Skip to main content

Severity archive

Critical severity CVEs

Critical

43,852 critical severity CVEs — 43,852 Critical, 126,426 High, 163,815 Medium, 18,047 Low, 1,862 Unrated across the current result set.

CVE-2000-0405

Published May 16, 2000

Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0384

Published May 8, 2000

NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC address, which could allow remot…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0428

Published May 4, 2000

Buffer overflow in the SMTP gateway for InterScan Virus Wall 3.32 and earlier allows a remote attacker to execute arbitrary commands via a long filename for a uuencoded attachment.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0425

Published May 3, 2000

Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0343

Published May 2, 2000

Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary commands via a long MAIL FROM mail header.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0449

Published May 1, 2000

Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0248

Published Apr 24, 2000

The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0322

Published Apr 24, 2000

The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary commands via shell metacharacters.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0295

Published Apr 21, 2000

Buffer overflow in LCDproc allows remote attackers to gain root privileges via the screen_add command.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0287

Published Apr 12, 2000

The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0253

Published Apr 11, 2000

The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0300

Published Apr 6, 2000

The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0244

Published Mar 29, 2000

The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0245

Published Mar 27, 2000

Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0233

Published Mar 15, 2000

SuSE Linux IMAP server allows remote attackers to bypass IMAP authentication and gain privileges.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0175

Published Mar 9, 2000

Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0177

Published Mar 2, 2000

DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0191

Published Feb 29, 2000

Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0222

Published Feb 15, 2000

The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0141

Published Feb 11, 2000

Infopop Ultimate Bulletin Board (UBB) allows remote attackers to execute commands via shell metacharacters in the topic hidden field.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0133

Published Feb 1, 2000

Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0109

Published Jan 31, 2000

The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 43,651-43,675 of 43,852 CVEsPage 1747 of 1755