Количество 343 490
Количество 343 490
CVE-2000-0733
Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.
CVE-2000-0732
Worm HTTP server allows remote attackers to cause a denial of service via a long URL.
CVE-2000-0731
Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2000-0730
Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.
CVE-2000-0729
FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.
CVE-2000-0728
xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.
CVE-2000-0727
xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.
CVE-2000-0726
CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the file in the $Attach$ hidden form variable.
CVE-2000-0725
Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.
CVE-2000-0724
The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files.
CVE-2000-0723
Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config.
CVE-2000-0722
Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages.
CVE-2000-0721
The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses.
CVE-2000-0720
news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.
CVE-2000-0719
VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program.
CVE-2000-0718
A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed.
CVE-2000-0717
GoodTech FTP server allows remote attackers to cause a denial of service via a large number of RNTO commands.
CVE-2000-0716
WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijack the session ID and read the user's email.
CVE-2000-0715
DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symlink attack on a temporary file.
CVE-2000-0714
umb-scheme 3.2-11 for Red Hat Linux is installed with world-writeable files.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2000-0733 Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request. | CVSS2: 10 | 6% Низкий | больше 25 лет назад | |
CVE-2000-0732 Worm HTTP server allows remote attackers to cause a denial of service via a long URL. | CVSS2: 5 | 1% Низкий | больше 25 лет назад | |
CVE-2000-0731 Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack. | CVSS2: 5 | 1% Низкий | больше 25 лет назад | |
CVE-2000-0730 Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges. | CVSS2: 4.6 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0729 FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header. | CVSS2: 2.1 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0728 xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack. | CVSS2: 7.2 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0727 xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters. | CVSS2: 7.6 | 1% Низкий | больше 25 лет назад | |
CVE-2000-0726 CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the file in the $Attach$ hidden form variable. | CVSS2: 2.6 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0725 Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request. | CVSS2: 7.2 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0724 The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files. | CVSS2: 6.2 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0723 Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config. | CVSS2: 1.2 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0722 Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages. | CVSS2: 6.2 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0721 The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses. | CVSS2: 6.2 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0720 news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program. | CVSS2: 5 | 4% Низкий | больше 25 лет назад | |
CVE-2000-0719 VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program. | CVSS2: 6.2 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0718 A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed. | CVSS2: 1.2 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0717 GoodTech FTP server allows remote attackers to cause a denial of service via a large number of RNTO commands. | CVSS2: 5 | 1% Низкий | больше 25 лет назад | |
CVE-2000-0716 WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijack the session ID and read the user's email. | CVSS2: 2.6 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0715 DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symlink attack on a temporary file. | CVSS2: 2.1 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0714 umb-scheme 3.2-11 for Red Hat Linux is installed with world-writeable files. | CVSS2: 7.2 | 0% Низкий | больше 25 лет назад |
Уязвимостей на страницу