Unknown · CVSS Not scored
Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to cause a denial of service by sending a large user name to the user dialog running on port 8002.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the "Linux kernel setuid/setcap vulnerability."
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Selena Sol WebBanner 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in HP Openview Network Node Manager 6.1 allows remote attackers to execute arbitrary commands via the Alarm service (OVALARMSRV) on port 2345.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
BRU backup software allows local users to append data to arbitrary files by specifying an alternate configuration file with the BRUEXECLOG environmental variable.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
xinetd 2.1.8.x does not properly restrict connections if hostnames are used for access control and the connecting host does not have a reverse DNS entry.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
JSP sample files in Allaire JRun 2.3.x allow remote attackers to access arbitrary files (e.g. via viewsource.jsp) or obtain configuration information.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
CUPS (Common Unix Printing System) 1.04 and earlier does not properly delete request files, which allows a remote attacker to cause a denial of service.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Race condition in MDaemon 2.8.5.0 POP server allows local users to cause a denial of service by entering a UIDL command and quickly exiting the server.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Kerberos 4 KDC program does not properly check for null termination of AUTH_MSG_KDC_REQUEST requests, which allows remote attackers to cause a denial of service via a malformed request.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denial of service, and local users to gain root privileges.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Ceilidh allows remote attackers to cause a denial of service via a large number of POST requests.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder Request" vulnerability.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Small HTTP Server ver 3.06 contains a memory corruption bug causing a memory overflow. The overflowed buffer crashes into a Structured Exception Handler resulting in a Denial of Service.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession ID's via the SessionServlet servlet.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Net Tools PKI Server does not properly restrict access to remote attackers when the XUDA template files do not contain absolute pathnames for other files.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a malformed IPP request.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
RSA ACE/Server allows remote attackers to cause a denial of service by flooding the server's authentication request port with UDP packets, which causes the server to crash.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long string.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a CGI POST request.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Check Point Firewall-1 allows remote attackers to cause a denial of service by sending a large number of malformed fragmented IP packets.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Net Tools PKI Server allows remote attackers to cause a denial of service via a long HTTP request.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
When configured to store configuration information in an LDAP directory, Shiva Access Manager 5.0.0 stores the root DN (Distinguished Name) name and password in cleartext in a file that is world readable, which allows local users to compromise the LDAP server.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The apsfilter software in the FreeBSD ports package does not properly read user filter configurations, which allows local users to execute commands as the lpd user.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
AIX cdmount allows local users to gain root privileges via shell metacharacters.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in KDE Kmail allows a remote attacker to cause a denial of service via an attachment with a long file name.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in WebShield SMTP 4.5.44 allows remote attackers to execute arbitrary commands via a long configuration parameter to the WebShield remote management service.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server script.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to modify SNMP configuration or gain privileges.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Intel express 8100 ISDN router allows remote attackers to cause a denial of service via oversized or fragmented ICMP packets.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Linux splitvt 1.6.3 and earlier allows local users to gain root privileges via a long password in the screen locking function.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
IMP does not remove files properly if the MSWordView application quits, which allows local users to cause a denial of service by filling up the disk space by requesting a large number of documents and prematurely stopping the request.
Published Oct 13, 2000 · Updated Aug 8, 2024