Search Results (29939 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2000-0081 1 Microsoft 1 Hotmail 2025-04-03 N/A
Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript.
CVE-2000-0082 1 Microsoft 1 Webtv 2025-04-03 N/A
WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML.
CVE-2000-0083 1 Hp 1 Hp-ux 2025-04-03 N/A
HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.
CVE-2000-0084 1 Globalscape 1 Cuteftp 2025-04-03 N/A
CuteFTP uses weak encryption to store password information in its tree.dat file.
CVE-2000-0085 1 Microsoft 1 Hotmail 2025-04-03 N/A
Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.
CVE-2000-0087 1 Netscape 2 Communicator, Navigator 2025-04-03 N/A
Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.
CVE-2000-0089 1 Microsoft 1 Windows Nt 2025-04-03 N/A
The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.
CVE-2000-0091 1 Inter7 1 Vpopmail 2025-04-03 N/A
Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.
CVE-2000-0094 1 Netbsd 1 Netbsd 2025-04-03 N/A
procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.
CVE-2000-0096 1 Qualcomm 1 Qpopper 2025-04-03 N/A
Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command.
CVE-2000-0097 1 Microsoft 1 Index Server 2025-04-03 N/A
The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability.
CVE-2000-0098 1 Microsoft 1 Index Server 2025-04-03 N/A
Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist.
CVE-2000-0100 1 Microsoft 1 Systems Management Server 2025-04-03 N/A
The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program.
CVE-2000-0101 1 Make-a-store 1 Orderpage 2025-04-03 N/A
The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2000-0102 1 Salescart 1 Salescart 2025-04-03 N/A
The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2000-0103 1 Netsmart 1 Smartcart 2025-04-03 N/A
The SmartCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2000-0131 1 Jgaa 1 Warftpd 2025-04-03 N/A
Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.
CVE-2000-0104 1 Web Express 1 Shoptron 2025-04-03 N/A
The Shoptron shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2000-0105 1 Microsoft 1 Outlook Express 2025-04-03 N/A
Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client.
CVE-2000-0106 1 Easycart 1 Easycart 2025-04-03 N/A
The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.