2000 CVE Vulnerabilities

1,241 CVEs published in 2000.

CVE IDSeverityCVSSDescription
CVE-2000-0048get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp p...
CVE-2000-0087Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a...
CVE-2000-0070NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC...
CVE-2000-0071IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with ...
CVE-2000-0067CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack.
CVE-2000-0074PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissi...
CVE-2000-0045MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.
CVE-2000-0046Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ ...
CVE-2000-0081Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the co...
CVE-2000-0080AIX techlibss allows local users to overwrite files via a symlink attack.
CVE-2000-1220The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root pri...
CVE-2000-1221The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reve...
CVE-2000-0061Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the ...
CVE-2000-0044Macros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands.
CVE-2000-0055Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.
CVE-2000-0084CuteFTP uses weak encryption to store password information in its tree.dat file.
CVE-2000-0056IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi.
CVE-2000-0058Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve emai...
CVE-2000-0057Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain s...
CVE-2000-0085Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code v...
CVE-2000-0053Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malfo...
CVE-2000-0052Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) att...
CVE-2000-0051The Allaire Spectra Configuration Wizard allows remote attackers to cause a denial of service by repeatedly resubmitting...
CVE-2000-0050The Allaire Spectra Webtop allows authenticated users to access other Webtop sections by specifying explicit URLs.
CVE-2000-0049Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.

Check if your code is affected by 2000 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now