CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2486 | CVE-2000-0917 | Entry | Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. | View | |||
2487 | CVE-2000-0918 | Candidate | Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters. | Proposed (20001129) | ACCEPT(2) Baker, Mell | NOOP(2) Cole, Wall | REVIEWING(1) Christey | Christey> May be a duplicate of CVE-2000-0373, but the ref"s in that CVE | are vague. I suspect this *isn"t* a duplicate because this is | a format string problem. | Baker> I think it is sufficiently different from 2000-0373. | View |
2488 | CVE-2000-0919 | Entry | Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | View | |||
2489 | CVE-2000-0920 | Entry | Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "." | View | |||
2490 | CVE-2000-0921 | Entry | Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter. | View |
Page 498 of 20943, showing 5 records out of 104715 total, starting on record 2486, ending on 2490