Unknown · CVSS Not scored
Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The CGI counter 4.0.7 by George Burgyan allows remote attackers to execute arbitrary commands via shell metacharacters.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in FreeBSD libmytinfo library allows local users to execute commands via a long TERMCAP environmental variable.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The makelev program in the golddig game from the FreeBSD ports collection allows local users to overwrite arbitrary files.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in INN 2.2.1 and earlier allows remote attackers to cause a denial of service via a maliciously formatted article.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the container object with a publishing rule.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
AppleShare IP 6.1 and later allows a remote attacker to read potentially sensitive information via an invalid range request to the web server.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in Caldera rmt command in the dump package 0.4b4 allows a local user to gain root privileges.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
A debugging feature in NetworkICE ICEcap 2.0.23 and earlier is enabled, which allows a remote attacker to bypass the weak authentication and post unencrypted events.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disabled NIS accounts.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
HP-UX 11.04 VirtualVault (VVOS) sends data to unprivileged processes via an interface that has multiple aliased IP addresses.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
BeOS allows remote attackers to cause a denial of service via malformed packets whose length field is less than the length of the headers.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Allaire Forums 2.0.5 allows remote attackers to bypass access restrictions to secure conferences via the rightAccessAllForums or rightModerateAllForums variables.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-info and ?wp-cs-dump.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file or using other methods.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverrc file.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.
Published Jul 12, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.
Published Jul 12, 2000 · Updated Aug 8, 2024