-
CVE-2000-0090
•
published on October 13, 2000
VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.
-
CVE-2000-0116
•
published on October 13, 2000
Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra in front of the SCRIPT tag.
-
CVE-2000-0094
•
published on October 13, 2000
procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.
-
CVE-2000-0127
•
published on October 13, 2000
The Webspeed configuration program does not properly disable access to the WSMadmin utility, which allows remote attackers to gain privileges via wsisa.dll.
-
CVE-2000-0128
•
published on October 13, 2000
The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters.
-
CVE-2000-0130
•
published on October 13, 2000
Buffer overflow in SCO scohelp program allows remote attackers to execute commands.
-
CVE-2000-0146
•
published on October 13, 2000
The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet.
-
CVE-2000-0179
•
published on October 13, 2000
HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555.
-
CVE-2000-0166
•
published on October 13, 2000
Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login name.
-
CVE-2000-0141
•
published on October 13, 2000
Infopop Ultimate Bulletin Board (UBB) allows remote attackers to execute commands via shell metacharacters in the topic hidden field.
-
CVE-2000-0164
•
published on October 13, 2000
The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords.
-
CVE-2000-0191
•
published on October 13, 2000
Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.
-
CVE-2000-0193
•
published on October 13, 2000
The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain privileges.
-
CVE-2000-0257
•
published on October 13, 2000
Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long URL.
-
CVE-2000-0263
•
published on October 13, 2000
The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.
-
CVE-2000-0265
•
published on October 13, 2000
Panda Security 3.0 allows users to uninstall the Panda software via its Add/Remove Programs applet.
-
CVE-2000-0285
•
published on October 13, 2000
Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter.
-
CVE-2000-0301
•
published on October 13, 2000
Ipswitch IMAIL server 6.02 and earlier allows remote attackers to cause a denial of service via the AUTH CRAM-MD5 command.
-
CVE-2000-0319
•
published on October 13, 2000
mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.
-
CVE-2000-0237
•
published on October 13, 2000
Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories.