CVE-2000-1050
Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request (aka the "extra leading...
Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request (aka the "extra leading...
Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of "." characters. Date published : 2001-01-22 http://www.allaire.com/handlers/index.cfm?ID=18085&Method=Full http://marc.info/?l=bugtraq&m=97310314724964&w=2
nss_ldap earlier than 121, when run with nscd (name service caching daemon), allows remote attackers to cause a denial of service via a flood of LDAP requests. Date published : 2001-01-22 http://www.securityfocus.com/bid/1863 http://www.linux-mandrake.com/en/security/MDKSA-2000-066-1.php3
Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges. Date published : 2001-01-22 http://www.securityfocus.com/bid/1820 http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html
Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function. Date published...
Buffer overflow in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function. Date published :...
Buffer overflow in ypbind 3.3 possibly allows an attacker to gain root privileges. Date published : 2001-01-22 http://www.calderasystems.com/support/security/advisories/CSSA-2000-039.0.txt http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1
Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service. Date published : 2001-01-22 http://www.securityfocus.com/bid/1820 http://archives.neohapsis.com/archives/bugtraq/2000-10/0356.html
The web administration interface for IBM AS/400 Firewall allows remote attackers to cause a denial of service via an empty GET request. Date published : 2001-01-22 http://www-1.ibm.com/support/search.wss?rs=0&q=SA90544&apar=only http://as400service.rochester.ibm.com/n_dir/nas4apar.NSF/5ec6cdc6ab42894a862568f90073c74a/9ce636030a58807186256955003d128d?OpenDocument
Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via a .. (dot dot) attack on the Image parameter. Date published : 2001-01-22 http://www.securityfocus.com/bid/1704 http://archives.neohapsis.com/archives/bugtraq/2000-09/0252.html
Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability. Date...
The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall. Date published...
Buffer overflow in dtterm in HP-UX 11.0 and HP Tru64 UNIX 4.0f through 5.1a allows local users to execute arbitrary code via a long -tn option. Date published : 2001-01-22 http://www.securityfocus.com/bid/1889 http://www.securityfocus.com/archive/1/75188
Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the...