-
CVE-2000-0749
•
published on January 22, 2001
Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system.
-
CVE-2000-0764
•
published on January 22, 2001
Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed IP packet.
-
CVE-2000-0783
•
published on January 22, 2001
Watchguard Firebox II allows remote attackers to cause a denial of service by sending a malformed URL to the authentication service on port 4100.
-
CVE-2000-0844
•
published on January 22, 2001
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
-
CVE-2000-0848
•
published on January 22, 2001
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.
-
CVE-2000-0852
•
published on January 22, 2001
Multiple buffer overflows in eject on FreeBSD and possibly other OSes allows local users to gain root privileges.
-
CVE-2000-0863
•
published on January 22, 2001
Buffer overflow in listmanager earlier than 2.105.1 allows local users to gain additional privileges.
-
CVE-2000-0868
•
published on January 22, 2001
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
-
CVE-2000-0871
•
published on January 22, 2001
Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server.
-
CVE-2000-0878
•
published on January 22, 2001
The mailto CGI script allows remote attacker to execute arbitrary commands via shell metacharacters in the emailadd form field.
-
CVE-2000-0883
•
published on January 22, 2001
The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.
-
CVE-2000-0888
•
published on January 22, 2001
named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the "srv bug."
-
CVE-2000-0702
•
published on January 22, 2001
The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.
-
CVE-2000-0806
•
published on January 22, 2001
The inter-module authentication mechanism (fwa1) in Check Point VPN-1/FireWall-1 4.1 and earlier may allow remote attackers to conduct a denial of service, aka "Inter-module Communications Bypass."
-
CVE-2000-0824
•
published on January 22, 2001
The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.
-
CVE-2000-0834
•
published on January 22, 2001
The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability.
-
CVE-2000-0849
•
published on January 22, 2001
Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.
-
CVE-2000-0850
•
published on January 22, 2001
Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested URL.
-
CVE-2000-0861
•
published on January 22, 2001
Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion.
-
CVE-2000-0862
•
published on January 22, 2001
Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information.