2000 CVE Vulnerabilities

1,241 CVEs published in 2000.

CVE IDSeverityCVSSDescription
CVE-2000-1134——Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when...
CVE-2000-1092——loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data d...
CVE-2000-1094——Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via...
CVE-2000-1095——modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell meta...
CVE-2000-1098——The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or ...
CVE-2000-1099——Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call in...
CVE-2000-1101——Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option ena...
CVE-2000-1102——PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode...
CVE-2000-1148——The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the ...
CVE-2000-1150——Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that co...
CVE-2000-1113——Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed ...
CVE-2000-1177——bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows...
CVE-2000-1241——Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impac...
CVE-2000-1242——The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote...
CVE-2000-1239——The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disab...
CVE-2000-1240——Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive...
CVE-2000-1243——Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user crede...
CVE-2000-1236——SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attac...
CVE-2000-1237——The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote...
CVE-2000-1234——violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as...
CVE-2000-1233——SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary ...
CVE-2000-1235——The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 a...
CVE-2000-1238——BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restr...
CVE-2000-1244——Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP head...
CVE-2000-1229——Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (...

Check if your code is affected by 2000 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now