NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
77441 | CVE-2000-1209 | The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida. | 2 | 10 | High | 2017-01-05 | 2016-10-17 | View | |
77442 | CVE-2000-1210 | Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp. | 2 | 5 | Medium | 2017-01-05 | 2016-10-17 | View | |
77443 | CVE-2000-1211 | Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
77444 | CVE-2000-1212 | Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects. | 2 | 5 | Medium | 2017-01-05 | 2008-09-10 | View | |
77445 | CVE-2000-1213 | ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping"s exposure to bugs that otherwise would occur at lower privileges. | 2 | 7.5 | High | 2017-01-05 | 2016-10-17 | View |
Page 555 of 17672, showing 5 records out of 88360 total, starting on record 2771, ending on 2775