Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by NVD-CWE-Other
Total 27865 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0701 3 Conectiva, Gnu, Redhat 3 Linux, Mailman, Linux 2008-09-10 4.6 MEDIUM N/A
The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.
CVE-2000-0703 1 Larry Wall 1 Perl 2008-09-10 7.2 HIGH N/A
suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a filename that contains the escape sequence.
CVE-2000-0714 1 University Of Massachusetts 1 Scheme 2008-09-10 7.2 HIGH N/A
umb-scheme 3.2-11 for Red Hat Linux is installed with world-writeable files.
CVE-2000-0725 1 Zope 1 Zope 2008-09-10 7.2 HIGH N/A
Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.
CVE-2000-0750 3 Netbsd, Openbsd, Redhat 3 Netbsd, Openbsd, Linux 2008-09-10 7.5 HIGH N/A
Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.
CVE-2000-0779 1 Checkpoint 1 Firewall-1 2008-09-10 7.5 HIGH N/A
Checkpoint Firewall-1 with the RSH/REXEC setting enabled allows remote attackers to bypass access restrictions and connect to a RSH/REXEC client via malformed connection requests.
CVE-2000-0787 1 Xchat 1 Xchat 2008-09-10 7.5 HIGH N/A
IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser.
CVE-2000-0800 1 Suse 1 Suse Linux 2008-09-10 10.0 HIGH N/A
String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.
CVE-2000-0616 1 Hp 1 Mpe Ix 2008-09-10 4.6 MEDIUM N/A
Vulnerability in HP TurboIMAGE DBUTIL allows local users to gain additional privileges via DBUTIL.PUB.SYS.
CVE-2000-0535 2 Freebsd, Openssl 2 Freebsd, Openssl 2008-09-10 5.0 MEDIUM N/A
OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken.
CVE-2000-0544 1 Microsoft 2 Windows 2000, Windows Nt 2008-09-10 5.0 MEDIUM N/A
Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.
CVE-2000-0545 1 Sgi 1 Mailx 2008-09-10 4.6 MEDIUM N/A
Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (carbon copy) parameter.
CVE-2000-0554 1 Lilikoi 1 Ceilidh 2008-09-10 5.0 MEDIUM N/A
Ceilidh allows remote attackers to obtain the real path of the Ceilidh directory via the translated_path hidden form field.
CVE-2000-0283 1 Sgi 1 Irix 2008-09-10 6.4 MEDIUM N/A
The default installation of IRIX Performance Copilot allows remote attackers to access sensitive system information via the pmcd daemon.
CVE-2000-0284 1 University Of Washington 1 Imap 2008-09-10 7.5 HIGH N/A
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.
CVE-2000-0285 1 Xfree86 Project 1 X11r6 2008-09-10 7.2 HIGH N/A
Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter.
CVE-2000-0286 1 Redhat 1 Linux 2008-09-10 2.1 LOW N/A
X fontserver xfs allows local users to cause a denial of service via malformed input to the server.
CVE-2000-0287 1 Cnc 1 Technology Bizdb 2008-09-10 10.0 HIGH N/A
The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter.
CVE-2000-0288 2008-09-10 5.0 MEDIUM N/A
Infonautics getdoc.cgi allows remote attackers to bypass the payment phase for accessing documents via a modified form variable.
CVE-2000-0289 3 Debian, Linux, Redhat 3 Debian Linux, Linux Kernel, Linux 2008-09-10 5.0 MEDIUM N/A
IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection.