Skip to main content

Severity archive

High severity CVEs

High

124,776 high severity CVEs — 43,370 Critical, 124,776 High, 163,222 Medium, 17,939 Low, 2,047 Unrated across the current result set.

CVE-2000-1014

Published Dec 11, 2000

Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary commands via format characters in th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1015

Published Dec 11, 2000

The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode privileges and possibly exec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1020

Published Dec 11, 2000

Heap overflow in Worldclient in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1021

Published Dec 11, 2000

Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1022

Published Dec 11, 2000

The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted comma…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1023

Published Dec 11, 2000

The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name information via the nsManager.cgi CGI…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1028

Published Dec 11, 2000

Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1033

Published Dec 11, 2000

Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1037

Published Dec 11, 2000

Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1056

Published Dec 11, 2000

CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1059

Published Dec 11, 2000

The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an "xhost + localhost" command, which allows loc…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1072

Published Dec 11, 2000

iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the ip…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1073

Published Dec 11, 2000

csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1222

Published Dec 10, 2000

AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a maliciou…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1223

Published Nov 20, 2000

quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0804

Published Nov 14, 2000

Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass the directionality check via fragmented TCP connection requests or reopening closed TCP connection r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0805

Published Nov 14, 2000

Check Point VPN-1/FireWall-1 4.1 and earlier improperly retransmits encapsulated FWS packets, even if they do not come from a valid FWZ client, aka "Retransmission of Encapsulated…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0807

Published Nov 14, 2000

The OPSEC communications authentication mechanism (fwn1) in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to spoof connections, aka the "OPSEC Authenticatio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0808

Published Nov 14, 2000

The seed generation mechanism in the inter-module S/Key authentication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass authentication v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0824

Published Nov 14, 2000

The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arb…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0831

Published Nov 14, 2000

Buffer overflow in Fastream FTP++ 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long username.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0834

Published Nov 14, 2000

The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet://…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2000-0836

Published Nov 14, 2000

Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorization header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0846

Published Nov 14, 2000

Buffer overflow in Darxite 0.4 and earlier allows a remote attacker to execute arbitrary commands via a long username or password.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 124,251-124,275 of 124,776 CVEsPage 4971 of 4992