Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

1,019 results · Page 1/21
9.8
CVE-2000-1218

The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMa

9.8
CVE-2000-0944

CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password

7.5
CVE-2000-0258

IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped

7.5
CVE-2000-0342

Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by

7.5
CVE-2000-0497

IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provi

7.5
CVE-2000-0498

Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides

7.5
CVE-2000-0499

The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP prog

5.5
CVE-2000-0338

Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause

5.5
CVE-2000-0552

ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allow

5.5
CVE-2000-0972

HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target fil

CVE-1999-0964

Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCAL

CVE-2000-0069

The recover program in Solstice Backup allows local users to restore sensitive files.

CVE-2000-0120

The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuth

CVE-2000-0077

The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate P

CVE-2000-0078

The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH

CVE-2000-0082

WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML.

CVE-1999-0735

KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories.

CVE-1999-0744

Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long

CVE-1999-0876

Buffer overflow in Internet Explorer 4.0 via EMBED tag.

CVE-1999-0894

Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals.

CVE-2000-0049

Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.

CVE-2000-0050

The Allaire Spectra Webtop allows authenticated users to access other Webtop sections by specifying explicit URLs.

CVE-2000-0051

The Allaire Spectra Configuration Wizard allows remote attackers to cause a denial of service by repeatedly resubmitting

CVE-2000-0052

Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) att

CVE-2000-0053

Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malfo

CVE-2000-0057

Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain s

CVE-2000-0059

PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, whic

CVE-2000-0062

The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized ac

CVE-2000-0085

Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code v

CVE-2000-0056

IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi.

CVE-2000-0058

Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve emai

CVE-2000-0044

Macros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands.

CVE-2000-0055

Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.

CVE-2000-0084

CuteFTP uses weak encryption to store password information in its tree.dat file.

CVE-2000-0061

Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the

CVE-2000-1220

The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root pri

CVE-2000-1221

The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reve

CVE-2000-0046

Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ

CVE-2000-0080

AIX techlibss allows local users to overwrite files via a symlink attack.

CVE-2000-0081

Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the co

CVE-2000-0045

MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.

CVE-2000-0067

CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack.

CVE-2000-0071

IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with

CVE-2000-0074

PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissi

CVE-1999-1002

Netscape Navigator uses weak encryption for storing a user's Netscape mail password.

CVE-2000-0048

get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp p

CVE-2000-0070

NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC

CVE-2000-0087

Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a

CVE-2000-0066

WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request.

CVE-2000-0075

Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a den

Scan for 2000 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started