| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2000-0641 | 0.04 | — | 0.13 | Jul 8, 2000 | Savant web server allows remote attackers to execute arbitrary commands via a long GET request. | |||
| CVE-2000-0573 | 0.10 | — | 0.91 | Jul 7, 2000 | The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command. | |||
| CVE-2000-0574 | 0.04 | — | 0.13 | Jul 7, 2000 | FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands. | |||
| CVE-2000-0603 | 0.00 | — | 0.01 | Jul 7, 2000 | Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the "Stored Procedure Permissions" vulnerability. | |||
| CVE-2000-0651 | 0.00 | — | 0.01 | Jul 7, 2000 | The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim's machine. | |||
| CVE-2000-0571 | 0.03 | — | 0.03 | Jul 5, 2000 | LocalWEB HTTP server 1.2.0 allows remote attackers to cause a denial of service via a long GET request. | |||
| CVE-2000-0572 | 0.03 | — | 0.00 | Jul 5, 2000 | The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain privileges. | |||
| CVE-2000-0575 | 0.00 | — | 0.00 | Jul 5, 2000 | SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on NFS. | |||
| CVE-2000-0576 | 0.00 | — | 0.01 | Jul 5, 2000 | Oracle Web Listener for AIX versions 4.0.7.0.0 and 4.0.8.1.0 allows remote attackers to cause a denial of service via a malformed URL. | |||
| CVE-2000-0591 | 0.00 | — | 0.00 | Jul 5, 2000 | Novell BorderManager 3.0 and 3.5 allows remote attackers to bypass URL filtering by encoding characters in the requested URL. | |||
| CVE-2000-0595 | 0.00 | — | 0.00 | Jul 5, 2000 | libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory. | |||
| CVE-2000-0590 | 0.04 | — | 0.07 | Jul 4, 2000 | Poll It 2.0 CGI script allows remote attackers to read arbitrary files by specifying the file name in the data_dir parameter. | |||
| CVE-2000-0594 | 0.04 | — | 0.11 | Jul 4, 2000 | BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters. | |||
| CVE-2000-0566 | 0.00 | — | 0.00 | Jul 3, 2000 | makewhatis in Linux man package allows local users to overwrite files via a symlink attack. | |||
| CVE-2000-0584 | 0.04 | — | 0.07 | Jul 2, 2000 | Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name. | |||
| CVE-1999-0585 | 0.00 | — | 0.01 | Jul 1, 2000 | A Windows NT administrator account has the default name of Administrator. | |||
| CVE-2000-0568 | 0.00 | — | 0.01 | Jun 30, 2000 | Sybergen Secure Desktop 2.1 does not properly protect against false router advertisements (ICMP type 9), which allows remote attackers to modify default routes. | |||
| CVE-2000-0569 | 0.04 | — | 0.10 | Jun 30, 2000 | Sybergen Sygate allows remote attackers to cause a denial of service by sending a malformed DNS UDP packet to its internal interface. | |||
| CVE-2000-0580 | 0.05 | — | 0.21 | Jun 30, 2000 | Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization. | |||
| CVE-2000-0581 | 0.07 | — | 0.56 | Jun 30, 2000 | Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash. | |||
| CVE-2000-0582 | 0.03 | — | 0.05 | Jun 30, 2000 | Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros) to the SMTP Security Server proxy. | |||
| CVE-2000-0583 | 0.00 | — | 0.01 | Jun 30, 2000 | vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives. | |||
| CVE-2000-0586 | 0.04 | — | 0.09 | Jun 29, 2000 | Buffer overflow in Dalnet IRC server 4.6.5 allows remote attackers to cause a denial of service or execute arbitrary commands via the SUMMON command. | |||
| CVE-2000-0599 | 0.00 | — | 0.02 | Jun 29, 2000 | Buffer overflow in iMesh 1.02 allows remote attackers to execute arbitrary commands via a long string to the iMesh port. | |||
| CVE-2000-0612 | 0.01 | — | 0.15 | Jun 29, 2000 | Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table. | |||
| CVE-2000-0570 | 0.03 | — | 0.06 | Jun 27, 2000 | FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email with a long To: mail header. | |||
| CVE-2000-0592 | 0.03 | — | 0.05 | Jun 27, 2000 | Buffer overflows in POP3 service in WinProxy 2.0 and 2.0.1 allow remote attackers to execute arbitrary commands via long USER, PASS, LIST, RETR, or DELE commands. | |||
| CVE-2000-0593 | 0.00 | — | 0.01 | Jun 27, 2000 | WinProxy 2.0 and 2.0.1 allows remote attackers to cause a denial of service by sending an HTTP GET request without listing an HTTP version number. | |||
| CVE-2000-0596 | 0.01 | — | 0.13 | Jun 27, 2000 | Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability. | |||
| CVE-2000-0597 | 0.01 | — | 0.10 | Jun 27, 2000 | Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability. | |||
| CVE-2000-0587 | 0.00 | — | 0.00 | Jun 26, 2000 | The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability. | |||
