CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 184220 CVEs

CVE ID Severity Description EPSS Published
N/A

The WebShield SMTP Management Tool version 4.5.44 does not properly restrict access to the management port when an IP address does not resolve to a hostname, which allows remote attackers to access the configuration via the GET_CONFIG command.

0.6% 2000-05-01
N/A

Buffer overflow in WebShield SMTP 4.5.44 allows remote attackers to execute arbitrary commands via a long configuration parameter to the WebShield remote management service.

1.4% 2000-05-01
N/A

NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.

6.3% 2000-05-01
N/A

Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string.

1.5% 2000-05-01
N/A

The knfsd NFS server in Linux kernel 2.2.x allows remote attackers to cause a denial of service via a negative size value.

0.7% 2000-05-01
N/A

ATRIUM Cassandra NNTP Server 1.10 allows remote attackers to cause a denial of service via a long login name.

4.0% 2000-05-01
N/A

Eudora 4.1 allows remote attackers to perform a denial of service by sending attachments with long file names.

0.6% 2000-05-01
N/A

Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environmental variable.

0.6% 2000-04-29
7.5 HIGH

Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."

2.4% 2000-04-28
N/A

A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands.

5.4% 2000-04-27
N/A

Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.

0.9% 2000-04-27
N/A

The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.

85.1% 2000-04-26
N/A

The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.

0.1% 2000-04-26
N/A

Meeting Maker uses weak encryption (a polyalphabetic substitution cipher) for passwords, which allows remote attackers to sniff and decrypt passwords for Meeting Maker accounts.

0.4% 2000-04-25
N/A

pcAnywhere 8.x and 9.0 allows remote attackers to cause a denial of service via a TCP SYN scan, e.g. by nmap.

8.0% 2000-04-25
N/A

ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.

3.4% 2000-04-24
N/A

Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.

0.1% 2000-04-24
N/A

The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the container object with a publishing rule.

0.1% 2000-04-24
N/A

The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary commands via shell metacharacters.

77.8% 2000-04-24
N/A

Buffer overflow in IC Radius package allows a remote attacker to cause a denial of service via a long user name.

0.6% 2000-04-24
N/A

Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.

0.1% 2000-04-24
N/A

Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.

0.1% 2000-04-24
N/A

The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.

75.3% 2000-04-24
5.5 MEDIUM

Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.

1.3% 2000-04-23
N/A

mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.

0.7% 2000-04-23
N/A

IMP does not remove files properly if the MSWordView application quits, which allows local users to cause a denial of service by filling up the disk space by requesting a large number of documents and prematurely stopping the request.

0.4% 2000-04-22
N/A

The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information.

0.1% 2000-04-22
N/A

Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.

0.1% 2000-04-21
N/A

Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n.

0.7% 2000-04-21
N/A

Atrium Mercur Mail Server 3.2 allows local attackers to read other user's email and create arbitrary files via a dot dot (..) attack.

0.4% 2000-04-21
N/A

Buffer overflow in LCDproc allows remote attackers to gain root privileges via the screen_add command.

6.6% 2000-04-21
N/A

Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.

17.2% 2000-04-20
N/A

The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability.

0.7% 2000-04-20
N/A

RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070.

8.5% 2000-04-20
N/A

Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON option to the Telnet daemon before it is ready to accept it, which causes the system to reboot.

0.7% 2000-04-20
N/A

Cisco Catalyst 5.4.x allows a user to gain access to the "enable" mode without a password.

0.3% 2000-04-20
N/A

The Adtran MX2800 M13 Multiplexer allows remote attackers to cause a denial of service via a ping flood to the Ethernet interface, which causes the device to crash.

0.7% 2000-04-19
N/A

Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long URL.

15.0% 2000-04-19
N/A

Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability.

21.6% 2000-04-19
N/A

read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.

0.1% 2000-04-18
N/A

The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.

0.1% 2000-04-18
N/A

Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.

0.1% 2000-04-18
N/A

Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.

1.8% 2000-04-18
N/A

HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.

0.1% 2000-04-18
N/A

Panda Security 3.0 allows users to uninstall the Panda software via its Add/Remove Programs applet.

0.1% 2000-04-17
N/A

Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file or using other methods.

0.9% 2000-04-17
N/A

Buffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a document.

0.1% 2000-04-16
N/A

X fontserver xfs allows local users to cause a denial of service via malformed input to the server.

0.5% 2000-04-16
N/A

Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter.

0.0% 2000-04-16
N/A

Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.

78.7% 2000-04-16