Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 330 260

Количество 330 260

nvd логотип

CVE-2000-0663

больше 25 лет назад

The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative Shell Path" vulnerability.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2000-0662

больше 25 лет назад

Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2000-0661

больше 25 лет назад

WircSrv IRC Server 5.07s allows remote attackers to cause a denial of service via a long string to the server port.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0660

больше 25 лет назад

The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0659

больше 25 лет назад

Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long user ID in a SOCKS4 CONNECT request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0658

больше 25 лет назад

Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the POP3 protocol.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0657

больше 25 лет назад

Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long HELO command in the SMTP protocol.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0656

больше 25 лет назад

Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP protocol.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0655

больше 25 лет назад

Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2000-0654

больше 25 лет назад

Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2000-0653

больше 25 лет назад

Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2000-0652

больше 25 лет назад

IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0651

больше 25 лет назад

The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim's machine.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-0650

больше 25 лет назад

The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2000-0649

больше 25 лет назад

IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.

CVSS2: 2.6
EPSS: Средний
nvd логотип

CVE-2000-0648

больше 25 лет назад

WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command before a RENAME FROM (RNFR) command.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0647

больше 25 лет назад

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0646

больше 25 лет назад

WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0645

больше 25 лет назад

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2000-0644

больше 25 лет назад

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2000-0663

The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative Shell Path" vulnerability.

CVSS2: 4.6
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0662

Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).

CVSS2: 5
28%
Средний
больше 25 лет назад
nvd логотип
CVE-2000-0661

WircSrv IRC Server 5.07s allows remote attackers to cause a denial of service via a long string to the server port.

CVSS2: 5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0660

The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVSS2: 5
5%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0659

Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long user ID in a SOCKS4 CONNECT request.

CVSS2: 5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0658

Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the POP3 protocol.

CVSS2: 5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0657

Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long HELO command in the SMTP protocol.

CVSS2: 5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0656

Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP protocol.

CVSS2: 5
7%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0655

Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.

CVSS2: 5
15%
Средний
больше 25 лет назад
nvd логотип
CVE-2000-0654

Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability.

CVSS2: 4.6
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0653

Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.

CVSS2: 5
50%
Средний
больше 25 лет назад
nvd логотип
CVE-2000-0652

IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.

CVSS2: 5
4%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0651

The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim's machine.

CVSS2: 7.5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0650

The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse.

CVSS2: 2.1
0%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0649

IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.

CVSS2: 2.6
63%
Средний
больше 25 лет назад
nvd логотип
CVE-2000-0648

WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command before a RENAME FROM (RNFR) command.

CVSS2: 5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0647

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server.

CVSS2: 5
4%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0646

WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred.

CVSS2: 5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0645

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

CVSS2: 6.4
4%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0644

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing.

CVSS2: 5
8%
Низкий
больше 25 лет назад

Уязвимостей на страницу