Skip to main content

Year archive

CVEs published in 2000

Archive summary

1,019 CVEs published in 2000 — 145 Critical, 311 High, 467 Medium, 96 Low, 0 Unrated.

CVE-2000-1225

Published Dec 31, 2000

Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1226

Published Dec 31, 2000

Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1227

Published Dec 31, 2000

Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1228

Published Dec 31, 2000

Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1229

Published Dec 31, 2000

Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1230

Published Dec 31, 2000

Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1231

Published Dec 31, 2000

code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1232

Published Dec 31, 2000

upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1233

Published Dec 31, 2000

SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the sSQL parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1234

Published Dec 31, 2000

violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1235

Published Dec 31, 2000

The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged databa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1236

Published Dec 31, 2000

SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1237

Published Dec 31, 2000

The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute f…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1238

Published Dec 31, 2000

BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forwa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1239

Published Dec 31, 2000

The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticat…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-1240

Published Dec 31, 2000

Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive information via unknown attack vectors, which reveal the a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1241

Published Dec 31, 2000

Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impact and attack vectors, related to a "grave security fault."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-1242

Published Dec 31, 2000

The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-1243

Published Dec 31, 2000

Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product devel…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1244

Published Dec 31, 2000

Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the "From" field, which allows remote attacke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0307

Published Dec 20, 2000

Buffer overflow in HP-UX cstm program allows local users to gain root privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0803

Published Dec 19, 2000

GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0810

Published Dec 19, 2000

Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0811

Published Dec 19, 2000

Auction Weaver 1.0 through 1.04 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the username or bidfile form fields.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0817

Published Dec 19, 2000

Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protoc…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 1-25 of 1,019 CVEsPage 1 of 41