VYPR

CVEs

335,117 total · page 6653 of 6,703

  • CVE-2000-0946Dec 19, 2000
    risk 0.00cvss epss 0.00

    Compaq Easy Access Keyboard software 1.3 does not properly disable access to custom buttons when the screen is locked, which could allow an attacker to gain privileges or execute programs without authorization.

  • CVE-2000-0947Dec 19, 2000
    risk 0.00cvss epss 0.01

    Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.

  • CVE-2000-0948Dec 19, 2000
    risk 0.00cvss epss 0.00

    GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.

  • CVE-2000-0949Dec 19, 2000
    risk 0.03cvss epss 0.00

    Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.

  • CVE-2000-0950Dec 19, 2000
    risk 0.00cvss epss 0.00

    Format string vulnerability in x-gw in TIS Firewall Toolkit (FWTK) allows local users to execute arbitrary commands via a malformed display name.

  • CVE-2000-0951Dec 19, 2000
    risk 0.07cvss epss 0.49

    A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.

  • CVE-2000-0952Dec 19, 2000
    risk 0.00cvss epss 0.02

    global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters.

  • CVE-2000-0953Dec 19, 2000
    risk 0.03cvss epss 0.06

    Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection.

  • CVE-2000-0954Dec 19, 2000
    risk 0.00cvss epss 0.00

    Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server.

  • CVE-2000-0955Dec 19, 2000
    risk 0.04cvss epss 0.07

    Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.

  • CVE-2000-0956Dec 19, 2000
    risk 0.00cvss epss 0.00

    cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.

  • CVE-2000-0957Dec 19, 2000
    risk 0.00cvss epss 0.00

    The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.

  • CVE-2000-0958Dec 19, 2000
    risk 0.03cvss epss 0.06

    HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.

  • CVE-2000-0959Dec 19, 2000
    risk 0.00cvss epss 0.00

    glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.

  • CVE-2000-0960Dec 19, 2000
    risk 0.00cvss epss 0.01

    The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.

  • CVE-2000-0961Dec 19, 2000
    risk 0.00cvss epss 0.01

    Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.

  • CVE-2000-0962Dec 19, 2000
    risk 0.00cvss epss 0.01

    The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.

  • CVE-2000-0963Dec 19, 2000
    risk 0.00cvss epss 0.00

    Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.

  • CVE-2000-0964Dec 19, 2000
    risk 0.00cvss epss 0.02

    Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.

  • CVE-2000-0965Dec 19, 2000
    risk 0.00cvss epss 0.01

    The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization).

  • CVE-2000-0966Dec 19, 2000
    risk 0.00cvss epss 0.00

    Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.

  • CVE-2000-0967Dec 19, 2000
    risk 0.05cvss epss 0.27

    PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.

  • CVE-2000-0968Dec 19, 2000
    risk 0.00cvss epss 0.03

    Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.

  • CVE-2000-0969Dec 19, 2000
    risk 0.00cvss epss 0.03

    Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.

  • CVE-2000-0970Dec 19, 2000
    risk 0.03cvss epss 0.38

    IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.

  • CVE-2000-0971Dec 19, 2000
    risk 0.04cvss epss 0.12

    Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.

  • CVE-2000-0972MedDec 19, 2000
    risk 0.39cvss 5.5epss 0.02

    HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.

  • CVE-2000-0973Dec 19, 2000
    risk 0.04cvss epss 0.12

    Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.

  • CVE-2000-0974Dec 19, 2000
    risk 0.00cvss epss 0.02

    GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.

  • CVE-2000-0975Dec 19, 2000
    risk 0.04cvss epss 0.07

    Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack.

  • CVE-2000-0976Dec 19, 2000
    risk 0.03cvss epss 0.01

    Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.

  • CVE-2000-0977Dec 19, 2000
    risk 0.03cvss epss 0.04

    mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.

  • CVE-2000-0978Dec 19, 2000
    risk 0.00cvss epss 0.01

    bbd server in Big Brother System and Network Monitor before 1.5c2 allows remote attackers to execute arbitrary commands via the "&" shell metacharacter.

  • CVE-2000-0979Dec 19, 2000
    risk 0.04cvss epss 0.12

    File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.

  • CVE-2000-0980Dec 19, 2000
    risk 0.01cvss epss 0.07

    NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network.

  • CVE-2000-0981Dec 19, 2000
    risk 0.00cvss epss 0.01

    MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.

  • CVE-2000-0982Dec 19, 2000
    risk 0.01cvss epss 0.10

    Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability.

  • CVE-2000-0983Dec 19, 2000
    risk 0.05cvss epss 0.23

    Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability.

  • CVE-2000-0984Dec 19, 2000
    risk 0.06cvss epss 0.40

    The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string.

  • CVE-2000-0985Dec 19, 2000
    risk 0.03cvss epss 0.06

    Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command.

  • CVE-2000-0986Dec 19, 2000
    risk 0.00cvss epss 0.00

    Buffer overflow in Oracle 8.1.5 applications such as names, namesctl, onrsd, osslogin, tnslsnr, tnsping, trcasst, and trcroute possibly allow local users to gain privileges via a long ORACLE_HOME environmental variable.

  • CVE-2000-0987Dec 19, 2000
    risk 0.03cvss epss 0.00

    Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.

  • CVE-2000-0988Dec 19, 2000
    risk 0.00cvss epss 0.01

    WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access to its administrative interface and modify configuration.

  • CVE-2000-0989Dec 19, 2000
    risk 0.04cvss epss 0.12

    Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute commands via a long username.

  • CVE-2000-0990Dec 19, 2000
    risk 0.00cvss epss 0.01

    cmd5checkpw 0.21 and earlier allows remote attackers to cause a denial of service via an "SMTP AUTH" command with an unknown username.

  • CVE-2000-0991Dec 19, 2000
    risk 0.04cvss epss 0.09

    Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute arbitrary commands via a long telnet URL, aka the "HyperTerminal Buffer Overflow" vulnerability.

  • CVE-2000-0992Dec 19, 2000
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.

  • CVE-2000-0993Dec 19, 2000
    risk 0.03cvss epss 0.00

    Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.

  • CVE-2000-0994Dec 19, 2000
    risk 0.03cvss epss 0.00

    Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.

  • CVE-2000-0995Dec 19, 2000
    risk 0.00cvss epss 0.00

    Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.