| CVE-2000-0588 | 0.03 | — | 0.04 | Jun 26, 2000 | SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents SawMill attempts to parse as configuration commands. | |||
| CVE-2000-0589 | 0.03 | — | 0.02 | Jun 26, 2000 | SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration. | |||
| CVE-2000-0598 | 0.00 | — | 0.00 | Jun 26, 2000 | Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy. | |||
| CVE-2000-0600 | 0.00 | — | 0.01 | Jun 26, 2000 | Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed URL. | |||
| CVE-2000-0616 | 0.00 | — | 0.00 | Jun 26, 2000 | Vulnerability in HP TurboIMAGE DBUTIL allows local users to gain additional privileges via DBUTIL.PUB.SYS. | |||
| CVE-2000-0601 | 0.03 | — | 0.06 | Jun 25, 2000 | LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages. | |||
| CVE-2000-0585 | 0.01 | — | 0.10 | Jun 24, 2000 | ISC DHCP client program dhclient allows remote attackers to execute arbitrary commands via shell metacharacters. | |||
| CVE-2000-0610 | 0.00 | — | 0.01 | Jun 23, 2000 | NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return. | |||
| CVE-2000-0611 | 0.00 | — | 0.01 | Jun 23, 2000 | The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service. | |||
| CVE-2000-0539 | 0.00 | — | 0.01 | Jun 22, 2000 | Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession ID's via the SessionServlet servlet. | |||
| CVE-2000-0540 | 0.00 | — | 0.01 | Jun 22, 2000 | JSP sample files in Allaire JRun 2.3.x allow remote attackers to access arbitrary files (e.g. via viewsource.jsp) or obtain configuration information. | |||
| CVE-2000-0562 | 0.00 | — | 0.00 | Jun 22, 2000 | BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower. | |||
| CVE-2000-0617 | 0.03 | — | 0.00 | Jun 22, 2000 | Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long USER environmental variable. | |||
| CVE-2000-0618 | 0.00 | — | 0.00 | Jun 22, 2000 | Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable. | |||
| CVE-2000-0500 | 0.04 | — | 0.07 | Jun 21, 2000 | The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing. | |||
| CVE-2000-0510 | 0.00 | — | 0.01 | Jun 21, 2000 | CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a malformed IPP request. | |||
| CVE-2000-0511 | 0.00 | — | 0.01 | Jun 21, 2000 | CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a CGI POST request. | |||
| CVE-2000-0513 | 0.00 | — | 0.01 | Jun 21, 2000 | CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service by authenticating with a user name that does not exist or does not have a shadow password. | |||
| CVE-2000-0577 | 0.04 | — | 0.07 | Jun 21, 2000 | Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
- CVE-2000-0641Jul 8, 2000risk 0.04cvss —epss 0.13
Savant web server allows remote attackers to execute arbitrary commands via a long GET request.
- CVE-2000-0573Jul 7, 2000risk 0.10cvss —epss 0.91
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command.
- CVE-2000-0574Jul 7, 2000risk 0.04cvss —epss 0.13
FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.
- CVE-2000-0603Jul 7, 2000risk 0.00cvss —epss 0.01
Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the "Stored Procedure Permissions" vulnerability.
- CVE-2000-0651Jul 7, 2000risk 0.00cvss —epss 0.01
The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim's machine.
- CVE-2000-0571Jul 5, 2000risk 0.03cvss —epss 0.03
LocalWEB HTTP server 1.2.0 allows remote attackers to cause a denial of service via a long GET request.
- CVE-2000-0572Jul 5, 2000risk 0.03cvss —epss 0.00
The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain privileges.
- CVE-2000-0575Jul 5, 2000risk 0.00cvss —epss 0.00
SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on NFS.
- CVE-2000-0576Jul 5, 2000risk 0.00cvss —epss 0.01
Oracle Web Listener for AIX versions 4.0.7.0.0 and 4.0.8.1.0 allows remote attackers to cause a denial of service via a malformed URL.
- CVE-2000-0591Jul 5, 2000risk 0.00cvss —epss 0.00
Novell BorderManager 3.0 and 3.5 allows remote attackers to bypass URL filtering by encoding characters in the requested URL.
- CVE-2000-0595Jul 5, 2000risk 0.00cvss —epss 0.00
libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory.
- CVE-2000-0590Jul 4, 2000risk 0.04cvss —epss 0.07
Poll It 2.0 CGI script allows remote attackers to read arbitrary files by specifying the file name in the data_dir parameter.
- CVE-2000-0594Jul 4, 2000risk 0.04cvss —epss 0.11
BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.
- CVE-2000-0566Jul 3, 2000risk 0.00cvss —epss 0.00
makewhatis in Linux man package allows local users to overwrite files via a symlink attack.
- CVE-2000-0584Jul 2, 2000risk 0.04cvss —epss 0.07
Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.
