Skip to main content

Year archive

CVEs published in 2000

Archive summary

1,019 CVEs published in 2000 — 145 Critical, 311 High, 467 Medium, 96 Low, 0 Unrated.

CVE-2000-0494

Published Jun 16, 2000

Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server scri…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0501

Published Jun 16, 2000

Race condition in MDaemon 2.8.5.0 POP server allows local users to cause a denial of service by entering a UIDL command and quickly exiting the server.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-0512

Published Jun 16, 2000

CUPS (Common Unix Printing System) 1.04 and earlier does not properly delete request files, which allows a remote attacker to cause a denial of service.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0473

Published Jun 15, 2000

Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0475

Published Jun 15, 2000

Windows 2000 allows a local user process to access another user's desktop within the same windows station, aka the "Desktop Separation" vulnerability.

CVSS 4.6 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-0483

Published Jun 15, 2000

The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0484

Published Jun 15, 2000

Small HTTP Server ver 3.06 contains a memory corruption bug causing a memory overflow. The overflowed buffer crashes into a Structured Exception Handler resulting in a Denial of S…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0471

Published Jun 14, 2000

Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0477

Published Jun 14, 2000

Buffer overflow in Norton Antivirus for Exchange (NavExchange) allows remote attackers to cause a denial of service via a .zip file that contains long file names.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0478

Published Jun 14, 2000

In some cases, Norton Antivirus for Exchange (NavExchange) enters a "fail-open" state which allows viruses to pass through the server.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0514

Published Jun 14, 2000

GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denial of service, and local users to gain r…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0543

Published Jun 14, 2000

The command port for PGP Certificate Server 2.5.0 and 2.5.1 allows remote attackers to cause a denial of service if their hostname does not have a reverse DNS entry and they conne…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0542

Published Jun 13, 2000

Tigris remote access server before 11.5.4.22 does not properly record Radius accounting information when a user fails the initial login authentication but subsequently succeeds.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0565

Published Jun 13, 2000

SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-0535

Published Jun 12, 2000

OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0639

Published Jun 11, 2000

The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0506

Published Jun 9, 2000

The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from d…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0526

Published Jun 9, 2000

mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0527

Published Jun 9, 2000

userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 551-575 of 1,019 CVEsPage 23 of 41