Количество 331 703
Количество 331 703
CVE-2000-0104
The Shoptron shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2000-0103
The SmartCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2000-0102
The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2000-0101
The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2000-0100
The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program.
CVE-2000-0099
Buffer overflow in UnixWare ppptalk command allows local users to gain privileges via a long prompt argument.
CVE-2000-0098
Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist.
CVE-2000-0097
The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability.
CVE-2000-0096
Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command.
CVE-2000-0095
The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier.
CVE-2000-0094
procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.
CVE-2000-0093
An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.
CVE-2000-0092
The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.
CVE-2000-0091
Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.
CVE-2000-0090
VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.
CVE-2000-0089
The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.
CVE-2000-0088
Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability.
CVE-2000-0087
Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.
CVE-2000-0086
Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.
CVE-2000-0085
Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2000-0104 The Shoptron shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | CVSS2: 7.5 | 1% Низкий | около 26 лет назад | |
CVE-2000-0103 The SmartCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | CVSS2: 7.5 | 1% Низкий | около 26 лет назад | |
CVE-2000-0102 The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | CVSS2: 7.5 | 1% Низкий | около 26 лет назад | |
CVE-2000-0101 The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | CVSS2: 7.5 | 1% Низкий | около 26 лет назад | |
CVE-2000-0100 The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program. | CVSS2: 7.2 | 1% Низкий | около 26 лет назад | |
CVE-2000-0099 Buffer overflow in UnixWare ppptalk command allows local users to gain privileges via a long prompt argument. | CVSS2: 7.2 | 0% Низкий | около 26 лет назад | |
CVE-2000-0098 Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist. | CVSS2: 5 | 83% Высокий | около 26 лет назад | |
CVE-2000-0097 The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability. | CVSS2: 5 | 61% Средний | около 26 лет назад | |
CVE-2000-0096 Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command. | CVSS2: 7.2 | 0% Низкий | около 26 лет назад | |
CVE-2000-0095 The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier. | CVSS2: 5 | 1% Низкий | около 26 лет назад | |
CVE-2000-0094 procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr. | CVSS2: 7.2 | 0% Низкий | почти 26 лет назад | |
CVE-2000-0093 An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5. | CVSS2: 10 | 0% Низкий | около 26 лет назад | |
CVE-2000-0092 The BSD make program allows local users to modify files via a symlink attack when the -j option is being used. | CVSS2: 6.2 | 0% Низкий | около 26 лет назад | |
CVE-2000-0091 Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password. | CVSS2: 10 | 2% Низкий | около 26 лет назад | |
CVE-2000-0090 VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack. | CVSS2: 3.6 | 0% Низкий | около 26 лет назад | |
CVE-2000-0089 The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability. | CVSS2: 2.1 | 2% Низкий | около 26 лет назад | |
CVE-2000-0088 Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability. | CVSS2: 7.2 | 1% Низкий | около 26 лет назад | |
CVE-2000-0087 Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext. | CVSS2: 5 | 1% Низкий | около 26 лет назад | |
CVE-2000-0086 Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing. | CVSS2: 5 | 1% Низкий | около 26 лет назад | |
CVE-2000-0085 Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag. | CVSS2: 7.5 | 12% Средний | около 26 лет назад |
Уязвимостей на страницу