Unknown · CVSS Not scored
The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Savant web server allows remote attackers to read source code of CGI scripts via a GET request that does not include the HTTP version number.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Norton Antivirus for Exchange (NavExchange) allows remote attackers to cause a denial of service via a .zip file that contains long file names.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in MDBMS database server allows remote attackers to execute arbitrary commands via a long string.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
In some cases, Norton Antivirus for Exchange (NavExchange) enters a "fail-open" state which allows viruses to pass through the server.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Secure Locate (slocate) in Red Hat Linux allows local users to gain privileges via a malformed configuration file that is specified in the LOCATE_PATH environmental variable.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Novell BorderManager 3.0 and 3.5 allows remote attackers to bypass URL filtering by encoding characters in the requested URL.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Cisco TACACS+ tac_plus server allows remote attackers to cause a denial of service via a malformed packet with a long length field.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the "Stored Procedure Permissions" vulnerability.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents SawMill attempts to parse as configuration commands.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ISC DHCP client program dhclient allows remote attackers to execute arbitrary commands via shell metacharacters.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in iMesh 1.02 allows remote attackers to execute arbitrary commands via a long string to the iMesh port.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in cvconnect in SGI IRIX WorkShop allows local users to overwrite arbitrary files.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legitimate connections.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uucp.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in HP TurboIMAGE DBUTIL allows local users to gain additional privileges via DBUTIL.PUB.SYS.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Race condition in IPFilter firewall 3.4.3 and earlier, when configured with overlapping "return-rst" and "keep state" rules, allows remote attackers to bypass access restrictions.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Dalnet IRC server 4.6.5 allows remote attackers to cause a denial of service or execute arbitrary commands via the SUMMON command.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros) to the SMTP Security Server proxy.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
makewhatis in Linux man package allows local users to overwrite files via a symlink attack.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Kerberos 4 KDC program improperly frees memory twice (aka "double-free"), which allows remote attackers to cause a denial of service.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Windows 2000 allows a local user process to access another user's desktop within the same windows station, aka the "Desktop Separation" vulnerability.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
A FreeBSD patch for SSH on 2000-01-14 configures ssh to listen on port 722 as well as port 22, which might allow remote attackers to access SSH through port 722 even if port 22 is otherwise filtered.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to execute arbitrary commands via a long GET request.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
IRIX crontab creates temporary files with predictable file names and with the umask of the user, which could allow local users to modify another user's crontab file as it is being edited.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in innd 2.2.2 allows remote attackers to execute arbitrary commands via a cancel request containing a long message ID.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service by authenticating with a user name that does not exist or does not have a shadow password.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in WebBBS 1.15 allows remote attackers to execute arbitrary commands via a long HTTP GET request.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
LocalWEB HTTP server 1.2.0 allows remote attackers to cause a denial of service via a long GET request.
Published Oct 13, 2000 · Updated Aug 8, 2024