
|
openbsd
|
openbsd
|
IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets.
|
NVD-CWE-Other
|
CVE-2000-0310
|
2008-09-11 04:04 |
2001-03-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312659
|
4.6 |
MEDIUM
|
openbsd
|
openbsd
|
Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations.
|
NVD-CWE-Other
|
CVE-2000-0313
|
2008-09-11 04:04 |
2001-03-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312660
|
7.5 |
HIGH
|
atrium_software
|
mercur_mailserver
|
Atrium Mercur Mail Server 3.2 allows local attackers to read other user's email and create arbitrary files via a dot dot (..) attack.
|
NVD-CWE-Other
|
CVE-2000-0318
|
2008-09-11 04:04 |
2000-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312661
|
5.0 |
MEDIUM
|
icradius
|
icradius
|
Buffer overflow in IC Radius package allows a remote attacker to cause a denial of service via a long user name.
|
NVD-CWE-Other
|
CVE-2000-0321
|
2008-09-11 04:04 |
2000-04-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312662
|
5.0 |
MEDIUM
|
on_technology
|
meeting_maker
|
Meeting Maker uses weak encryption (a polyalphabetic substitution cipher) for passwords, which allows remote attackers to sniff and decrypt passwords for Meeting Maker accounts.
|
NVD-CWE-Other
|
CVE-2000-0326
|
2008-09-11 04:04 |
2000-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312663
|
2.1 |
LOW
|
allaire
|
spectra
|
The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the cont…
|
NVD-CWE-Other
|
CVE-2000-0334
|
2008-09-11 04:04 |
2000-04-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312664
|
7.5 |
HIGH
|
gnu isc
|
glibc bind
|
The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.
|
NVD-CWE-Other
|
CVE-2000-0335
|
2008-09-11 04:04 |
2000-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312665
|
2.1 |
LOW
|
openldap mandrakesoft redhat turbolinux
|
openldap mandrake_linux linux turbolinux
|
Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2000-0336
|
2008-09-11 04:04 |
2000-04-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312666
|
5.0 |
MEDIUM
|
networkice
|
icecap_manager
|
A debugging feature in NetworkICE ICEcap 2.0.23 and earlier is enabled, which allows a remote attacker to bypass the weak authentication and post unencrypted events.
|
NVD-CWE-Other
|
CVE-2000-0350
|
2008-09-11 04:04 |
2000-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312667
|
10.0 |
HIGH
|
university_of_washington
|
pine
|
Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.
|
NVD-CWE-Other
|
CVE-2000-0353
|
2008-09-11 04:04 |
1999-06-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312668
|
7.5 |
HIGH
|
bent_bagger redhat suse
|
pbpg linux suse_linux
|
pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.
|
NVD-CWE-Other
|
CVE-2000-0355
|
2008-09-11 04:04 |
1999-08-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312669
|
4.6 |
MEDIUM
|
redhat
|
linux
|
Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disabled NIS accounts.
|
NVD-CWE-Other
|
CVE-2000-0356
|
2008-09-11 04:04 |
1999-10-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312670
|
7.5 |
HIGH
|
redhat
|
linux
|
ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.
|
NVD-CWE-Other
|
CVE-2000-0357
|
2008-09-11 04:04 |
1999-12-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312671
|
5.0 |
MEDIUM
|
redhat
|
linux
|
ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.
|
NVD-CWE-Other
|
CVE-2000-0358
|
2008-09-11 04:04 |
1999-12-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312672
|
10.0 |
HIGH
|
acme_labs
|
thttpd
|
Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.
|
NVD-CWE-Other
|
CVE-2000-0359
|
2008-09-11 04:04 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312673
|
5.0 |
MEDIUM
|
isc
|
inn
|
Buffer overflow in INN 2.2.1 and earlier allows remote attackers to cause a denial of service via a maliciously formatted article.
|
NVD-CWE-Other
|
CVE-2000-0360
|
2008-09-11 04:04 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312674
|
2.1 |
LOW
|
suse
|
suse_linux
|
The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password inform…
|
NVD-CWE-Other
|
CVE-2000-0361
|
2008-09-11 04:04 |
1999-12-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312675
|
7.2 |
HIGH
|
suse
|
suse_linux
|
Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2000-0362
|
2008-09-11 04:04 |
1999-10-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312676
|
6.2 |
MEDIUM
|
suse
|
suse_linux
|
Linux cdwtools 093 and earlier allows local users to gain root privileges via the /tmp directory.
|
NVD-CWE-Other
|
CVE-2000-0363
|
2008-09-11 04:04 |
1999-10-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312677
|
2.1 |
LOW
|
debian
|
debian_linux
|
dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.
|
NVD-CWE-Other
|
CVE-2000-0366
|
2008-09-11 04:04 |
1999-12-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312678
|
7.2 |
HIGH
|
michael_jennings
|
eterm
|
Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.
|
NVD-CWE-Other
|
CVE-2000-0367
|
2008-09-11 04:04 |
1999-02-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312679
|
5.0 |
MEDIUM
|
caldera
|
openlinux
|
The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows remote attackers to cause a denial of service.
