CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 93710 CVEs

CVE ID Severity Description EPSS Published
N/A

NetBSD ptrace call on VAX allows local users to gain privileges by modifying the PSL contents in the debugging process.

0.1% 2000-02-01
N/A

GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.

0.1% 2000-02-01
N/A

The CartIt shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

0.6% 2000-02-01
N/A

The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

3.1% 2000-02-01
N/A

The @Retail shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

0.6% 2000-02-01
N/A

The Check It Out shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

0.6% 2000-02-01
N/A

Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands.

6.2% 2000-02-01
N/A

Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.

6.7% 2000-02-01
N/A

The shopping cart application provided with Filemaker allows remote users to modify sensitive purchase information via hidden form fields.

0.6% 2000-02-01
N/A

The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creation" vulnerability.

1.9% 2000-02-01
N/A

The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

0.6% 2000-02-01
N/A

The Intellivend shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

0.6% 2000-02-01
N/A

Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.

0.4% 2000-02-01
N/A

The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

0.6% 2000-02-01
N/A

Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client.

54.2% 2000-02-01
N/A

The Shoptron shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

0.6% 2000-02-01
N/A

The SmartCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

0.6% 2000-02-01
N/A

The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

0.6% 2000-02-01
N/A

The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

0.6% 2000-02-01
N/A

Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.

6.0% 2000-01-31
N/A

The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords.

2.2% 2000-01-31
N/A

The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).

0.1% 2000-01-30
N/A

Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra < in front of the SCRIPT tag.

1.8% 2000-01-29
N/A

The RightFax web client uses predictable session numbers, which allows remote attackers to hijack user sessions.

0.8% 2000-01-29
N/A

Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine.

0.5% 2000-01-27
N/A

Buffer overflow in SCO scohelp program allows remote attackers to execute commands.

0.4% 2000-01-27
N/A

The SyGate Remote Management program does not properly restrict access to its administration service, which allows remote attackers to cause a denial of service, or access network traffic statistics.

1.1% 2000-01-27
N/A

Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.

84.7% 2000-01-26
N/A

Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist.

82.7% 2000-01-26
N/A

The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability.

60.9% 2000-01-26
N/A

Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command.

0.1% 2000-01-26
N/A

The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier.

0.5% 2000-01-24
N/A

IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page.

4.9% 2000-01-21
N/A

An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.

0.3% 2000-01-21
N/A

Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.

2.5% 2000-01-21
N/A

Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability.

0.5% 2000-01-20
N/A

A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.

0.8% 2000-01-20
N/A

The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.

0.1% 2000-01-19
N/A

Buffer overflow in UnixWare ppptalk command allows local users to gain privileges via a long prompt argument.

0.1% 2000-01-18
N/A

Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.

0.6% 2000-01-18
N/A

The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.

0.6% 2000-01-18
N/A

HP VirtualVault with the PHSS_17692 patch allows unprivileged processes to bypass access restrictions via the Trusted Gateway Proxy (TGP).

0.4% 2000-01-18
N/A

VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.

0.1% 2000-01-17
N/A

Visual Casel (Vcasel) does not properly prevent users from executing files, which allows local users to use a relative pathname to specify an alternate file which has an approved name and possibly gain privileges.

0.2% 2000-01-17
N/A

Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request.

4.5% 2000-01-17
N/A

cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to cause a denial of service via a malformed URL that includes shell metacharacters.

0.7% 2000-01-17
N/A

cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to read arbitrary files by specifying the filename in a parameter to the script.

0.6% 2000-01-17
N/A

Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a denial of service by repeating multiple HELO, MAIL FROM, RCPT TO, and DATA commands in the same session.

6.0% 2000-01-13
N/A

WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request.

0.6% 2000-01-13
N/A

Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.

0.8% 2000-01-12