Total
289036 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2000-0124 | 1 Surfcontrol | 1 Superscout | 2025-04-03 | N/A |
surfCONTROL SuperScout does not properly asign a category to web sites with a . (dot) at the end, which may allow users to bypass web access restrictions. | ||||
CVE-2000-0126 | 1 Microsoft | 1 Internet Information Server | 2025-04-03 | N/A |
Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack. | ||||
CVE-2000-0127 | 1 Progress | 1 Webspeed | 2025-04-03 | N/A |
The Webspeed configuration program does not properly disable access to the WSMadmin utility, which allows remote attackers to gain privileges via wsisa.dll. | ||||
CVE-2000-0128 | 1 Daniel Beckham | 1 The Finger Server | 2025-04-03 | N/A |
The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters. | ||||
CVE-2000-0133 | 1 H. Nomura | 1 Tiny Ftpdaemon | 2025-04-03 | N/A |
Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands. | ||||
CVE-2001-0419 | 1 Oracle | 1 Application Server | 2025-04-03 | N/A |
Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/. | ||||
CVE-2001-1237 | 1 Peaceworks Computer Consulting | 1 Phormation | 2025-04-03 | N/A |
Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable. | ||||
CVE-2002-0031 | 1 Yahoo | 1 Messenger | 2025-04-03 | N/A |
Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (1) call, (2) sendim, (3) getimv, (4) chat, (5) addview, or (6) addfriend. | ||||
CVE-2002-0253 | 1 Php | 1 Php | 2025-04-03 | N/A |
PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path. | ||||
CVE-2002-0341 | 1 Novell | 1 Groupwise | 2025-04-03 | N/A |
GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter. | ||||
CVE-2000-0134 | 1 Adgrafix Corporation | 1 Check It Out | 2025-04-03 | N/A |
The Check It Out shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | ||||
CVE-2001-0421 | 1 Sun | 2 Solaris, Sunos | 2025-04-03 | N/A |
FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition. | ||||
CVE-2001-1240 | 1 Engardelinux | 1 Secure Linux | 2025-04-03 | N/A |
The default configuration of sudo in Engarde Secure Linux 1.0.1 allows any user in the admin group to run certain commands that could be leveraged to gain full root access. | ||||
CVE-2000-0136 | 1 Mcmurtrey Whitaker And Associates | 1 Cart32 | 2025-04-03 | N/A |
The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | ||||
CVE-2000-0137 | 1 Cartit | 1 Cartit | 2025-04-03 | N/A |
The CartIt shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | ||||
CVE-2001-0422 | 1 Sun | 2 Solaris, Sunos | 2025-04-03 | N/A |
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable. | ||||
CVE-2000-0141 | 1 Infopop | 1 Ultimate Bulletin Board | 2025-04-03 | N/A |
Infopop Ultimate Bulletin Board (UBB) allows remote attackers to execute commands via shell metacharacters in the topic hidden field. | ||||
CVE-2001-0424 | 2 Freebsd, Timecop | 2 Freebsd, Bubblemon | 2025-04-03 | N/A |
BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id. | ||||
CVE-2000-0142 | 1 Netopia | 1 Timbuktu Pro | 2025-04-03 | N/A |
The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417. | ||||
CVE-2001-1241 | 1 Steve Grimm | 1 Un-cgi | 2025-04-03 | N/A |
Un-CGI 1.9 and earlier does not verify that a CGI script has the execution bits set before executing it, which allows remote attackers to execute arbitrary commands by directing Un-CGI to a document that begins with "#!" and the desired program name. |