Skip to main content

Year archive

CVEs published in 2000

Archive summary

1,019 CVEs published in 2000 — 145 Critical, 311 High, 467 Medium, 96 Low, 0 Unrated.

CVE-2000-0555

Published Jun 9, 2000

Ceilidh allows remote attackers to cause a denial of service via a large number of POST requests.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0377

Published Jun 8, 2000

The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka…

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-0497

Published Jun 8, 2000

IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0498

Published Jun 8, 2000

Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0499

Published Jun 8, 2000

The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0502

Published Jun 8, 2000

Mcafee VirusScan 4.03 does not properly restrict access to the alert text file before it is sent to the Central Alert Server, which allows local users to modify alerts in an arbit…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-0522

Published Jun 8, 2000

RSA ACE/Server allows remote attackers to cause a denial of service by flooding the server's authentication request port with UDP packets, which causes the server to crash.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0525

Published Jun 8, 2000

OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0554

Published Jun 8, 2000

Ceilidh allows remote attackers to obtain the real path of the Ceilidh directory via the translated_path hidden form field.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0376

Published Jun 7, 2000

Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0515

Published Jun 7, 2000

The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to modify SNMP configuration or gain privileges.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0520

Published Jun 7, 2000

Buffer overflow in restore program 0.4b17 and earlier in dump package allows local users to execute arbitrary commands via a long tape name.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0532

Published Jun 7, 2000

A FreeBSD patch for SSH on 2000-01-14 configures ssh to listen on port 722 as well as port 22, which might allow remote attackers to access SSH through port 722 even if port 22 is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0534

Published Jun 7, 2000

The apsfilter software in the FreeBSD ports package does not properly read user filter configurations, which allows local users to execute commands as the lpd user.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0538

Published Jun 7, 2000

ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0559

Published Jun 7, 2000

eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-0482

Published Jun 6, 2000

Check Point Firewall-1 allows remote attackers to cause a denial of service by sending a large number of malformed fragmented IP packets.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0503

Published Jun 6, 2000

The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-0516

Published Jun 6, 2000

When configured to store configuration information in an LDAP directory, Shiva Access Manager 5.0.0 stores the root DN (Distinguished Name) name and password in cleartext in a fil…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0523

Published Jun 6, 2000

Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a long MKD command.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0552

Published Jun 6, 2000

ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0558

Published Jun 6, 2000

Buffer overflow in HP Openview Network Node Manager 6.1 allows remote attackers to execute arbitrary commands via the Alarm service (OVALARMSRV) on port 2345.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0518

Published Jun 5, 2000

Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "…

CVSS 2.6 · Low
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-0519

Published Jun 5, 2000

Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer ses…

CVSS 2.6 · Low
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 576-600 of 1,019 CVEsPage 24 of 41