VYPR

CVEs

340,763 total · page 6784 of 6,816

  • CVE-2000-0048Jan 12, 2000
    risk 0.03cvss epss 0.00

    get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp program.

  • CVE-2000-0070Jan 12, 2000
    risk 0.00cvss epss 0.02

    NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC Port Request."

  • CVE-2000-0087Jan 12, 2000
    risk 0.00cvss epss 0.01

    Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.

  • CVE-2000-0045Jan 11, 2000
    risk 0.03cvss epss 0.02

    MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.

  • CVE-2000-0067Jan 11, 2000
    risk 0.00cvss epss 0.00

    CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack.

  • CVE-2000-0071Jan 11, 2000
    risk 0.06cvss epss 0.71

    IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.

  • CVE-2000-0074Jan 11, 2000
    risk 0.03cvss epss 0.06

    PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions.

  • CVE-2000-0046Jan 10, 2000
    risk 0.03cvss epss 0.05

    Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ message.

  • CVE-2000-0080Jan 10, 2000
    risk 0.00cvss epss 0.00

    AIX techlibss allows local users to overwrite files via a symlink attack.

  • CVE-2000-0081Jan 10, 2000
    risk 0.02cvss epss 0.29

    Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript.

  • CVE-2000-1220Jan 8, 2000
    risk 0.03cvss epss 0.03

    The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.

  • CVE-2000-1221Jan 8, 2000
    risk 0.04cvss epss 0.11

    The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended…

  • CVE-2000-0061Jan 7, 2000
    risk 0.04cvss epss 0.16

    Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.

  • CVE-2000-0044Jan 6, 2000
    risk 0.00cvss epss 0.02

    Macros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands.

  • CVE-2000-0055Jan 6, 2000
    risk 0.00cvss epss 0.00

    Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.

  • CVE-2000-0084Jan 6, 2000
    risk 0.00cvss epss 0.00

    CuteFTP uses weak encryption to store password information in its tree.dat file.

  • CVE-2000-0056Jan 5, 2000
    risk 0.03cvss epss 0.01

    IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi.

  • CVE-2000-0058Jan 5, 2000
    risk 0.00cvss epss 0.01

    Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files.

  • CVE-1999-0735Jan 4, 2000
    risk 0.03cvss epss 0.00

    KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories.

  • CVE-1999-0744Jan 4, 2000
    risk 0.03cvss epss 0.06

    Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.

  • CVE-1999-0876Jan 4, 2000
    risk 0.02cvss epss 0.24

    Buffer overflow in Internet Explorer 4.0 via EMBED tag.

  • CVE-1999-0894Jan 4, 2000
    risk 0.00cvss epss 0.00

    Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals.

  • CVE-2000-0049Jan 4, 2000
    risk 0.03cvss epss 0.02

    Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.

  • CVE-2000-0050Jan 4, 2000
    risk 0.00cvss epss 0.00

    The Allaire Spectra Webtop allows authenticated users to access other Webtop sections by specifying explicit URLs.

  • CVE-2000-0051Jan 4, 2000
    risk 0.00cvss epss 0.01

    The Allaire Spectra Configuration Wizard allows remote attackers to cause a denial of service by repeatedly resubmitting data collections for indexing via a URL.

  • CVE-2000-0052Jan 4, 2000
    risk 0.03cvss epss 0.00

    Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.

  • CVE-2000-0053Jan 4, 2000
    risk 0.01cvss epss 0.14

    Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.

  • CVE-2000-0057Jan 4, 2000
    risk 0.03cvss epss 0.03

    Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain sensitive system information.

  • CVE-2000-0059Jan 4, 2000
    risk 0.03cvss epss 0.03

    PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.

  • CVE-2000-0062Jan 4, 2000
    risk 0.00cvss epss 0.01

    The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.

  • CVE-2000-0085Jan 4, 2000
    risk 0.01cvss epss 0.12

    Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.

  • CVE-2000-0077Jan 2, 2000
    risk 0.03cvss epss 0.01

    The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.

  • CVE-2000-0078Jan 2, 2000
    risk 0.00cvss epss 0.00

    The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.

  • CVE-2000-0082Jan 2, 2000
    risk 0.03cvss epss 0.37

    WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML.

  • CVE-1999-0964Jan 1, 2000
    risk 0.00cvss epss 0.00

    Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable.

  • CVE-2000-0069Jan 1, 2000
    risk 0.00cvss epss 0.00

    The recover program in Solstice Backup allows local users to restore sensitive files.

  • CVE-2000-0120Jan 1, 2000
    risk 0.00cvss epss 0.00

    The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter.

  • CVE-1999-0154Dec 31, 1999
    risk 0.07cvss epss 0.48

    IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.

  • CVE-1999-0808Dec 31, 1999
    risk 0.00cvss epss 0.02

    Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.

  • CVE-1999-0815Dec 31, 1999
    risk 0.01cvss epss 0.17

    Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.

  • CVE-1999-1035Dec 31, 1999
    risk 0.01cvss epss 0.18

    IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.

  • CVE-1999-1042Dec 31, 1999
    risk 0.00cvss epss 0.00

    Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.

  • CVE-1999-1043Dec 31, 1999
    risk 0.01cvss epss 0.06

    Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).

  • CVE-1999-1055Dec 31, 1999
    risk 0.01cvss epss 0.08

    Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."

  • CVE-1999-1074Dec 31, 1999
    risk 0.00cvss epss 0.01

    Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.

  • CVE-1999-1084Dec 31, 1999
    risk 0.03cvss epss 0.01

    The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.

  • CVE-1999-1087Dec 31, 1999
    risk 0.01cvss epss 0.12

    Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by…

  • CVE-1999-1093Dec 31, 1999
    risk 0.01cvss epss 0.06

    Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.

  • CVE-1999-1094Dec 31, 1999
    risk 0.01cvss epss 0.07

    Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."

  • CVE-1999-1100Dec 31, 1999
    risk 0.00cvss epss 0.01

    Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force…