Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2000-04-14 CVE-2000-0260 Unspecified vulnerability in Microsoft Frontpage and Visual Interdev
Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link View Server-Side Component" vulnerability.
network
low complexity
microsoft
7.5
2000-04-14 CVE-2000-0254 Unspecified vulnerability in Craig Dansie Shopping Cart 3.0.4
The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.
network
low complexity
craig-dansie
5.0
2000-04-14 CVE-2000-0250 Unspecified vulnerability in QNX 4.25A
The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.
local
low complexity
qnx
7.2
2000-04-12 CVE-2000-0288 Infonautics getdoc.cgi allows remote attackers to bypass the payment phase for accessing documents via a modified form variable.
network
low complexity
5.0
2000-04-12 CVE-2000-0287 Unspecified vulnerability in CNC Technology Bizdb 1.0
The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter.
network
low complexity
cnc
critical
10.0
2000-04-12 CVE-2000-0283 Unspecified vulnerability in SGI Irix
The default installation of IRIX Performance Copilot allows remote attackers to access sensitive system information via the pmcd daemon.
network
low complexity
sgi
6.4
2000-04-12 CVE-2000-0282 Unspecified vulnerability in Talentsoft Web+ 4
TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a ..
network
low complexity
talentsoft
5.0
2000-04-12 CVE-2000-0259 Unspecified vulnerability in Microsoft Terminal Server and Windows NT
The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users.
local
low complexity
microsoft
7.2
2000-04-12 CVE-2000-0258 Improper Input Validation vulnerability in Microsoft products
IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.
network
low complexity
microsoft CWE-20
5.0
2000-04-11 CVE-2000-0253 Unspecified vulnerability in Craig Dansie Shopping Cart 3.0.4
The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields.
network
low complexity
craig-dansie
critical
10.0