Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 307 743

Количество 307 743

nvd логотип

CVE-2000-0746

почти 25 лет назад

Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2000-0745

почти 25 лет назад

admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-0744

почти 25 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2000-0743. Reason: This candidate is a duplicate of CVE-2000-0743. Notes: All CVE users should reference CVE-2000-0743 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2000-0743

почти 25 лет назад

Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2000-0742

почти 25 лет назад

The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2000-0741

почти 25 лет назад

Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-0740

почти 25 лет назад

Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2000-0739

почти 25 лет назад

Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0738

почти 25 лет назад

WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0737

почти 25 лет назад

The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2000-0736

почти 25 лет назад

Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0735

почти 25 лет назад

Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0734

почти 25 лет назад

eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0733

почти 25 лет назад

Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2000-0732

почти 25 лет назад

Worm HTTP server allows remote attackers to cause a denial of service via a long URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0731

почти 25 лет назад

Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0730

почти 25 лет назад

Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2000-0729

почти 25 лет назад

FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2000-0728

почти 25 лет назад

xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2000-0727

почти 25 лет назад

xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.

CVSS2: 7.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2000-0746

Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.

CVSS2: 7.5
12%
Средний
почти 25 лет назад
nvd логотип
CVE-2000-0745

admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.

CVSS2: 7.5
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0744

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2000-0743. Reason: This candidate is a duplicate of CVE-2000-0743. Notes: All CVE users should reference CVE-2000-0743 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

почти 25 лет назад
nvd логотип
CVE-2000-0743

Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.

CVSS2: 10
5%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0742

The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability.

CVSS2: 5
19%
Средний
почти 25 лет назад
nvd логотип
CVE-2000-0741

Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.

CVSS2: 7.5
7%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0740

Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port.

CVSS2: 5
11%
Средний
почти 25 лет назад
nvd логотип
CVE-2000-0739

Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server.

CVSS2: 5
5%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0738

WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail.

CVSS2: 5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0737

The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability.

CVSS2: 4.6
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0736

Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message.

CVSS2: 5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0735

Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message.

CVSS2: 5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0734

eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.

CVSS2: 5
4%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0733

Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.

CVSS2: 10
6%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0732

Worm HTTP server allows remote attackers to cause a denial of service via a long URL.

CVSS2: 5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0731

Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVSS2: 5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0730

Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0729

FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.

CVSS2: 2.1
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0728

xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.

CVSS2: 7.2
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-0727

xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.

CVSS2: 7.6
1%
Низкий
почти 25 лет назад

Уязвимостей на страницу