VYPR

CVEs

335,096 total · page 6671 of 6,702

  • CVE-2000-0056Jan 5, 2000
    risk 0.03cvss epss 0.01

    IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi.

  • CVE-2000-0058Jan 5, 2000
    risk 0.00cvss epss 0.01

    Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files.

  • CVE-1999-0735Jan 4, 2000
    risk 0.03cvss epss 0.00

    KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories.

  • CVE-1999-0744Jan 4, 2000
    risk 0.03cvss epss 0.06

    Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.

  • CVE-1999-0876Jan 4, 2000
    risk 0.02cvss epss 0.24

    Buffer overflow in Internet Explorer 4.0 via EMBED tag.

  • CVE-1999-0894Jan 4, 2000
    risk 0.00cvss epss 0.00

    Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals.

  • CVE-2000-0049Jan 4, 2000
    risk 0.03cvss epss 0.02

    Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.

  • CVE-2000-0050Jan 4, 2000
    risk 0.00cvss epss 0.00

    The Allaire Spectra Webtop allows authenticated users to access other Webtop sections by specifying explicit URLs.

  • CVE-2000-0051Jan 4, 2000
    risk 0.00cvss epss 0.01

    The Allaire Spectra Configuration Wizard allows remote attackers to cause a denial of service by repeatedly resubmitting data collections for indexing via a URL.

  • CVE-2000-0052Jan 4, 2000
    risk 0.03cvss epss 0.00

    Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.

  • CVE-2000-0053Jan 4, 2000
    risk 0.01cvss epss 0.14

    Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.

  • CVE-2000-0057Jan 4, 2000
    risk 0.03cvss epss 0.03

    Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain sensitive system information.

  • CVE-2000-0059Jan 4, 2000
    risk 0.03cvss epss 0.03

    PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.

  • CVE-2000-0062Jan 4, 2000
    risk 0.00cvss epss 0.01

    The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.

  • CVE-2000-0085Jan 4, 2000
    risk 0.01cvss epss 0.12

    Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.

  • CVE-2000-0077Jan 2, 2000
    risk 0.03cvss epss 0.01

    The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.

  • CVE-2000-0078Jan 2, 2000
    risk 0.00cvss epss 0.00

    The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.

  • CVE-2000-0082Jan 2, 2000
    risk 0.03cvss epss 0.37

    WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML.

  • CVE-1999-0964Jan 1, 2000
    risk 0.00cvss epss 0.00

    Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable.

  • CVE-2000-0069Jan 1, 2000
    risk 0.00cvss epss 0.00

    The recover program in Solstice Backup allows local users to restore sensitive files.

  • CVE-2000-0120Jan 1, 2000
    risk 0.00cvss epss 0.00

    The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter.

  • CVE-1999-0154Dec 31, 1999
    risk 0.07cvss epss 0.48

    IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.

  • CVE-1999-0808Dec 31, 1999
    risk 0.00cvss epss 0.02

    Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.

  • CVE-1999-0815Dec 31, 1999
    risk 0.01cvss epss 0.17

    Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.

  • CVE-1999-1035Dec 31, 1999
    risk 0.01cvss epss 0.18

    IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.

  • CVE-1999-1042Dec 31, 1999
    risk 0.00cvss epss 0.00

    Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.

  • CVE-1999-1043Dec 31, 1999
    risk 0.01cvss epss 0.06

    Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).

  • CVE-1999-1055Dec 31, 1999
    risk 0.01cvss epss 0.08

    Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."

  • CVE-1999-1074Dec 31, 1999
    risk 0.00cvss epss 0.01

    Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.

  • CVE-1999-1084Dec 31, 1999
    risk 0.03cvss epss 0.01

    The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.

  • CVE-1999-1087Dec 31, 1999
    risk 0.01cvss epss 0.12

    Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.

  • CVE-1999-1093Dec 31, 1999
    risk 0.01cvss epss 0.06

    Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.

  • CVE-1999-1094Dec 31, 1999
    risk 0.01cvss epss 0.07

    Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."

  • CVE-1999-1100Dec 31, 1999
    risk 0.00cvss epss 0.01

    Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force attack.

  • CVE-1999-1102Dec 31, 1999
    risk 0.00cvss epss 0.00

    lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.

  • CVE-1999-1104Dec 31, 1999
    risk 0.00cvss epss 0.00

    Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.

  • CVE-1999-1105Dec 31, 1999
    risk 0.04cvss epss 0.49

    Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive.

  • CVE-1999-1117Dec 31, 1999
    risk 0.03cvss epss 0.00

    lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.

  • CVE-1999-1124Dec 31, 1999
    risk 0.00cvss epss 0.00

    HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the request is coming from the local host.

  • CVE-1999-1126Dec 31, 1999
    risk 0.00cvss epss 0.00

    Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with "DPR_".

  • CVE-1999-1127HigDec 31, 1999
    risk 0.51cvss 7.5epss 0.30

    Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability.

  • CVE-1999-1132Dec 31, 1999
    risk 0.02cvss epss 0.19

    Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.

  • CVE-1999-1148Dec 31, 1999
    risk 0.01cvss epss 0.18

    FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.

  • CVE-1999-1157Dec 31, 1999
    risk 0.01cvss epss 0.14

    Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.

  • CVE-1999-1167Dec 31, 1999
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation.

  • CVE-1999-1175Dec 31, 1999
    risk 0.00cvss epss 0.01

    Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.

  • CVE-1999-1177Dec 31, 1999
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the pathname for an upload operation.

  • CVE-1999-1206Dec 31, 1999
    risk 0.00cvss epss 0.02

    SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control.

  • CVE-1999-1222Dec 31, 1999
    risk 0.01cvss epss 0.10

    Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.

  • CVE-1999-1223Dec 31, 1999
    risk 0.01cvss epss 0.16

    IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.