Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 307 024

Количество 307 024

nvd логотип

CVE-2000-0974

больше 24 лет назад

GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-0973

больше 24 лет назад

Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2000-0972

больше 24 лет назад

HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2000-0971

больше 24 лет назад

Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2000-0970

больше 24 лет назад

IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2000-0969

больше 24 лет назад

Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2000-0968

больше 24 лет назад

Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2000-0967

больше 24 лет назад

PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2000-0966

больше 24 лет назад

Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2000-0965

больше 24 лет назад

The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0964

больше 24 лет назад

Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2000-0963

больше 24 лет назад

Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2000-0962

больше 24 лет назад

The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0961

больше 24 лет назад

Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2000-0960

больше 24 лет назад

The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0959

больше 24 лет назад

glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.

CVSS2: 1.2
EPSS: Низкий
nvd логотип

CVE-2000-0958

больше 24 лет назад

HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0957

больше 24 лет назад

The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-0956

больше 24 лет назад

cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2000-0955

больше 24 лет назад

Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2000-0974

GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.

CVSS2: 7.5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0973

Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.

CVSS2: 10
10%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0972

HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.

CVSS3: 5.5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0971

Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.

CVSS2: 10
8%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0970

IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.

CVSS2: 7.5
20%
Средний
больше 24 лет назад
nvd логотип
CVE-2000-0969

Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.

CVSS2: 10
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0968

Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.

CVSS2: 10
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0967

PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.

CVSS2: 10
27%
Средний
больше 24 лет назад
nvd логотип
CVE-2000-0966

Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0965

The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization).

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0964

Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.

CVSS2: 10
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0963

Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.

CVSS2: 7.2
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0962

The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0961

Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.

CVSS2: 10
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0960

The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0959

glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.

CVSS2: 1.2
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0958

HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.

CVSS2: 5
4%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0957

The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.

CVSS2: 7.5
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0956

cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.

CVSS2: 4.6
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2000-0955

Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.

CVSS2: 7.5
4%
Низкий
больше 24 лет назад

Уязвимостей на страницу