CVE-2000-0181
Published Mar 11, 2000Firewall-1 3.0 and 4.0 leaks packets with private IP address information, which could allow remote attackers to determine the real IP address of the host that is making the connec…
Loading current evidence
Historical archive search
Search decades of CVEs by regex, severity, date, CWE, vendor/product tags, KEV, PoC, and other evidence.
Results
353,189 results · Sorted by Highest Buzz score first
Firewall-1 3.0 and 4.0 leaks packets with private IP address information, which could allow remote attackers to determine the real IP address of the host that is making the connec…
Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java…
Vulnerability in the EELS system in SCO UnixWare 7.1.x allows remote attackers to cause a denial of service.
Buffer overflow in ircII 4.4 IRC client allows remote attackers to execute commands via the DCC chat capability.
Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges via a long parameter.
StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.
Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.
RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private.
The Pocsag POC32 program does not properly prevent remote users from accessing its server port, even if the option has been disabled.
The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are installed on the system.
The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local users to gain privileges.
The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges.
Trend Micro OfficeScan allows remote attackers to replay administrative commands and modify the configuration of OfficeScan clients.
Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.
DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters.
AOL Instant Messenger (AIM) client allows remote attackers to cause a denial of service via a message with a malformed ASCII value.
The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain privileges.
ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.
The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitra…
SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters.
The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not…
Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.
The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch.
Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail…
Every filter state lives in the URL so you can bookmark, share, and crawl exact historical slices instead of a client-only search session.
Buzz order uses the latest all-time evidence snapshot, refreshed every two hours. Evidence-bearing CVEs rank first; records without a snapshot continue newest-first.