Количество 371 863
Количество 371 863
CVE-2000-0384
NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC address, which could allow remote attackers to gain root access.
CVE-2000-0383
The file transfer component of AOL Instant Messenger (AIM) reveals the physical path of the transferred file to the remote recipient.
CVE-2000-0382
ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site.
CVE-2000-0381
The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existing database in the db parameter.
CVE-2000-0380
The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.
CVE-2000-0379
The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so.
CVE-2000-0378
The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.
CVE-2000-0377
The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability.
CVE-2000-0376
Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request.
CVE-2000-0375
The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files.
CVE-2000-0374
The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions.
CVE-2000-0373
Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges.
CVE-2000-0372
Vulnerability in Caldera rmt command in the dump package 0.4b4 allows a local user to gain root privileges.
CVE-2000-0371
The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack.
CVE-2000-0370
The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.
CVE-2000-0369
The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows remote attackers to cause a denial of service.
CVE-2000-0368
Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data.
CVE-2000-0367
Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.
CVE-2000-0366
dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.
CVE-2000-0365
Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2000-0384 NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC address, which could allow remote attackers to gain root access. | CVSS2: 10 | 6% Низкий | около 26 лет назад | |
CVE-2000-0383 The file transfer component of AOL Instant Messenger (AIM) reveals the physical path of the transferred file to the remote recipient. | CVSS2: 5 | 1% Низкий | около 26 лет назад | |
CVE-2000-0382 ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site. | CVSS2: 2.6 | 1% Низкий | около 26 лет назад | |
CVE-2000-0381 The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existing database in the db parameter. | CVSS2: 6.4 | 3% Низкий | около 26 лет назад | |
CVE-2000-0380 The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string. | CVSS2: 7.1 | 35% Средний | больше 26 лет назад | |
CVE-2000-0379 The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so. | CVSS2: 3.6 | 2% Низкий | около 26 лет назад | |
CVE-2000-0378 The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in. | CVSS2: 7.2 | 1% Низкий | около 26 лет назад | |
CVE-2000-0377 The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability. | CVSS2: 5 | 19% Средний | около 26 лет назад | |
CVE-2000-0376 Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request. | CVSS2: 10 | 3% Низкий | около 26 лет назад | |
CVE-2000-0375 The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files. | CVSS2: 2.1 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0374 The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions. | CVSS2: 10 | 4% Низкий | почти 27 лет назад | |
CVE-2000-0373 Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges. | CVSS2: 7.2 | 0% Низкий | около 27 лет назад | |
CVE-2000-0372 Vulnerability in Caldera rmt command in the dump package 0.4b4 allows a local user to gain root privileges. | CVSS2: 7.2 | 0% Низкий | около 26 лет назад | |
CVE-2000-0371 The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack. | CVSS2: 1.2 | 0% Низкий | больше 27 лет назад | |
CVE-2000-0370 The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command. | CVSS2: 10 | 5% Низкий | больше 27 лет назад | |
CVE-2000-0369 The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows remote attackers to cause a denial of service. | CVSS2: 5 | 2% Низкий | почти 27 лет назад | |
CVE-2000-0368 Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data. | CVSS2: 2.1 | 0% Низкий | больше 25 лет назад | |
CVE-2000-0367 Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges. | CVSS2: 7.2 | 0% Низкий | больше 27 лет назад | |
CVE-2000-0366 dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files. | CVSS2: 2.1 | 0% Низкий | больше 26 лет назад | |
CVE-2000-0365 Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices. | CVSS2: 4.6 | 0% Низкий | около 27 лет назад |
Уязвимостей на страницу