National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

There are 133,753 matching records.
Displaying matches 131361 through 131380.
Vuln ID Summary CVSS Severity
CVE-2000-1069

pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by specifying the same value to the entered_password and admin_password parameters.

Published: December 11, 2000; 12:00:00 AM -05:00
    V2: 6.4 MEDIUM
CVE-2000-1070

pollit.cgi in Poll It 2.01 and earlier uses data files that are located under the web document root, which allows remote attackers to access sensitive or private information.

Published: December 11, 2000; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-2000-1071

The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges.

Published: December 11, 2000; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-2000-1072

iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.

Published: December 11, 2000; 12:00:00 AM -05:00
    V2: 7.2 HIGH
CVE-2000-1073

csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory.

Published: December 11, 2000; 12:00:00 AM -05:00
    V2: 7.2 HIGH
CVE-2000-1074

csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.

Published: December 11, 2000; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-2000-1075

Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.

Published: December 11, 2000; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-2000-1076

Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.

Published: December 11, 2000; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-2000-1077

Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.

Published: December 11, 2000; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-2000-1078

ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.

Published: December 11, 2000; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-2000-1222

AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.

Published: December 10, 2000; 12:00:00 AM -05:00
    V2: 7.2 HIGH
CVE-2000-1224

Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others.

Published: November 23, 2000; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-2000-1217

Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability.

Published: November 21, 2000; 12:00:00 AM -05:00
    V2: 4.6 MEDIUM
CVE-2000-1223

quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request.

Published: November 20, 2000; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-2000-0804

Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass the directionality check via fragmented TCP connection requests or reopening closed TCP connection requests, aka "One-way Connection Enforcement Bypass."

Published: November 14, 2000; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-2000-0805

Check Point VPN-1/FireWall-1 4.1 and earlier improperly retransmits encapsulated FWS packets, even if they do not come from a valid FWZ client, aka "Retransmission of Encapsulated Packets."

Published: November 14, 2000; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-2000-0806

The inter-module authentication mechanism (fwa1) in Check Point VPN-1/FireWall-1 4.1 and earlier may allow remote attackers to conduct a denial of service, aka "Inter-module Communications Bypass."

Published: November 14, 2000; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-2000-0807

The OPSEC communications authentication mechanism (fwn1) in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to spoof connections, aka the "OPSEC Authentication Vulnerability."

Published: November 14, 2000; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-2000-0808

The seed generation mechanism in the inter-module S/Key authentication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass authentication via a brute force attack, aka "One-time (s/key) Password Authentication."

Published: November 14, 2000; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-2000-0809

Buffer overflow in Getkey in the protocol checker in the inter-module communication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to cause a denial of service.

Published: November 14, 2000; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM