Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2000-1207

почти 26 лет назад

userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2000-1206

почти 27 лет назад

Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-1205

больше 26 лет назад

Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2000-1204

почти 26 лет назад

Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2000-1203

почти 25 лет назад

Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-1202

почти 25 лет назад

ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2000-1201

почти 25 лет назад

Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-1200

почти 25 лет назад

Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2000-1199

почти 25 лет назад

PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2000-1198

почти 25 лет назад

qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2000-1197

почти 25 лет назад

POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2000-1196

почти 25 лет назад

PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-1195

почти 25 лет назад

telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-1194

почти 25 лет назад

Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-1193

почти 25 лет назад

Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-1192

почти 25 лет назад

Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-1191

почти 25 лет назад

htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-1190

почти 25 лет назад

imwheel-solo in imwheel package allows local users to modify arbitrary files via a symlink attack from the .imwheelrc file.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2000-1189

больше 25 лет назад

Buffer overflow in pam_localuser PAM module in Red Hat Linux 7.x and 6.x allows attackers to gain privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2000-1188

больше 25 лет назад

Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2000-1207

userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).

CVSS2: 7.2
0%
Низкий
почти 26 лет назад
nvd логотип
CVE-2000-1206

Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.

CVSS2: 5
5%
Низкий
почти 27 лет назад
nvd логотип
CVE-2000-1205

Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.

CVSS2: 4.3
24%
Средний
больше 26 лет назад
nvd логотип
CVE-2000-1204

Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.

CVSS2: 5
10%
Средний
почти 26 лет назад
nvd логотип
CVE-2000-1203

Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.

CVSS2: 5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1202

ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.

CVSS2: 7.2
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1201

Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264.

CVSS2: 5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1200

Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.

CVSS2: 5
48%
Средний
почти 25 лет назад
nvd логотип
CVE-2000-1199

PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.

CVSS2: 4.6
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1198

qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.

CVSS3: 5.5
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1197

POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.

CVSS2: 2.1
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1196

PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.

CVSS2: 5
4%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1195

telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option.

CVSS2: 7.5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1194

Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.

CVSS2: 7.5
3%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1193

Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port.

CVSS2: 5
3%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1192

Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap.

CVSS2: 7.5
3%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1191

htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.

CVSS2: 5
3%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1190

imwheel-solo in imwheel package allows local users to modify arbitrary files via a symlink attack from the .imwheelrc file.

CVSS2: 2.1
0%
Низкий
почти 25 лет назад
nvd логотип
CVE-2000-1189

Buffer overflow in pam_localuser PAM module in Red Hat Linux 7.x and 6.x allows attackers to gain privileges.

CVSS2: 7.2
0%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-1188

Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter.

CVSS2: 5
2%
Низкий
больше 25 лет назад

Уязвимостей на страницу