|
NVD-CWE-Other
|
CVE-2000-0369
|
2008-09-11 04:04 |
1999-10-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312680
|
10.0 |
HIGH
|
caldera
|
openlinux
|
The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.
|
NVD-CWE-Other
|
CVE-2000-0370
|
2008-09-11 04:04 |
1999-01-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312681
|
1.2 |
LOW
|
kde
|
kde
|
The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2000-0371
|
2008-09-11 04:04 |
1999-03-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312682
|
2.1 |
LOW
|
freebsd
|
freebsd
|
The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files.
|
NVD-CWE-Other
|
CVE-2000-0375
|
2008-09-11 04:04 |
2001-03-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312683
|
10.0 |
HIGH
|
i-drive
|
filo
|
Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request.
|
NVD-CWE-Other
|
CVE-2000-0376
|
2008-09-11 04:04 |
2000-06-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312684
|
7.2 |
HIGH
|
redhat
|
linux
|
The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allow…
|
NVD-CWE-Other
|
CVE-2000-0378
|
2008-09-11 04:04 |
2000-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312685
|
2.6 |
LOW
|
allaire
|
clustercats
|
ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site.
|
NVD-CWE-Other
|
CVE-2000-0382
|
2008-09-11 04:04 |
2000-05-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312686
|
5.0 |
MEDIUM
|
filemaker
|
filemaker
|
FileMaker Pro 5 Web Companion allows remote attackers to bypass Field-Level database security restrictions via the XML publishing or email capabilities.
|
NVD-CWE-Other
|
CVE-2000-0385
|
2008-09-11 04:04 |
2000-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312687
|
7.5 |
HIGH
|
filemaker
|
filemaker
|
FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email.
|
NVD-CWE-Other
|
CVE-2000-0386
|
2008-09-11 04:04 |
2000-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312688
|
2.1 |
LOW
|
alexander_siegel
|
golddig
|
The makelev program in the golddig game from the FreeBSD ports collection allows local users to overwrite arbitrary files.
|
NVD-CWE-Other
|
CVE-2000-0387
|
2008-09-11 04:04 |
2000-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312689
|
7.5 |
HIGH
|
freebsd
|
freebsd
|
Buffer overflow in FreeBSD libmytinfo library allows local users to execute commands via a long TERMCAP environmental variable.
|
NVD-CWE-Other
|
CVE-2000-0388
|
2008-09-11 04:04 |
1990-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312690
|
7.2 |
HIGH
|
kde
|
kde
|
The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program …
|
NVD-CWE-Other
|
CVE-2000-0393
|
2008-09-11 04:04 |
2000-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312691
|
5.0 |
MEDIUM
|
pacific_software
|
carello
|
The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP fil…
|
NVD-CWE-Other
|
CVE-2000-0396
|
2008-09-11 04:04 |
2000-05-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312692
|
5.0 |
MEDIUM
|
seattle_lab_software
|
emurl
|
The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.
|
NVD-CWE-Other
|
CVE-2000-0397
|
2008-09-11 04:04 |
2000-05-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312693
|
10.0 |
HIGH
|
rockliffe
|
mailsite
|
Buffer overflow in wconsole.dll in Rockliffe MailSite Management Agent allows remote attackers to execute arbitrary commands via a long query_string parameter in the HTTP GET request.
|
NVD-CWE-Other
|
CVE-2000-0398
|
2008-09-11 04:04 |
2000-05-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312694
|
5.0 |
MEDIUM
|
alt-n
|
mdaemon
|
Buffer overflow in MDaemon POP server allows remote attackers to cause a denial of service via a long user name.
|
NVD-CWE-Other
|
CVE-2000-0399
|
2008-09-11 04:04 |
2000-05-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312695
|
10.0 |
HIGH
|
atstake
|
antisniff
|
Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.
|
NVD-CWE-Other
|
CVE-2000-0405
|
2008-09-11 04:04 |
2000-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312696
|
2.6 |
LOW
|
netscape
|
communicator
|
Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web…
|
NVD-CWE-Other
|
CVE-2000-0406
|
2008-09-11 04:04 |
2000-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312697
|
3.7 |
LOW
|
netscape
|
communicator
|
Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.
|
NVD-CWE-Other
|
CVE-2000-0409
|
2008-09-11 04:04 |
2000-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312698
|
5.0 |
MEDIUM
|
allaire
|
coldfusion_server
|
ColdFusion Server 4.5.1 allows remote attackers to cause a denial of service by making repeated requests to a CFCACHE tagged cache file that is not stored in memory.
|
NVD-CWE-Other
|
CVE-2000-0410
|
2008-09-11 04:04 |
2000-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312699
|
7.5 |
HIGH
|
napster
|
knapster
|
The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname …
|
NVD-CWE-Other
|
CVE-2000-0412
|
2008-09-11 04:04 |
1999-05-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312700
|
4.6 |
MEDIUM
|
hp
|
hp-ux vvos
|
Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables.
|
NVD-CWE-Other
|
CVE-2000-0414
|
2008-09-11 04:04 |
2000-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|