CSV
172,061 results for "vulnerability" Page 11
CVE-2000-0917 Exploit

Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.

Dec 19, 2000 7 affected product(s) NVD
10.0
CVSS
86.1%
EPSS
⚡ 75.8
CVE-2000-0886 Exploit

IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.

Dec 19, 2000 2 affected product(s) NVD
7.5
CVSS
89.2%
EPSS
⚡ 66.8
CVE-2000-0884 Exploit

IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.

Dec 19, 2000 2 affected product(s) NVD
7.5
CVSS
84.1%
EPSS
⚡ 65.2
CVE-2000-1034

Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability.

Dec 11, 2000 1 affected product(s) NVD
10.0
CVSS
22.1%
EPSS
⚡ 46.6
CVE-2000-1040

Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service.

Dec 11, 2000 4 affected product(s) NVD
10.0
CVSS
1.8%
EPSS
⚡ 40.6
CVE-2000-1010

Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.

Dec 11, 2000 10 affected product(s) NVD
10.0
CVSS
1.6%
EPSS
⚡ 40.5
CVE-2000-0947

Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.

Dec 19, 2000 3 affected product(s) NVD
10.0
CVSS
0.9%
EPSS
⚡ 40.3
CVE-2000-1043

Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.

Dec 11, 2000 3 affected product(s) NVD
10.0
CVSS
0.5%
EPSS
⚡ 40.1
CVE-2000-1044

Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges.

Dec 11, 2000 4 affected product(s) NVD
10.0
CVSS
0.5%
EPSS
⚡ 40.1
CVE-2000-0885

Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates.

Dec 19, 2000 6 affected product(s) NVD
7.5
CVSS
24.7%
EPSS
⚡ 37.4
CVE-2000-0817

Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability.

Dec 19, 2000 1 affected product(s) NVD
7.5
CVSS
13.4%
EPSS
⚡ 34
CVE-2000-1014

Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary commands via format characters in the queryText parameter.

Dec 11, 2000 1 affected product(s) NVD
7.5
CVSS
8.7%
EPSS
⚡ 32.6
CVE-2000-0942

The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.

Dec 19, 2000 1 affected product(s) NVD
5.1
CVSS
36.9%
EPSS
⚡ 31.5
CVE-2000-0900

Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.

Dec 19, 2000 4 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2000-0998

Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function.

Dec 11, 2000 9 affected product(s) NVD
7.2
CVSS
0.3%
EPSS
⚡ 28.9
CVE-2000-0918

Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.

Dec 19, 2000 1 affected product(s) NVD
7.2
CVSS
0.1%
EPSS
⚡ 28.8
CVE-2000-0929

Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.

Dec 19, 2000 1 affected product(s) NVD
5.0
CVSS
21.4%
EPSS
⚡ 26.4
CVE-2000-0858

Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability.

Nov 14, 2000 2 affected product(s) NVD
5.0
CVSS
20.4%
EPSS
⚡ 26.1
CVE-2000-0940

Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.

Dec 19, 2000 1 affected product(s) NVD
6.4
CVSS
0.6%
EPSS
⚡ 25.8
CVE-2000-0862

Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information.

Nov 14, 2000 1 affected product(s) NVD
6.4
CVSS
0.4%
EPSS
⚡ 25.7