Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2000-0885

больше 25 лет назад

Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2000-0884

больше 25 лет назад

IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.

CVSS2: 7.5
EPSS: Высокий
nvd логотип

CVE-2000-0883

больше 25 лет назад

The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0882

больше 25 лет назад

Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0881

больше 25 лет назад

The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2000-0880

больше 25 лет назад

LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2000-0879

больше 25 лет назад

LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2000-0878

больше 25 лет назад

The mailto CGI script allows remote attacker to execute arbitrary commands via shell metacharacters in the emailadd form field.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-0877

больше 25 лет назад

mailform.pl CGI script in MailForm 2.0 allows remote attackers to read arbitrary files by specifying the file name in the XX-attach_file parameter, which MailForm then sends to the attacker.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0876

больше 25 лет назад

WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0875

больше 25 лет назад

WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to cause a denial of service by sending a long string of unprintable characters.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0874

больше 25 лет назад

Eudora mail client includes the absolute path of the sender's host within a virtual card (VCF).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0873

больше 25 лет назад

netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2000-0872

больше 25 лет назад

explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0871

больше 25 лет назад

Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2000-0870

больше 25 лет назад

Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2000-0869

больше 25 лет назад

The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2000-0868

больше 25 лет назад

The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2000-0867

больше 25 лет назад

Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2000-0866

больше 25 лет назад

Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2000-0885

Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates.

CVSS2: 7.5
13%
Средний
больше 25 лет назад
nvd логотип
CVE-2000-0884

IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.

CVSS2: 7.5
71%
Высокий
больше 25 лет назад
nvd логотип
CVE-2000-0883

The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.

CVSS2: 5
9%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0882

Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash.

CVSS2: 5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0881

The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.

CVSS2: 2.1
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0880

LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file.

CVSS2: 3.6
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0879

LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.

CVSS2: 2.1
0%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0878

The mailto CGI script allows remote attacker to execute arbitrary commands via shell metacharacters in the emailadd form field.

CVSS2: 7.5
2%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0877

mailform.pl CGI script in MailForm 2.0 allows remote attackers to read arbitrary files by specifying the file name in the XX-attach_file parameter, which MailForm then sends to the attacker.

CVSS2: 5
2%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0876

WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname.

CVSS2: 5
2%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0875

WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to cause a denial of service by sending a long string of unprintable characters.

CVSS2: 5
2%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0874

Eudora mail client includes the absolute path of the sender's host within a virtual card (VCF).

CVSS2: 5
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0873

netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.

CVSS2: 2.1
1%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0872

explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVSS2: 5
7%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0871

Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server.

CVSS2: 5
2%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0870

Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string.

CVSS2: 7.5
2%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0869

The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.

CVSS2: 5
51%
Средний
больше 25 лет назад
nvd логотип
CVE-2000-0868

The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.

CVSS2: 5
45%
Средний
больше 25 лет назад
nvd логотип
CVE-2000-0867

Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.

CVSS2: 7.2
0%
Низкий
больше 25 лет назад
nvd логотип
CVE-2000-0866

Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes.

CVSS2: 2.1
0%
Низкий
больше 25 лет назад

Уязвимостей на страницу