Search Results (29815 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-1999-1554 1 Sgi 1 Irix 2025-04-03 N/A
/usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.
CVE-2002-0683 1 Pacific Software 1 Carello 2025-04-03 N/A
Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter.
CVE-2000-0002 1 Zbsoft 1 Zbserver 2025-04-03 N/A
Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.
CVE-2000-0008 1 1st Choice Software 1 Ftppro 2025-04-03 N/A
FTPPro allows local users to read sensitive information, which is stored in plain text.
CVE-2000-0009 1 Nortel 1 Optivity Net Architect 2025-04-03 N/A
The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which allows local users to execute arbitrary commands.
CVE-2000-0013 1 Sgi 1 Irix 2025-04-03 N/A
IRIX soundplayer program allows local users to gain privileges by including shell metacharacters in a .wav file, which is executed via the midikeys program.
CVE-1999-0305 3 Bsdi, Freebsd, Openbsd 3 Bsd Os, Freebsd, Openbsd 2025-04-03 N/A
The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections.
CVE-2000-0018 1 Windowmaker 1 Wmmon 2025-04-03 N/A
wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file.
CVE-2002-1960 1 Cybozu 1 Share360 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in Cybozu Share360 1.1 allows remote attackers to inject arbitrary web script or HTML via an HTML link.
CVE-2000-0031 1 Redhat 1 Linux 2025-04-03 N/A
The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.
CVE-2000-0032 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.
CVE-2000-0033 1 Trend Micro 1 Interscan Viruswall 2025-04-03 N/A
InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments.
CVE-2000-0034 1 Netscape 1 Communicator 2025-04-03 N/A
Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."
CVE-2000-0035 1 Great Circle Associates 1 Majordomo 2025-04-03 N/A
resend command in Majordomo allows local users to gain privileges via shell metacharacters.
CVE-2000-0037 1 Great Circle Associates 1 Majordomo 2025-04-03 N/A
Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.
CVE-1999-0308 1 Hp 1 Hp-ux 2025-04-03 N/A
HP-UX gwind program allows users to modify arbitrary files.
CVE-2002-0712 1 Entrust 1 Entrust Authority Security Manager 2025-04-03 N/A
Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.
CVE-2000-0038 1 Glftpd 1 Glftpd 2025-04-03 N/A
glFtpD includes a default glftpd user account with a default password and a UID of 0.
CVE-2002-0722 1 Microsoft 1 Internet Explorer 2025-04-03 N/A
Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to misrepresent the source of a file in the File Download dialogue box to trick users into thinking that the file type is safe to download, aka "File Origin Spoofing."
CVE-2002-1966 1 My Postcards 1 My Postcards Platinum 2025-04-03 N/A
Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.