2000 CVE Vulnerabilities

1,241 CVEs published in 2000.

CVE IDSeverityCVSSDescription
CVE-2000-0959glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a...
CVE-2000-0962The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to ...
CVE-2000-0966Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain p...
CVE-2000-0955Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which ...
CVE-2000-0956cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could a...
CVE-2000-0953Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection.
CVE-2000-0954Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise ...
CVE-2000-0957The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constru...
CVE-2000-0908BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Au...
CVE-2000-0951A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list direc...
CVE-2000-0958HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named wind...
CVE-2000-0952global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via sh...
CVE-2000-0967PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary com...
CVE-2000-0946Compaq Easy Access Keyboard software 1.3 does not properly disable access to custom buttons when the screen is locked, w...
CVE-2000-0945The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands with...
CVE-2000-0947Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands...
CVE-2000-0943Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute ...
CVE-2000-0944CRITICAL9.8CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password...
CVE-2000-0948GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.
CVE-2000-0940Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot ...
CVE-2000-0939Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly s...
CVE-2000-0941Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in ...
CVE-2000-0937Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the...
CVE-2000-0902getalbum.php in PhotoAlbum before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2000-0938Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided...

Check if your code is affected by 2000 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now