CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1990 | CVE-2000-0412 | Candidate | The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file. | Proposed (20000615) | ACCEPT(4) Baker, Levy, Ozancin, Stracener | MODIFY(1) Frech | NOOP(2) Cole, Prosser | Frech> ADDREF XF:knapster-view-files | View |
1989 | CVE-2000-0411 | Entry | Matt Wright"s FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter. | View | |||
1988 | CVE-2000-0410 | Entry | ColdFusion Server 4.5.1 allows remote attackers to cause a denial of service by making repeated requests to a CFCACHE tagged cache file that is not stored in memory. | View | |||
1987 | CVE-2000-0409 | Entry | Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate. | View | |||
1986 | CVE-2000-0408 | Entry | IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability. | View |
Page 20546 of 20943, showing 5 records out of 104715 total, starting on record 102726, ending on 102730