CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2486  CVE-2000-0917  Entry  Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.        View
2487  CVE-2000-0918  Candidate  Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.  Proposed (20001129)  ACCEPT(2) Baker, Mell | NOOP(2) Cole, Wall | REVIEWING(1) Christey  Christey> May be a duplicate of CVE-2000-0373, but the ref"s in that CVE | are vague. I suspect this *isn"t* a duplicate because this is | a format string problem. | Baker> I think it is sufficiently different from 2000-0373.  View
2488  CVE-2000-0919  Entry  Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.        View
2489  CVE-2000-0920  Entry  Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."        View
2490  CVE-2000-0921  Entry  Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.        View

Page 498 of 20943, showing 5 records out of 104715 total, starting on record 2486, ending on 2490

Actions