Количество 306 905
Количество 306 905

CVE-2000-0768
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.

CVE-2000-0767
The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability.

CVE-2000-0766
Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileges via a long HTTP GET request.

CVE-2000-0765
Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.

CVE-2000-0764
Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed IP packet.

CVE-2000-0763
xlockmore and xlockf do not properly cleanse user-injected format strings, which allows local users to gain root privileges via the -d option.

CVE-2000-0762
The default installation of eTrust Access Control (formerly SeOS) uses a default encryption key, which allows remote attackers to spoof the eTrust administrator and gain privileges.

CVE-2000-0761
OS2/Warp 4.5 FTP server allows remote attackers to cause a denial of service via a long username.

CVE-2000-0760
The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.

CVE-2000-0759
Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.

CVE-2000-0758
The web interface for Lyris List Manager 3 and 4 allows list subscribers to obtain administrative access by modifying the value of the list_admin hidden form field.

CVE-2000-0757
The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.

CVE-2000-0756
Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.

CVE-2000-0755
Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.

CVE-2000-0754
Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.

CVE-2000-0753
The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files.

CVE-2000-0752
Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.

CVE-2000-0751
mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.

CVE-2000-0750
Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.

CVE-2000-0749
Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2000-0768 A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability. | CVSS2: 2.6 | 16% Средний | почти 25 лет назад |
![]() | CVE-2000-0767 The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability. | CVSS2: 2.6 | 13% Средний | почти 25 лет назад |
![]() | CVE-2000-0766 Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileges via a long HTTP GET request. | CVSS2: 7.5 | 5% Низкий | почти 25 лет назад |
![]() | CVE-2000-0765 Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability. | CVSS2: 5.1 | 11% Средний | почти 25 лет назад |
![]() | CVE-2000-0764 Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed IP packet. | CVSS2: 5 | 1% Низкий | почти 25 лет назад |
![]() | CVE-2000-0763 xlockmore and xlockf do not properly cleanse user-injected format strings, which allows local users to gain root privileges via the -d option. | CVSS2: 7.2 | 0% Низкий | почти 25 лет назад |
![]() | CVE-2000-0762 The default installation of eTrust Access Control (formerly SeOS) uses a default encryption key, which allows remote attackers to spoof the eTrust administrator and gain privileges. | CVSS2: 10 | 1% Низкий | почти 25 лет назад |
![]() | CVE-2000-0761 OS2/Warp 4.5 FTP server allows remote attackers to cause a denial of service via a long username. | CVSS2: 5 | 1% Низкий | почти 25 лет назад |
![]() | CVE-2000-0760 The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension. | CVSS2: 6.4 | 38% Средний | почти 25 лет назад |
![]() | CVE-2000-0759 Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path. | CVSS2: 6.4 | 40% Средний | почти 25 лет назад |
![]() | CVE-2000-0758 The web interface for Lyris List Manager 3 and 4 allows list subscribers to obtain administrative access by modifying the value of the list_admin hidden form field. | CVSS2: 4.6 | 0% Низкий | почти 25 лет назад |
![]() | CVE-2000-0757 The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed. | CVSS2: 10 | 2% Низкий | почти 25 лет назад |
![]() | CVE-2000-0756 Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service. | CVSS2: 5 | 12% Средний | почти 25 лет назад |
![]() | CVE-2000-0755 Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges. | CVSS2: 4.6 | 0% Низкий | почти 25 лет назад |
![]() | CVE-2000-0754 Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords. | CVSS2: 2.1 | 0% Низкий | почти 25 лет назад |
![]() | CVE-2000-0753 The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files. | CVSS2: 5 | 18% Средний | почти 25 лет назад |
![]() | CVE-2000-0752 Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments. | CVSS2: 7.2 | 0% Низкий | почти 25 лет назад |
![]() | CVE-2000-0751 mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands. | CVSS2: 7.5 | 18% Средний | почти 25 лет назад |
![]() | CVE-2000-0750 Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name. | CVSS2: 7.5 | 2% Низкий | почти 25 лет назад |
![]() | CVE-2000-0749 Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system. | CVSS2: 7.2 | 0% Низкий | почти 25 лет назад |
Уязвимостей на страницу