-
CVE-2000-0601
•
published on October 13, 2000
LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages.
-
CVE-2000-0603
•
published on October 13, 2000
Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the "Stored Procedure Permissions" vulnerability.
-
CVE-2000-0604
•
published on October 13, 2000
gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uucp.
-
CVE-2000-0611
•
published on October 13, 2000
The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service.
-
CVE-2000-0628
•
published on October 13, 2000
The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.
-
CVE-2000-0634
•
published on October 13, 2000
The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.
-
CVE-2000-0635
•
published on October 13, 2000
The view_page.html sample page in the MiniVend shopping cart program allows remote attackers to execute arbitrary commands via shell metacharacters.
-
CVE-2000-0639
•
published on October 13, 2000
The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server.
-
CVE-2000-0641
•
published on October 13, 2000
Savant web server allows remote attackers to execute arbitrary commands via a long GET request.
-
CVE-2000-0522
•
published on October 13, 2000
RSA ACE/Server allows remote attackers to cause a denial of service by flooding the server's authentication request port with UDP packets, which causes the server to crash.
-
CVE-2000-0536
•
published on October 13, 2000
xinetd 2.1.8.x does not properly restrict connections if hostnames are used for access control and the connecting host does not have a reverse DNS entry.
-
CVE-2000-0539
•
published on October 13, 2000
Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession ID's via the SessionServlet servlet.
-
CVE-2000-0553
•
published on October 13, 2000
Race condition in IPFilter firewall 3.4.3 and earlier, when configured with overlapping "return-rst" and "keep state" rules, allows remote attackers to bypass access restrictions.
-
CVE-2000-0557
•
published on October 13, 2000
Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to execute arbitrary commands via a long GET request.
-
CVE-2000-0566
•
published on October 13, 2000
makewhatis in Linux man package allows local users to overwrite files via a symlink attack.
-
CVE-2000-0586
•
published on October 13, 2000
Buffer overflow in Dalnet IRC server 4.6.5 allows remote attackers to cause a denial of service or execute arbitrary commands via the SUMMON command.
-
CVE-2000-0613
•
published on October 13, 2000
Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legitimate connections.
-
CVE-2000-0636
•
published on October 13, 2000
HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a malformed FTP quote command.
-
CVE-2000-0644
•
published on October 13, 2000
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing.
-
CVE-2000-0655
•
published on October 13, 2000
Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.