| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2000-0884 | 0.10 | — | 0.84 | Dec 19, 2000 | IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability. | |||
| CVE-2000-0885 | 0.02 | — | 0.25 | Dec 19, 2000 | Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates. | |||
| CVE-2000-0886 | 0.10 | — | 0.89 | Dec 19, 2000 | IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability. | |||
| CVE-2000-0887 | 0.04 | — | 0.17 | Dec 19, 2000 | named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the "zxfr bug." | |||
| CVE-2000-0888 | 0.01 | — | 0.16 | Dec 19, 2000 | named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the "srv bug." | |||
| CVE-2000-0900 | 0.00 | — | 0.01 | Dec 19, 2000 | Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack. | |||
| CVE-2000-0901 | 0.03 | — | 0.00 | Dec 19, 2000 | Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters in the vbell_msg initialization variable. | |||
| CVE-2000-0902 | 0.00 | — | 0.01 | Dec 19, 2000 | getalbum.php in PhotoAlbum before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |||
| CVE-2000-0903 | 0.03 | — | 0.05 | Dec 19, 2000 | Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |||
| CVE-2000-0904 | 0.03 | — | 0.05 | Dec 19, 2000 | Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information. | |||
| CVE-2000-0905 | 0.00 | — | 0.01 | Dec 19, 2000 | QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page. | |||
| CVE-2000-0906 | 0.04 | — | 0.09 | Dec 19, 2000 | Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the category or format parameters. | |||
| CVE-2000-0907 | 0.00 | — | 0.02 | Dec 19, 2000 | EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands. | |||
| CVE-2000-0908 | 0.04 | — | 0.09 | Dec 19, 2000 | BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Authorization or Referer MIME headers in the HTTP request. | |||
| CVE-2000-0909 | 0.04 | — | 0.11 | Dec 19, 2000 | Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header. | |||
| CVE-2000-0910 | 0.00 | — | 0.00 | Dec 19, 2000 | Horde library 1.02 allows attackers to execute arbitrary commands via shell metacharacters in the "from" address. | |||
| CVE-2000-0911 | 0.00 | — | 0.01 | Dec 19, 2000 | IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment. | |||
| CVE-2000-0912 | 0.03 | — | 0.06 | Dec 19, 2000 | MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter. | |||
| CVE-2000-0914 | 0.04 | — | 0.07 | Dec 19, 2000 | OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests. | |||
| CVE-2000-0915 | 0.00 | — | 0.01 | Dec 19, 2000 | fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name. | |||
| CVE-2000-0916 | 0.04 | — | 0.08 | Dec 19, 2000 | FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections. | |||
| CVE-2000-0917 | 0.10 | — | 0.86 | Dec 19, 2000 | Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. | |||
| CVE-2000-0918 | 0.00 | — | 0.00 | Dec 19, 2000 | Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters. | |||
| CVE-2000-0919 | 0.03 | — | 0.05 | Dec 19, 2000 | Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |||
| CVE-2000-0920 | 0.04 | — | 0.07 | Dec 19, 2000 | Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "." | |||
| CVE-2000-0921 | 0.03 | — | 0.05 | Dec 19, 2000 | Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter. | |||
| CVE-2000-0922 | 0.03 | — | 0.05 | Dec 19, 2000 | Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter. | |||
| CVE-2000-0923 | 0.00 | — | 0.02 | Dec 19, 2000 | authenticate.cgi CGI program in Aplio PRO allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter. | |||
| CVE-2000-0924 | 0.03 | — | 0.05 | Dec 19, 2000 | Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catigory" parameter. | |||
| CVE-2000-0925 | 0.03 | — | 0.06 | Dec 19, 2000 | The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information. | |||
| CVE-2000-0926 | 0.04 | — | 0.07 | Dec 19, 2000 | SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable. | |||
| CVE-2000-0927 | 0.00 | — | 0.00 | Dec 19, 2000 | WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions. | |||
