2000 CVE Vulnerabilities

1,241 CVEs published in 2000.

CVE IDSeverityCVSSDescription
CVE-2000-0769——O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote...
CVE-2000-0748——OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user i...
CVE-2000-0685——BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to co...
CVE-2000-0695——Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line...
CVE-2000-0753——The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment t...
CVE-2000-0726——CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the fi...
CVE-2000-0754——Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.
CVE-2000-0770——IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrict...
CVE-2000-0757——The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privil...
CVE-2000-0755——Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.
CVE-2000-0721——The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows lo...
CVE-2000-0563——The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS ...
CVE-2000-0720——news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which...
CVE-2000-0758——The web interface for Lyris List Manager 3 and 4 allows list subscribers to obtain administrative access by modifying th...
CVE-2000-0684——BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile an...
CVE-2000-0707——PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allow...
CVE-2000-0712——Linux Intrusion Detection System (LIDS) 0.9.7 allows local users to gain root privileges when LIDS is disabled via the s...
CVE-2000-0693——pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the "cp" program, which al...
CVE-2000-0717——GoodTech FTP server allows remote attackers to cause a denial of service via a large number of RNTO commands.
CVE-2000-0688——Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote atta...
CVE-2000-0686——Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in ...
CVE-2000-0692——ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets wi...
CVE-2000-0719——VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Tro...
CVE-2000-0722——Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /t...
CVE-2000-0697——The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execut...

Check if your code is affected by 2000 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now