CVE-2000-0250
Published Apr 14, 2000The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.
Loading current evidence
Historical archive search
Search decades of CVEs by regex, severity, date, CWE, vendor/product tags, KEV, PoC, and other evidence.
Results
1,019 results · Sorted by Highest Buzz score first
The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.
The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, d…
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS u…
The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request.
TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program.
The default installation of IRIX Performance Copilot allows remote attackers to access sensitive system information via the pmcd daemon.
The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter.
Infonautics getdoc.cgi allows remote attackers to bypass the payment phase for accessing documents via a modified form variable.
The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack.
The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs.
The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into _init before the privileged process is e…
The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable.
The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields.
The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name.
CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after crac…
BeOS 4.5 and 5.0 allow local users to cause a denial of service via malformed direct system calls using interrupt 37.
Buffer overflow in healthd for FreeBSD allows local users to gain root privileges.
PCAnywhere allows remote attackers to cause a denial of service by terminating the connection before PCAnywhere provides a login prompt.
BeOS allows remote attackers to cause a denial of service via malformed packets whose length field is less than the length of the headers.
The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories.
HP-UX 11.04 VirtualVault (VVOS) sends data to unprivileged processes via an interface that has multiple aliased IP addresses.
The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts.
Ipswitch IMAIL server 6.02 and earlier allows remote attackers to cause a denial of service via the AUTH CRAM-MD5 command.
The Nbase-Xyplex EdgeBlaster router allows remote attackers to cause a denial of service via a scan for the FormMail CGI program.
Every filter state lives in the URL so you can bookmark, share, and crawl exact historical slices instead of a client-only search session.
Buzz order uses the latest all-time evidence snapshot, refreshed every two hours. Evidence-bearing CVEs rank first; records without a snapshot continue newest-first.