2000 CVE Vulnerabilities

1,241 CVEs published in 2000.

CVE IDSeverityCVSSDescription
CVE-2000-0769O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote...
CVE-2000-0748OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user i...
CVE-2000-0685BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to co...
CVE-2000-0695Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line...
CVE-2000-0753The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment t...
CVE-2000-0726CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the fi...
CVE-2000-0754Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.
CVE-2000-0770IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrict...
CVE-2000-0757The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privil...
CVE-2000-0755Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.
CVE-2000-0721The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows lo...
CVE-2000-0563The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS ...
CVE-2000-0720news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which...
CVE-2000-0758The web interface for Lyris List Manager 3 and 4 allows list subscribers to obtain administrative access by modifying th...
CVE-2000-0684BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile an...
CVE-2000-0707PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allow...
CVE-2000-0712Linux Intrusion Detection System (LIDS) 0.9.7 allows local users to gain root privileges when LIDS is disabled via the s...
CVE-2000-0693pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the "cp" program, which al...
CVE-2000-0717GoodTech FTP server allows remote attackers to cause a denial of service via a large number of RNTO commands.
CVE-2000-0688Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote atta...
CVE-2000-0686Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in ...
CVE-2000-0692ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets wi...
CVE-2000-0719VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Tro...
CVE-2000-0722Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /t...
CVE-2000-0697The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execut...

Check if your code is affected by 2000 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now