Количество 365 269
Количество 365 269
CVE-2000-0879
LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.
CVE-2000-0878
The mailto CGI script allows remote attacker to execute arbitrary commands via shell metacharacters in the emailadd form field.
CVE-2000-0877
mailform.pl CGI script in MailForm 2.0 allows remote attackers to read arbitrary files by specifying the file name in the XX-attach_file parameter, which MailForm then sends to the attacker.
CVE-2000-0876
WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname.
CVE-2000-0875
WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to cause a denial of service by sending a long string of unprintable characters.
CVE-2000-0874
Eudora mail client includes the absolute path of the sender's host within a virtual card (VCF).
CVE-2000-0873
netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.
CVE-2000-0872
explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2000-0871
Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server.
CVE-2000-0870
Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string.
CVE-2000-0869
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
CVE-2000-0868
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
CVE-2000-0867
Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.
CVE-2000-0866
Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes.
CVE-2000-0865
Buffer overflow in dvtermtype in Tridia Double Vision 3.07.00 allows local users to gain root privileges via a long terminal type argument.
CVE-2000-0864
Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileges, via a symlink attack.
CVE-2000-0863
Buffer overflow in listmanager earlier than 2.105.1 allows local users to gain additional privileges.
CVE-2000-0862
Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information.
CVE-2000-0861
Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion.
CVE-2000-0860
The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2000-0879 LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services. | CVSS2: 2.1 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0878 The mailto CGI script allows remote attacker to execute arbitrary commands via shell metacharacters in the emailadd form field. | CVSS2: 7.5 | 2% Низкий | больше 25 лет назад | |
CVE-2000-0877 mailform.pl CGI script in MailForm 2.0 allows remote attackers to read arbitrary files by specifying the file name in the XX-attach_file parameter, which MailForm then sends to the attacker. | CVSS2: 5 | 2% Низкий | больше 25 лет назад | |
CVE-2000-0876 WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname. | CVSS2: 5 | 2% Низкий | больше 25 лет назад | |
CVE-2000-0875 WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to cause a denial of service by sending a long string of unprintable characters. | CVSS2: 5 | 2% Низкий | больше 25 лет назад | |
CVE-2000-0874 Eudora mail client includes the absolute path of the sender's host within a virtual card (VCF). | CVSS2: 5 | 1% Низкий | больше 25 лет назад | |
CVE-2000-0873 netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities. | CVSS2: 2.1 | 1% Низкий | больше 25 лет назад | |
CVE-2000-0872 explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | CVSS2: 5 | 7% Низкий | больше 25 лет назад | |
CVE-2000-0871 Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server. | CVSS2: 5 | 2% Низкий | больше 25 лет назад | |
CVE-2000-0870 Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string. | CVSS2: 7.5 | 2% Низкий | больше 25 лет назад | |
CVE-2000-0869 The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method. | CVSS2: 5 | 51% Средний | больше 25 лет назад | |
CVE-2000-0868 The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/. | CVSS2: 5 | 45% Средний | больше 25 лет назад | |
CVE-2000-0867 Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages. | CVSS2: 7.2 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0866 Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes. | CVSS2: 2.1 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0865 Buffer overflow in dvtermtype in Tridia Double Vision 3.07.00 allows local users to gain root privileges via a long terminal type argument. | CVSS2: 7.2 | 1% Низкий | больше 25 лет назад | |
CVE-2000-0864 Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileges, via a symlink attack. | CVSS2: 6.2 | 1% Низкий | больше 25 лет назад | |
CVE-2000-0863 Buffer overflow in listmanager earlier than 2.105.1 allows local users to gain additional privileges. | CVSS2: 7.2 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0862 Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information. | CVSS2: 6.4 | 1% Низкий | больше 25 лет назад | |
CVE-2000-0861 Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion. | CVSS2: 7.2 | 1% Низкий | больше 25 лет назад | |
CVE-2000-0860 The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables. | CVSS2: 5 | 3% Низкий | больше 25 лет назад |
Уязвимостей на страницу