- CVE-1999-0585Jul 1, 2000risk 0.00cvss —epss 0.01
A Windows NT administrator account has the default name of Administrator.
- CVE-2000-0568Jun 30, 2000risk 0.00cvss —epss 0.01
Sybergen Secure Desktop 2.1 does not properly protect against false router advertisements (ICMP type 9), which allows remote attackers to modify default routes.
- CVE-2000-0569Jun 30, 2000risk 0.04cvss —epss 0.10
Sybergen Sygate allows remote attackers to cause a denial of service by sending a malformed DNS UDP packet to its internal interface.
- CVE-2000-0580Jun 30, 2000risk 0.05cvss —epss 0.21
Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization.
- CVE-2000-0581Jun 30, 2000risk 0.07cvss —epss 0.56
Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash.
- CVE-2000-0582Jun 30, 2000risk 0.03cvss —epss 0.05
Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros) to the SMTP Security Server proxy.
- CVE-2000-0583Jun 30, 2000risk 0.00cvss —epss 0.01
vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives.
- CVE-2000-0586Jun 29, 2000risk 0.04cvss —epss 0.09
Buffer overflow in Dalnet IRC server 4.6.5 allows remote attackers to cause a denial of service or execute arbitrary commands via the SUMMON command.
- CVE-2000-0599Jun 29, 2000risk 0.00cvss —epss 0.02
Buffer overflow in iMesh 1.02 allows remote attackers to execute arbitrary commands via a long string to the iMesh port.
- CVE-2000-0612Jun 29, 2000risk 0.01cvss —epss 0.15
Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table.
- CVE-2000-0570Jun 27, 2000risk 0.03cvss —epss 0.06
FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email with a long To: mail header.
- CVE-2000-0592Jun 27, 2000risk 0.03cvss —epss 0.05
Buffer overflows in POP3 service in WinProxy 2.0 and 2.0.1 allow remote attackers to execute arbitrary commands via long USER, PASS, LIST, RETR, or DELE commands.
- CVE-2000-0593Jun 27, 2000risk 0.00cvss —epss 0.01
WinProxy 2.0 and 2.0.1 allows remote attackers to cause a denial of service by sending an HTTP GET request without listing an HTTP version number.
- CVE-2000-0596Jun 27, 2000risk 0.01cvss —epss 0.13
Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.
- CVE-2000-0597Jun 27, 2000risk 0.01cvss —epss 0.10
Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.
- CVE-2000-0587Jun 26, 2000risk 0.00cvss —epss 0.00
The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability.
- CVE-2000-0588Jun 26, 2000risk 0.03cvss —epss 0.04
SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents SawMill attempts to parse as configuration commands.
- CVE-2000-0589Jun 26, 2000risk 0.03cvss —epss 0.02
SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration.
- CVE-2000-0598Jun 26, 2000risk 0.00cvss —epss 0.00
Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy.
- CVE-2000-0600Jun 26, 2000risk 0.00cvss —epss 0.01
Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed URL.
- CVE-2000-0616Jun 26, 2000risk 0.00cvss —epss 0.00
Vulnerability in HP TurboIMAGE DBUTIL allows local users to gain additional privileges via DBUTIL.PUB.SYS.
- CVE-2000-0601Jun 25, 2000risk 0.03cvss —epss 0.06
LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages.
- CVE-2000-0585Jun 24, 2000risk 0.01cvss —epss 0.10
ISC DHCP client program dhclient allows remote attackers to execute arbitrary commands via shell metacharacters.
- CVE-2000-0610Jun 23, 2000risk 0.00cvss —epss 0.01
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return.
- CVE-2000-0611Jun 23, 2000risk 0.00cvss —epss 0.01
The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service.
- CVE-2000-0539Jun 22, 2000risk 0.00cvss —epss 0.01
Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession ID's via the SessionServlet servlet.
- CVE-2000-0540Jun 22, 2000risk 0.00cvss —epss 0.01
JSP sample files in Allaire JRun 2.3.x allow remote attackers to access arbitrary files (e.g. via viewsource.jsp) or obtain configuration information.
- CVE-2000-0562Jun 22, 2000risk 0.00cvss —epss 0.00
BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower.
- CVE-2000-0617Jun 22, 2000risk 0.03cvss —epss 0.00
Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long USER environmental variable.
- CVE-2000-0618Jun 22, 2000risk 0.00cvss —epss 0.00
Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable.
- CVE-2000-0500Jun 21, 2000risk 0.04cvss —epss 0.07
The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing.
- CVE-2000-0510Jun 21, 2000risk 0.00cvss —epss 0.01
CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a malformed IPP request.
- CVE-2000-0511Jun 21, 2000risk 0.00cvss —epss 0.01
CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a CGI POST request.
- CVE-2000-0513Jun 21, 2000risk 0.00cvss —epss 0.01
CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service by authenticating with a user name that does not exist or does not have a shadow password.
- CVE-2000-0577Jun 21, 2000risk 0.04cvss —epss 0.07
Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.