Unknown · CVSS Not scored
The WebShield SMTP Management Tool version 4.5.44 does not properly restrict access to the management port when an IP address does not resolve to a hostname, which allows remote attackers to access the configuration via the GET_CONFIG command.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may produce predictable keys.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
UltraBoard 1.6 and other versions allow remote attackers to cause a denial of service by referencing UltraBoard in the Session parameter, which causes UltraBoard to fork copies of itself.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a dot dot (..) and ends with a null byte.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows remote attackers to cause a denial of service.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary commands via shell metacharacters.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The knfsd NFS server in Linux kernel 2.2.x allows remote attackers to cause a denial of service via a negative size value.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environmental variable.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Atrium Mercur Mail Server 3.2 allows local attackers to read other user's email and create arbitrary files via a dot dot (..) attack.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Ipswitch IMAIL server 6.02 and earlier allows remote attackers to cause a denial of service via the AUTH CRAM-MD5 command.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Panda Security 3.0 allows users to uninstall the Panda software via its Add/Remove Programs applet.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a .. (dot dot) attack.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long URL.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
PCAnywhere allows remote attackers to cause a denial of service by terminating the connection before PCAnywhere provides a login prompt.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in the web server for Norton AntiVirus for Internet Email Gateways allows remote attackers to cause a denial of service via a long URL.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Infopop Ultimate Bulletin Board (UBB) allows remote attackers to execute commands via shell metacharacters in the topic hidden field.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Pocsag POC32 program does not properly prevent remote users from accessing its server port, even if the option has been disabled.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain privileges.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Webspeed configuration program does not properly disable access to the WSMadmin utility, which allows remote attackers to gain privileges via wsisa.dll.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to cause a denial of service via a malformed URL that includes shell metacharacters.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login name.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a denial of service by repeating multiple HELO, MAIL FROM, RCPT TO, and DATA commands in the same session.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra < in front of the SCRIPT tag.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request.
Published Oct 13, 2000 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in SCO scohelp program allows remote attackers to execute commands.
Published Oct 13, 2000 · Updated Aug 8, 2024