Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2000-12-11 CVE-2000-1024 Unspecified vulnerability in Unify Ewave Servletexec 3.0C
eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.
network
low complexity
unify
critical
10.0
2000-12-11 CVE-2000-1010 Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.
network
low complexity
openbsd redhat
critical
10.0
2000-12-11 CVE-2000-0999 Unspecified vulnerability in Openbsd Openssh 4.5
Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges.
network
low complexity
openbsd
critical
10.0
2000-11-14 CVE-2000-0854 Unspecified vulnerability in Microsoft Office 2000
When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.
network
low complexity
microsoft
critical
10.0
2000-11-14 CVE-2000-0848 Unspecified vulnerability in IBM Websphere Application Server 3.0.2
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.
network
low complexity
ibm
critical
10.0
2000-11-14 CVE-2000-0844 Permissions, Privileges, and Access Controls vulnerability in multiple products
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
10.0
2000-11-14 CVE-2000-0843 Buffer Overflow vulnerability in NT Authentication PAM Modules
Buffer overflow in pam_smb and pam_ntdom pluggable authentication modules (PAM) allow remote attackers to execute arbitrary commands via a login with a long user name.
network
low complexity
dave-airlie luke-kenneth-casson-leighton
critical
10.0
2000-11-14 CVE-2000-0841 Buffer Overflow vulnerability in Davide Libenzi Xmail 0.58
Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long APOP command.
network
low complexity
davide-libenzi
critical
10.0
2000-11-14 CVE-2000-0840 Buffer Overflow vulnerability in Davide Libenzi Xmail 0.58
Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long USER command.
network
low complexity
davide-libenzi
critical
10.0
2000-11-14 CVE-2000-0833 Buffer Overflow vulnerability in Jack De Winter Winsmtp 1.6F/2.X
Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command.
network
low complexity
jack-de-winter
critical
10.0