CSV
172,061 results for "vulnerability" Page 12
CVE-2000-0917 Exploit

Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.

Dec 19, 2000 7 affected product(s) NVD
10.0
CVSS
86.1%
EPSS
⚡ 75.8
CVE-2000-0886 Exploit

IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.

Dec 19, 2000 2 affected product(s) NVD
7.5
CVSS
89.2%
EPSS
⚡ 66.8
CVE-2000-0884 Exploit

IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.

Dec 19, 2000 2 affected product(s) NVD
7.5
CVSS
84.1%
EPSS
⚡ 65.2
CVE-2000-0970

IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.

Dec 19, 2000 2 affected product(s) NVD
7.5
CVSS
38.5%
EPSS
⚡ 41.5
CVE-2000-0969

Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.

Dec 19, 2000 1 affected product(s) NVD
10.0
CVSS
2.7%
EPSS
⚡ 40.8
CVE-2000-0947

Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.

Dec 19, 2000 3 affected product(s) NVD
10.0
CVSS
0.9%
EPSS
⚡ 40.3
CVE-2000-1241

Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impact and attack vectors, related to a "grave security fault."

Dec 31, 2000 1 affected product(s) NVD
10.0
CVSS
0.4%
EPSS
⚡ 40.1
CVE-2000-0885

Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates.

Dec 19, 2000 6 affected product(s) NVD
7.5
CVSS
24.7%
EPSS
⚡ 37.4
CVE-2000-0817

Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability.

Dec 19, 2000 1 affected product(s) NVD
7.5
CVSS
13.4%
EPSS
⚡ 34
CVE-2000-0982

Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability.

Dec 19, 2000 5 affected product(s) NVD
7.5
CVSS
10.2%
EPSS
⚡ 33.1
CVE-2000-0991

Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute arbitrary commands via a long telnet URL, aka the "HyperTerminal Buffer Overflow" vulnerability.

Dec 19, 2000 1 affected product(s) NVD
7.5
CVSS
9.1%
EPSS
⚡ 32.7
CVE-2000-0942

The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.

Dec 19, 2000 1 affected product(s) NVD
5.1
CVSS
36.9%
EPSS
⚡ 31.5
CVE-2000-1082

The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.

Jan 9, 2001 4 affected product(s) NVD
4.6
CVSS
43.1%
EPSS
⚡ 31.3
CVE-2000-0900

Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.

Dec 19, 2000 4 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2000-1236

SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.

Dec 31, 2000 1 affected product(s) NVD
7.5
CVSS
1.0%
EPSS
⚡ 30.3
CVE-2000-1233

SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the sSQL parameter.

Dec 31, 2000 1 affected product(s) NVD
7.5
CVSS
0.6%
EPSS
⚡ 30.2
CVE-2000-0979

File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.

Dec 19, 2000 4 affected product(s) NVD
6.4
CVSS
11.6%
EPSS
⚡ 29.1
CVE-2000-0993

Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.

Dec 19, 2000 13 affected product(s) NVD
7.2
CVSS
0.2%
EPSS
⚡ 28.9
CVE-2000-0994

Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.

Dec 19, 2000 5 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2000-0918

Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.

Dec 19, 2000 1 affected product(s) NVD
7.2
CVSS
0.1%
EPSS
⚡ 28.8