CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2536  CVE-2000-0967  Entry  PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.        View
2537  CVE-2000-0968  Entry  Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.        View
2538  CVE-2000-0969  Entry  Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.        View
2539  CVE-2000-0970  Entry  IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.        View
2540  CVE-2000-0971  Candidate  Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.  Proposed (20001129)  ACCEPT(3) Cole, Frech, Mell | NOOP(2) Armstrong, Christey  Christey> Fix typo: "possible" should be "possibly" | Christey> fix typo: "and possible"  View

Page 508 of 20943, showing 5 records out of 104715 total, starting on record 2536, ending on 2540

Actions