| CVE-2000-0928 | 0.00 | — | 0.00 | Dec 19, 2000 | WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares. | |||
| CVE-2000-0929 | 0.05 | — | 0.21 | Dec 19, 2000 | Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability. | |||
| CVE-2000-0930 | 0.03 | — | 0.05 | Dec 19, 2000 | Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch. | |||
| CVE-2000-0931 | 0.00 | — | 0.01 | Dec 19, 2000 | Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data. | |||
| CVE-2000-0932 | 0.00 | — | 0.01 | Dec 19, 2000 | MAILsweeper for SMTP 3.x does not properly handle corrupt CDA documents in a ZIP file and hangs, which allows remote attackers to cause a denial of service. | |||
| CVE-2000-0933 | 0.00 | — | 0.03 | Dec 19, 2000 | The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability. | |||
| CVE-2000-0934 | 0.00 | — | 0.00 | Dec 19, 2000 | Glint in Red Hat Linux 5.2 allows local users to overwrite arbitrary files and cause a denial of service via a symlink attack. | |||
| CVE-2000-0935 | 0.03 | — | 0.00 | Dec 19, 2000 | Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file. | |||
| CVE-2000-0936 | 0.03 | — | 0.01 | Dec 19, 2000 | Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords. | |||
| CVE-2000-0937 | 0.03 | — | 0.04 | Dec 19, 2000 | Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks. | |||
| CVE-2000-0938 | 0.00 | — | 0.01 | Dec 19, 2000 | Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server. | |||
| CVE-2000-0939 | 0.00 | — | 0.01 | Dec 19, 2000 | Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart. | |||
| CVE-2000-0940 | 0.00 | — | 0.01 | Dec 19, 2000 | Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter. | |||
| CVE-2000-0941 | 0.04 | — | 0.13 | Dec 19, 2000 | Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter. | |||
| CVE-2000-0942 | 0.06 | — | 0.37 | Dec 19, 2000 | The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability. | |||
| CVE-2000-0943 | 0.00 | — | 0.02 | Dec 19, 2000 | Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command. | |||
| CVE-2000-0944 | Cri | 0.68 | 9.8 | 0.11 | Dec 19, 2000 | CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password. | ||
| CVE-2000-0945 | 0.10 | — | 0.88 | Dec 19, 2000 | The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory. |
- CVE-2000-0884Dec 19, 2000risk 0.10cvss —epss 0.84
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.
- CVE-2000-0885Dec 19, 2000risk 0.02cvss —epss 0.25
Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates.
- CVE-2000-0886Dec 19, 2000risk 0.10cvss —epss 0.89
IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.
- CVE-2000-0887Dec 19, 2000risk 0.04cvss —epss 0.17
named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the "zxfr bug."
- CVE-2000-0888Dec 19, 2000risk 0.01cvss —epss 0.16
named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the "srv bug."
- CVE-2000-0900Dec 19, 2000risk 0.00cvss —epss 0.01
Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.
- CVE-2000-0901Dec 19, 2000risk 0.03cvss —epss 0.00
Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters in the vbell_msg initialization variable.
- CVE-2000-0902Dec 19, 2000risk 0.00cvss —epss 0.01
getalbum.php in PhotoAlbum before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
- CVE-2000-0903Dec 19, 2000risk 0.03cvss —epss 0.05
Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
- CVE-2000-0904Dec 19, 2000risk 0.03cvss —epss 0.05
Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information.
- CVE-2000-0905Dec 19, 2000risk 0.00cvss —epss 0.01
QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page.
- CVE-2000-0906Dec 19, 2000risk 0.04cvss —epss 0.09
Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the category or format parameters.
- CVE-2000-0907Dec 19, 2000risk 0.00cvss —epss 0.02
EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands.
- CVE-2000-0908Dec 19, 2000risk 0.04cvss —epss 0.09
BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Authorization or Referer MIME headers in the HTTP request.
- CVE-2000-0909Dec 19, 2000risk 0.04cvss —epss 0.11
Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.
