CVE-2000-0405
Published May 16, 2000Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.
Severity archive
43,852 critical severity CVEs — 43,852 Critical, 126,426 High, 163,815 Medium, 18,047 Low, 1,862 Unrated across the current result set.
Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.
NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC address, which could allow remot…
Buffer overflow in the SMTP gateway for InterScan Virus Wall 3.32 and earlier allows a remote attacker to execute arbitrary commands via a long filename for a uuencoded attachment.
Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.
Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary commands via a long MAIL FROM mail header.
Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields.
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.
The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary commands via shell metacharacters.
Buffer overflow in LCDproc allows remote attackers to gain root privileges via the screen_add command.
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS u…
The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter.
The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields.
The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts.
The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.
Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts.
SuSE Linux IMAP server allows remote attackers to bypass IMAP authentication and gain privileges.
Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.
DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters.
Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.
Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login name.
The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without…
Infopop Ultimate Bulletin Board (UBB) allows remote attackers to execute commands via shell metacharacters in the topic hidden field.
The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters.
Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands.
The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords.