Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 306 740

Количество 306 740

nvd логотип

CVE-2000-1212

больше 24 лет назад

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-1211

больше 24 лет назад

Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-1210

больше 23 лет назад

Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-1209

около 23 лет назад

The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.

CVSS2: 10
EPSS: Высокий
nvd логотип

CVE-2000-1208

около 23 лет назад

Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2000-1207

почти 25 лет назад

userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2000-1206

около 26 лет назад

Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-1205

больше 25 лет назад

Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2000-1204

почти 25 лет назад

Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-1203

около 24 лет назад

Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-1202

почти 24 года назад

ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2000-1201

почти 24 года назад

Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-1200

почти 24 года назад

Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2000-1199

почти 24 года назад

PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2000-1198

почти 24 года назад

qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2000-1197

почти 24 года назад

POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2000-1196

почти 24 года назад

PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-1195

почти 24 года назад

telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-1194

почти 24 года назад

Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-1193

почти 24 года назад

Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2000-1212

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-1211

Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.

CVSS2: 7.5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-1210

Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.

CVSS2: 5
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2000-1209

The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.

CVSS2: 10
90%
Высокий
около 23 лет назад
nvd логотип
CVE-2000-1208

Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.

CVSS2: 7.2
0%
Низкий
около 23 лет назад
nvd логотип
CVE-2000-1207

userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).

CVSS2: 7.2
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1206

Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.

CVSS2: 5
3%
Низкий
около 26 лет назад
nvd логотип
CVE-2000-1205

Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.

CVSS2: 4.3
9%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-1204

Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.

CVSS2: 5
4%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1203

Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.

CVSS2: 5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2000-1202

ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.

CVSS2: 7.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2000-1201

Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264.

CVSS2: 5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2000-1200

Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.

CVSS2: 5
20%
Средний
почти 24 года назад
nvd логотип
CVE-2000-1199

PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.

CVSS2: 4.6
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2000-1198

qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.

CVSS3: 5.5
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2000-1197

POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.

CVSS2: 2.1
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2000-1196

PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.

CVSS2: 5
9%
Низкий
почти 24 года назад
nvd логотип
CVE-2000-1195

telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option.

CVSS2: 7.5
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2000-1194

Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.

CVSS2: 7.5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2000-1193

Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port.

CVSS2: 5
4%
Низкий
почти 24 года назад

Уязвимостей на страницу