Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 703

Количество 331 703

nvd логотип

CVE-2000-0746

больше 25 лет назад

Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2000-0745

больше 25 лет назад

admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-0744

больше 25 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2000-0743. Reason: This candidate is a duplicate of CVE-2000-0743. Notes: All CVE users should reference CVE-2000-0743 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2000-0743

больше 25 лет назад

Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2000-0742

больше 25 лет назад

The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2000-0741

больше 25 лет назад

Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-0740

больше 25 лет назад

Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0739

больше 25 лет назад

Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0738

больше 25 лет назад

WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0737

больше 25 лет назад

The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2000-0736

больше 25 лет назад

Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0735

больше 25 лет назад

Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0734

больше 25 лет назад

eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0733

больше 25 лет назад

Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2000-0732

больше 25 лет назад

Worm HTTP server allows remote attackers to cause a denial of service via a long URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0731

больше 25 лет назад

Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0730

больше 25 лет назад

Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2000-0729

больше 25 лет назад

FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2000-0728

больше 25 лет назад

xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2000-0727

больше 25 лет назад

xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.

CVSS2: 7.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2000-0746

Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.

CVSS2: 7.5
18%
Средний
больше 25 лет назад
nvd логотип
CVE-2000-0745

admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.

CVSS2: 7.5
0%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0744

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2000-0743. Reason: This candidate is a duplicate of CVE-2000-0743. Notes: All CVE users should reference CVE-2000-0743 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

больше 25 лет назад
nvd логотип
CVE-2000-0743

Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.

CVSS2: 10
6%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0742

The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability.

CVSS2: 5
19%
Средний
больше 25 лет назад
nvd логотип
CVE-2000-0741

Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.

CVSS2: 7.5
7%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0740

Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port.

CVSS2: 5
9%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0739

Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server.

CVSS2: 5
5%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0738

WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail.

CVSS2: 5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0737

The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability.

CVSS2: 4.6
2%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0736

Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message.

CVSS2: 5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0735

Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message.

CVSS2: 5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0734

eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.

CVSS2: 5
4%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0733

Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.

CVSS2: 10
6%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0732

Worm HTTP server allows remote attackers to cause a denial of service via a long URL.

CVSS2: 5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0731

Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVSS2: 5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0730

Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0729

FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.

CVSS2: 2.1
0%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0728

xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.

CVSS2: 7.2
0%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0727

xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.

CVSS2: 7.6
1%
Низкий
больше 25 лет назад

Уязвимостей на страницу