Total
27865 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2001-0232 | 1 Ibrow | 1 News Desk | 2008-09-05 | 5.0 MEDIUM | N/A |
newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters. | |||||
CVE-2001-0220 | 2 Ja-elvis, Ko-helvis | 2 Ja-elvis, Ko-helvis | 2008-09-05 | 7.2 HIGH | N/A |
Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges. | |||||
CVE-2001-0229 | 1 Sun | 1 Chilisoft | 2008-09-05 | 7.2 HIGH | N/A |
Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts. | |||||
CVE-2001-0320 | 1 Francisco Burzi | 1 Php-nuke | 2008-09-05 | 10.0 HIGH | N/A |
bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument. | |||||
CVE-2001-0275 | 1 Moby | 1 Netsuite Web Server | 2008-09-05 | 2.1 LOW | N/A |
Moby Netsuite Web Server 1.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request. | |||||
CVE-2001-0214 | 1 Way | 1 Way-board | 2008-09-05 | 5.0 MEDIUM | N/A |
Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte. | |||||
CVE-2001-0312 | 1 Ibm | 1 Websphere Plugin | 2008-09-05 | 5.0 MEDIUM | N/A |
IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing. | |||||
CVE-2000-1235 | 1 Oracle | 1 Application Server | 2008-09-05 | 5.0 MEDIUM | N/A |
The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files. | |||||
CVE-2000-0856 | 1 Xs4all Data | 1 Xs4all Data Sunftp | 2008-09-05 | 7.5 HIGH | N/A |
Buffer overflow in SunFTP build 9(1) allows remote attackers to cause a denial of service or possibly execute arbitrary commands via a long GET request. | |||||
CVE-2000-0842 | 1 Sco | 1 Unixware | 2008-09-05 | 5.0 MEDIUM | N/A |
The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |||||
CVE-2000-0843 | 2 Dave Airlie, Luke Kenneth Casson Leighton | 2 Pam Smb, Pam Ntdom | 2008-09-05 | 10.0 HIGH | N/A |
Buffer overflow in pam_smb and pam_ntdom pluggable authentication modules (PAM) allow remote attackers to execute arbitrary commands via a login with a long user name. | |||||
CVE-2000-0845 | 1 Digital | 1 Unix | 2008-09-05 | 6.4 MEDIUM | N/A |
kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet. | |||||
CVE-2000-0855 | 1 Xs4all Data | 1 Xs4all Data Sunftp | 2008-09-05 | 5.0 MEDIUM | N/A |
SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline. | |||||
CVE-2000-0882 | 1 Intel | 4 Express 510t, Express 520t, Express 550f and 1 more | 2008-09-05 | 5.0 MEDIUM | N/A |
Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash. | |||||
CVE-2000-0893 | 1 Sgi | 1 Irix | 2008-09-05 | 5.0 MEDIUM | N/A |
The presence of the Distributed GL Daemon (dgld) service on port 5232 on SGI IRIX systems allows remote attackers to identify the target host as an SGI system. | |||||
CVE-2000-0903 | 1 Qnx | 1 Voyager | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |||||
CVE-2000-0904 | 1 Qnx | 1 Voyager | 2008-09-05 | 5.0 MEDIUM | N/A |
Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information. | |||||
CVE-2000-0905 | 1 Qnx | 1 Voyager | 2008-09-05 | 5.0 MEDIUM | N/A |
QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page. | |||||
CVE-2000-0907 | 1 Etype | 1 Eserv | 2008-09-05 | 7.5 HIGH | N/A |
EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands. | |||||
CVE-2000-0916 | 1 Freebsd | 1 Freebsd | 2008-09-05 | 7.5 HIGH | N/A |
FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections. |