Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2000-04-24 CVE-2000-0316 Unspecified vulnerability in SUN Solaris and Sunos
Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.
local
low complexity
sun
7.2
2000-04-24 CVE-2000-0248 Unspecified vulnerability in Redhat Linux 6.2
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.
network
low complexity
redhat
critical
10.0
2000-04-23 CVE-2000-0338 Improper Locking vulnerability in Concurrent Versions Software Project Concurrent Versions Software
Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.
5.5
2000-04-22 CVE-2000-0459 Unspecified vulnerability in IMP
IMP does not remove files properly if the MSWordView application quits, which allows local users to cause a denial of service by filling up the disk space by requesting a large number of documents and prematurely stopping the request.
network
low complexity
imp
5.0
2000-04-22 CVE-2000-0458 Unspecified vulnerability in IMP
The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information.
local
low complexity
imp
2.1
2000-04-21 CVE-2000-0336 Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.
local
low complexity
openldap mandrakesoft redhat turbolinux
2.1
2000-04-21 CVE-2000-0318 Unspecified vulnerability in Atrium Software Mercur Mailserver 3.2
Atrium Mercur Mail Server 3.2 allows local attackers to read other user's email and create arbitrary files via a dot dot (..) attack.
network
low complexity
atrium-software
7.5
2000-04-20 CVE-2000-0331 Unspecified vulnerability in Microsoft Terminal Server, Windows 2000 and Windows NT
Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.
network
low complexity
microsoft
5.0
2000-04-20 CVE-2000-0311 Unspecified vulnerability in Microsoft Windows 2000
The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability.
local
low complexity
microsoft
2.1
2000-04-20 CVE-2000-0272 Unspecified vulnerability in Realnetworks Realserver
RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070.
network
low complexity
realnetworks
7.8