Skip to main content

Year archive

CVEs published in 2000

Archive summary

1,019 CVEs published in 2000 — 145 Critical, 311 High, 467 Medium, 96 Low, 0 Unrated.

CVE-2000-0521

Published Jun 5, 2000

Savant web server allows remote attackers to read source code of CGI scripts via a GET request that does not include the HTTP version number.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0524

Published Jun 5, 2000

Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0537

Published Jun 5, 2000

BRU backup software allows local users to append data to arbitrary files by specifying an alternate configuration file with the BRUEXECLOG environmental variable.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0544

Published Jun 5, 2000

Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0556

Published Jun 5, 2000

Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to cause a denial of service by sending a large user name to the user dialog running on port 8002.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0557

Published Jun 5, 2000

Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to execute arbitrary commands via a long GET request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0492

Published Jun 4, 2000

PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0536

Published Jun 4, 2000

xinetd 2.1.8.x does not properly restrict connections if hostnames are used for access control and the connecting host does not have a reverse DNS entry.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0468

Published Jun 2, 2000

man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0467

Published Jun 1, 2000

Buffer overflow in Linux splitvt 1.6.3 and earlier allows local users to gain root privileges via a long password in the screen locking function.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0470

Published Jun 1, 2000

Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0474

Published Jun 1, 2000

Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0487

Published Jun 1, 2000

The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES e…

CVSS 3.6 · Low
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-0490

Published Jun 1, 2000

Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0493

Published Jun 1, 2000

Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long string.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0507

Published Jun 1, 2000

Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0509

Published Jun 1, 2000

Buffer overflows in the finger and whois demonstration scripts in Sambar Server 4.3 allow remote attackers to execute arbitrary commands via a long hostname.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0505

Published May 31, 2000

The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-0530

Published May 31, 2000

The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0402

Published May 30, 2000

The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the…

CVSS 2.1 · Low
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-0485

Published May 30, 2000

Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability.

CVSS 2.1 · Low
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-0486

Published May 30, 2000

Buffer overflow in Cisco TACACS+ tac_plus server allows remote attackers to cause a denial of service via a malformed packet with a long length field.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0488

Published May 30, 2000

Buffer overflow in ITHouse mail server 1.04 allows remote attackers to execute arbitrary commands via a long RCPT TO mail command.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 601-625 of 1,019 CVEsPage 25 of 41