CVE-2000-1000 to CVE-2000-1999
85 CVEs with public proof-of-concept exploits.
- CVE-2000-10021 PoCPOP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which…
- CVE-2000-10051 PoCDirectory traversal vulnerability in html_web_store.cgi and web_store.cgi CGI programs in eXtropia WebStore allows remote attackers to…
- CVE-2000-10081 PoCPalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device…
- CVE-2000-10092 PoCsdump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root…
- CVE-2000-10141 PoCFormat string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute…
- CVE-2000-10161 PoCThe default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers…
- CVE-2000-10211 PoCHeap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute…
- CVE-2000-10221 PoCThe mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows…
- CVE-2000-10231 PoCThe Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain…
- CVE-2000-10251 PoCeWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that…
- CVE-2000-10261 PoCMultiple buffer overflows in LBNL tcpdump allow remote attackers to execute arbitrary commands.
- CVE-2000-10271 PoCCisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server…
- CVE-2000-10282 PoCsBuffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.
- CVE-2000-10291 PoCBuffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query.
- CVE-2000-10331 PoCServ-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous)…
- CVE-2000-10351 PoCBuffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute…
- CVE-2000-10361 PoCDirectory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via a .. (dot dot)…
- CVE-2000-10372 PoCsCheck Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords,…
- CVE-2000-10401 PoCFormat string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker…
- CVE-2000-10461 PoCMultiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and…
- CVE-2000-10501 PoCAllaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an…
- CVE-2000-10531 PoCAllaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack…
- CVE-2000-10541 PoCBuffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and…
- CVE-2000-10581 PoCBuffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attackers to cause a…
- CVE-2000-10611 PoCMicrosoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX controls, which allows…
- CVE-2000-10691 PoCpollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by…
- CVE-2000-10721 PoCiCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and…
- CVE-2000-10741 PoCcsstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser…
- CVE-2000-10752 PoCsDirectory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read…
- CVE-2000-10781 PoCICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.
- CVE-2000-10811 PoCThe xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a…
- CVE-2000-10831 PoCThe xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer…
- CVE-2000-10851 PoCThe xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a…
- CVE-2000-10893 PoCsBuffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer…
- CVE-2000-10921 PoCloadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by…
- CVE-2000-10931 PoCBuffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.
- CVE-2000-10941 PoCBuffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon"…
- CVE-2000-10952 PoCsmodprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.
- CVE-2000-10961 PoCcrontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user…
- CVE-2000-11001 PoCThe default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which…
- CVE-2000-11032 PoCsrcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by…
- CVE-2000-11051 PoCThe ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely…
- CVE-2000-11101 PoCdocument.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by…
- CVE-2000-11121 PoCMicrosoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a…
- CVE-2000-11131 PoCBuffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream…
- CVE-2000-11141 PoCUnify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as…
- CVE-2000-11161 PoCBuffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute…
- CVE-2000-11191 PoCBuffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.
- CVE-2000-11201 PoCBuffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.
- CVE-2000-11211 PoCBuffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.
- CVE-2000-11241 PoCBuffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.
- CVE-2000-11254 PoCsrestore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users…
- CVE-2000-11271 PoCregistrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log…
- CVE-2000-11281 PoCThe default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows…
- CVE-2000-11291 PoCMcAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.
- CVE-2000-11321 PoCDCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum"…
- CVE-2000-11342 PoCsMultiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing <<…
- CVE-2000-11401 PoCRecourse ManTrap 1.6 does not properly hide processes from attackers, which could allow attackers to determine that they are in a honeypot…
- CVE-2000-11441 PoCRecourse ManTrap 1.6 sets up a chroot environment to hide the fact that it is running, but the inode number for the resulting "/" file…
- CVE-2000-11471 PoCBuffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE"…
- CVE-2000-11541 PoCRHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.
- CVE-2000-11691 PoCOpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access…
- CVE-2000-11711 PoCDirectory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot…
- CVE-2000-11731 PoCMicrosys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the…
- CVE-2000-11742 PoCsMultiple buffer overflows in AFS ACL parser for Ethereal 0.8.13 and earlier allows remote attackers to execute arbitrary commands via a…
- CVE-2000-11752 PoCsBuffer overflow in Koules 1.4 allows local users to execute arbitrary commands via a long command line argument.
- CVE-2000-11761 PoCDirectory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack…
- CVE-2000-11771 PoCbb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers…
- CVE-2000-11801 PoCBuffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line…
- CVE-2000-11811 PoCReal Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including…
- CVE-2000-11831 PoCBuffer overflow in socks5 server on Linux allows attackers to execute arbitrary commands via a long connection request.
- CVE-2000-11862 PoCsBuffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and…
- CVE-2000-11931 PoCPerformance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service…
- CVE-2000-11962 PoCsPSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file…
- CVE-2000-11981 PoCqpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack…
- CVE-2000-11991 PoCPostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges…
- CVE-2000-12094 PoCsThe "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine…
- CVE-2000-12202 PoCsThe line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing…
- CVE-2000-12212 PoCsThe line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved…
- CVE-2000-12241 PoCCaucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with…
- CVE-2000-12281 PoCPhorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that…
- CVE-2000-12301 PoCBackdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER…
- CVE-2000-12341 PoCviolation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by…
- CVE-2000-12431 PoCPrivacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an…
- CVE-2000-12441 PoCComputer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the…