Количество 376 173
Количество 376 173
CVE-2000-0094
procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.
CVE-2000-0093
An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.
CVE-2000-0092
The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.
CVE-2000-0091
Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.
CVE-2000-0090
VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.
CVE-2000-0089
The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.
CVE-2000-0088
Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability.
CVE-2000-0087
Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.
CVE-2000-0086
Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.
CVE-2000-0085
Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.
CVE-2000-0084
CuteFTP uses weak encryption to store password information in its tree.dat file.
CVE-2000-0083
HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.
CVE-2000-0082
WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML.
CVE-2000-0081
Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript.
CVE-2000-0080
AIX techlibss allows local users to overwrite files via a symlink attack.
CVE-2000-0079
The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.
CVE-2000-0078
The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.
CVE-2000-0077
The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.
CVE-2000-0076
nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.
CVE-2000-0075
Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a denial of service by repeating multiple HELO, MAIL FROM, RCPT TO, and DATA commands in the same session.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2000-0094 procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr. | CVSS2: 7.2 | 1% Низкий | больше 26 лет назад | |
CVE-2000-0093 An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5. | CVSS2: 10 | 1% Низкий | больше 26 лет назад | |
CVE-2000-0092 The BSD make program allows local users to modify files via a symlink attack when the -j option is being used. | CVSS2: 6.2 | 0% Низкий | больше 26 лет назад | |
CVE-2000-0091 Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password. | CVSS2: 10 | 13% Средний | больше 26 лет назад | |
CVE-2000-0090 VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack. | CVSS2: 3.6 | 0% Низкий | больше 26 лет назад | |
CVE-2000-0089 The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability. | CVSS2: 2.1 | 2% Низкий | больше 26 лет назад | |
CVE-2000-0088 Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability. | CVSS2: 7.2 | 2% Низкий | больше 26 лет назад | |
CVE-2000-0087 Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext. | CVSS2: 5 | 1% Низкий | больше 26 лет назад | |
CVE-2000-0086 Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing. | CVSS2: 5 | 1% Низкий | больше 26 лет назад | |
CVE-2000-0085 Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag. | CVSS2: 7.5 | 15% Средний | больше 26 лет назад | |
CVE-2000-0084 CuteFTP uses weak encryption to store password information in its tree.dat file. | CVSS2: 5 | 1% Низкий | больше 26 лет назад | |
CVE-2000-0083 HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges. | CVSS2: 4.6 | 0% Низкий | больше 26 лет назад | |
CVE-2000-0082 WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML. | CVSS2: 5 | 15% Средний | больше 26 лет назад | |
CVE-2000-0081 Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript. | CVSS2: 10 | 19% Средний | больше 26 лет назад | |
CVE-2000-0080 AIX techlibss allows local users to overwrite files via a symlink attack. | CVSS2: 2.1 | 0% Низкий | больше 26 лет назад | |
CVE-2000-0079 The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL. | CVSS2: 7.5 | 2% Низкий | больше 26 лет назад | |
CVE-2000-0078 The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command. | CVSS2: 7.2 | 1% Низкий | больше 26 лет назад | |
CVE-2000-0077 The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands. | CVSS2: 7.2 | 1% Низкий | больше 26 лет назад | |
CVE-2000-0076 nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover. | CVSS2: 2.1 | 0% Низкий | больше 26 лет назад | |
CVE-2000-0075 Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a denial of service by repeating multiple HELO, MAIL FROM, RCPT TO, and DATA commands in the same session. | CVSS2: 5 | 2% Низкий | больше 26 лет назад |
Уязвимостей на страницу