Unknown · CVSS Not scored
Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Denial of service in AIX ptrace system call allows local users to crash the system.
Published Jan 18, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The KDE klock program allows local users to unlock a session using malformed input.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account without a password.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A malicious Palace server can force a client to execute arbitrary programs.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The open() function in FreeBSD allows local attackers to write to arbitrary files.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
mmap function in BSD allows local attackers in the kmem group to modify memory through devices.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Remote command execution in Microsoft Internet Explorer using .lnk and .url files.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.
Published Jan 18, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.
Published Jan 18, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
cfingerd lists all users on a system via search.**@target.
Published Jan 18, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.
Published Jan 4, 2000 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.
Published Jan 18, 2000 · Updated Aug 1, 2024