VYPR

CVEs

335,110 total · page 6660 of 6,703

  • CVE-2000-0658Jul 25, 2000
    risk 0.00cvss epss 0.01

    Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the POP3 protocol.

  • CVE-2000-0659Jul 25, 2000
    risk 0.00cvss epss 0.01

    Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long user ID in a SOCKS4 CONNECT request.

  • CVE-2000-0663Jul 25, 2000
    risk 0.00cvss epss 0.01

    The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative Shell Path" vulnerability.

  • CVE-2000-0652Jul 24, 2000
    risk 0.03cvss epss 0.04

    IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.

  • CVE-2000-0644Jul 21, 2000
    risk 0.04cvss epss 0.08

    WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing.

  • CVE-2000-0645Jul 21, 2000
    risk 0.03cvss epss 0.04

    WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

  • CVE-2000-0646Jul 21, 2000
    risk 0.00cvss epss 0.01

    WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred.

  • CVE-2000-0647Jul 21, 2000
    risk 0.03cvss epss 0.04

    WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server.

  • CVE-2000-0671Jul 21, 2000
    risk 0.03cvss epss 0.05

    Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory contents, and read source code by inserting a null character (%00) to the URL.

  • CVE-2000-0621Jul 20, 2000
    risk 0.00cvss epss 0.06

    Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.

  • CVE-2000-0624Jul 20, 2000
    risk 0.04cvss epss 0.06

    Buffer overflow in Winamp 2.64 and earlier allows remote attackers to execute arbitrary commands via a long #EXTINF: extension in the M3U playlist.

  • CVE-2000-0653Jul 20, 2000
    risk 0.07cvss epss 0.47

    Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.

  • CVE-2000-0672Jul 20, 2000
    risk 0.00cvss epss 0.03

    The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.

  • CVE-2000-0615Jul 19, 2000
    risk 0.00cvss epss 0.00

    LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.

  • CVE-2000-0619Jul 19, 2000
    risk 0.00cvss epss 0.01

    Top Layer AppSwitch 2500 allows remote attackers to cause a denial of service via malformed ICMP packets.

  • CVE-2000-0622Jul 19, 2000
    risk 0.04cvss epss 0.07

    Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords" parameter.

  • CVE-2000-0636Jul 19, 2000
    risk 0.05cvss epss 0.31

    HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a malformed FTP quote command.

  • CVE-2000-0567Jul 18, 2000
    risk 0.04cvss epss 0.18

    Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability.

  • CVE-2000-0625Jul 18, 2000
    risk 0.03cvss epss 0.00

    NetZero 3.0 and earlier uses weak encryption for storing a user's login information, which allows a local user to decrypt the password.

  • CVE-2000-0626Jul 18, 2000
    risk 0.03cvss epss 0.05

    Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.

  • CVE-2000-0627Jul 18, 2000
    risk 0.00cvss epss 0.00

    BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl.

  • CVE-2000-0633Jul 18, 2000
    risk 0.00cvss epss 0.00

    Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.

  • CVE-2000-0623Jul 17, 2000
    risk 0.00cvss epss 0.03

    Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.

  • CVE-2000-0630Jul 17, 2000
    risk 0.09cvss epss 0.76

    IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.

  • CVE-2000-0632Jul 17, 2000
    risk 0.00cvss epss 0.01

    Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string.

  • CVE-2000-0665Jul 17, 2000
    risk 0.08cvss epss 0.67

    GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username.

  • CVE-2000-0666Jul 16, 2000
    risk 0.06cvss epss 0.35

    rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.

  • CVE-2000-0631Jul 14, 2000
    risk 0.04cvss epss 0.48

    An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability.

  • CVE-2000-0662Jul 14, 2000
    risk 0.02cvss epss 0.28

    Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).

  • CVE-2000-0649Jul 13, 2000
    risk 0.08cvss epss 0.63

    IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.

  • CVE-2000-0675Jul 13, 2000
    risk 0.04cvss epss 0.09

    Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long string.

  • CVE-1999-0812Jul 12, 2000
    risk 0.00cvss epss 0.00

    Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations.

  • CVE-2000-0372Jul 12, 2000
    risk 0.00cvss epss 0.00

    Vulnerability in Caldera rmt command in the dump package 0.4b4 allows a local user to gain root privileges.

  • CVE-2000-0629Jul 12, 2000
    risk 0.00cvss epss 0.02

    The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.

  • CVE-2000-0642Jul 12, 2000
    risk 0.00cvss epss 0.01

    The default configuration of WebActive HTTP Server 1.00 stores the web access log active.log in the document root, which allows remote attackers to view the logs by directly requesting the page.

  • CVE-2000-0643Jul 12, 2000
    risk 0.00cvss epss 0.01

    Buffer overflow in WebActive HTTP Server 1.00 allows remote attackers to cause a denial of service via a long URL.

  • CVE-2000-0660Jul 12, 2000
    risk 0.04cvss epss 0.07

    The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

  • CVE-2000-0670Jul 12, 2000
    risk 0.03cvss epss 0.03

    The cvsweb CGI script in CVSWeb 1.80 allows remote attackers with write access to a CVS repository to execute arbitrary commands via shell metacharacters.

  • CVE-2000-0674Jul 12, 2000
    risk 0.00cvss epss 0.01

    ftp.pl CGI program for Virtual Visions FTP browser allows remote attackers to read directories outside of the document root via a .. (dot dot) attack.

  • CVE-2000-0628Jul 11, 2000
    risk 0.00cvss epss 0.01

    The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.

  • CVE-2000-0638Jul 11, 2000
    risk 0.04cvss epss 0.07

    bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the HOSTSVC parameter.

  • CVE-2000-0648Jul 11, 2000
    risk 0.03cvss epss 0.01

    WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command before a RENAME FROM (RNFR) command.

  • CVE-2000-0650Jul 11, 2000
    risk 0.00cvss epss 0.00

    The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse.

  • CVE-2000-0654Jul 11, 2000
    risk 0.00cvss epss 0.01

    Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability.

  • CVE-2000-0669Jul 11, 2000
    risk 0.04cvss epss 0.17

    Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.

  • CVE-2000-0605Jul 10, 2000
    risk 0.00cvss epss 0.00

    Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords.

  • CVE-2000-0614Jul 10, 2000
    risk 0.00cvss epss 0.01

    Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded compressed attachments which specify absolute path names for the decompressed output.

  • CVE-2000-0635Jul 10, 2000
    risk 0.00cvss epss 0.02

    The view_page.html sample page in the MiniVend shopping cart program allows remote attackers to execute arbitrary commands via shell metacharacters.

  • CVE-2000-0661Jul 10, 2000
    risk 0.00cvss epss 0.01

    WircSrv IRC Server 5.07s allows remote attackers to cause a denial of service via a long string to the server port.

  • CVE-2000-0640Jul 8, 2000
    risk 0.03cvss epss 0.05

    Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or not.