2000 CVE Vulnerabilities

1,241 CVEs published in 2000.

CVE IDSeverityCVSSDescription
CVE-2000-1134Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when...
CVE-2000-1092loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data d...
CVE-2000-1094Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via...
CVE-2000-1095modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell meta...
CVE-2000-1098The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or ...
CVE-2000-1099Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call in...
CVE-2000-1101Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option ena...
CVE-2000-1102PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode...
CVE-2000-1148The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the ...
CVE-2000-1150Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that co...
CVE-2000-1113Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed ...
CVE-2000-1177bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows...
CVE-2000-1241Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impac...
CVE-2000-1242The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote...
CVE-2000-1239The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disab...
CVE-2000-1240Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive...
CVE-2000-1243Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user crede...
CVE-2000-1236SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attac...
CVE-2000-1237The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote...
CVE-2000-1234violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as...
CVE-2000-1233SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary ...
CVE-2000-1235The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 a...
CVE-2000-1238BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restr...
CVE-2000-1244Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP head...
CVE-2000-1229Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (...

Check if your code is affected by 2000 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now