- CVE-2000-0910Dec 19, 2000risk 0.00cvss —epss 0.00
Horde library 1.02 allows attackers to execute arbitrary commands via shell metacharacters in the "from" address.
- CVE-2000-0911Dec 19, 2000risk 0.00cvss —epss 0.01
IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment.
- CVE-2000-0912Dec 19, 2000risk 0.03cvss —epss 0.06
MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter.
- CVE-2000-0914Dec 19, 2000risk 0.04cvss —epss 0.07
OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.
- CVE-2000-0915Dec 19, 2000risk 0.00cvss —epss 0.01
fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.
- CVE-2000-0916Dec 19, 2000risk 0.04cvss —epss 0.08
FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.
- CVE-2000-0917Dec 19, 2000risk 0.10cvss —epss 0.86
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
- CVE-2000-0918Dec 19, 2000risk 0.00cvss —epss 0.00
Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.
- CVE-2000-0919Dec 19, 2000risk 0.03cvss —epss 0.05
Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.
- CVE-2000-0920Dec 19, 2000risk 0.04cvss —epss 0.07
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."
- CVE-2000-0921Dec 19, 2000risk 0.03cvss —epss 0.05
Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.
- CVE-2000-0922Dec 19, 2000risk 0.03cvss —epss 0.05
Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter.
- CVE-2000-0923Dec 19, 2000risk 0.00cvss —epss 0.02
authenticate.cgi CGI program in Aplio PRO allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter.
- CVE-2000-0924Dec 19, 2000risk 0.03cvss —epss 0.05
Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catigory" parameter.
- CVE-2000-0925Dec 19, 2000risk 0.03cvss —epss 0.06
The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.
- CVE-2000-0926Dec 19, 2000risk 0.04cvss —epss 0.07
SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable.
- CVE-2000-0927Dec 19, 2000risk 0.00cvss —epss 0.00
WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions.
- CVE-2000-0928Dec 19, 2000risk 0.00cvss —epss 0.00
WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares.
- CVE-2000-0929Dec 19, 2000risk 0.05cvss —epss 0.21
Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.
- CVE-2000-0930Dec 19, 2000risk 0.03cvss —epss 0.05
Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.
- CVE-2000-0931Dec 19, 2000risk 0.00cvss —epss 0.01
Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data.
- CVE-2000-0932Dec 19, 2000risk 0.00cvss —epss 0.01
MAILsweeper for SMTP 3.x does not properly handle corrupt CDA documents in a ZIP file and hangs, which allows remote attackers to cause a denial of service.
- CVE-2000-0933Dec 19, 2000risk 0.00cvss —epss 0.03
The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability.
- CVE-2000-0934Dec 19, 2000risk 0.00cvss —epss 0.00
Glint in Red Hat Linux 5.2 allows local users to overwrite arbitrary files and cause a denial of service via a symlink attack.
- CVE-2000-0935Dec 19, 2000risk 0.03cvss —epss 0.00
Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.
- CVE-2000-0936Dec 19, 2000risk 0.03cvss —epss 0.01
Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords.
- CVE-2000-0937Dec 19, 2000risk 0.03cvss —epss 0.04
Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks.
- CVE-2000-0938Dec 19, 2000risk 0.00cvss —epss 0.01
Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server.
- CVE-2000-0939Dec 19, 2000risk 0.00cvss —epss 0.01
Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart.
- CVE-2000-0940Dec 19, 2000risk 0.00cvss —epss 0.01
Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.
- CVE-2000-0941Dec 19, 2000risk 0.04cvss —epss 0.13
Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.
- CVE-2000-0942Dec 19, 2000risk 0.06cvss —epss 0.37
The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
- CVE-2000-0943Dec 19, 2000risk 0.00cvss —epss 0.02
Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command.
- risk 0.68cvss 9.8epss 0.11
CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.
- CVE-2000-0945Dec 19, 2000risk 0.10cvss —epss 0.88
The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.