Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2000-02-01 CVE-2000-0133 Buffer Overflow vulnerability in Tiny FTPd
Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands.
network
low complexity
h-nomura
critical
10.0
2000-01-31 CVE-2000-0109 Unspecified vulnerability in Comstock Multicsp 4.2
The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords.
network
low complexity
comstock
critical
10.0
2000-01-21 CVE-2000-0093 Unspecified vulnerability in Redhat Linux 6.1
An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.
network
low complexity
redhat
critical
10.0
2000-01-21 CVE-2000-0091 Unspecified vulnerability in Inter7 Vpopmail
Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.
network
low complexity
inter7
critical
10.0
2000-01-18 CVE-1999-0992 Unspecified vulnerability in HP Vvos
HP VirtualVault with the PHSS_17692 patch allows unprivileged processes to bypass access restrictions via the Trusted Gateway Proxy (TGP).
network
low complexity
hp
critical
10.0
2000-01-17 CVE-2000-0065 Unspecified vulnerability in Avtronics Inetserv 3.0
Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request.
network
low complexity
avtronics
critical
10.0
2000-01-10 CVE-2000-0081 Unspecified vulnerability in Microsoft Hotmail
Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g.
network
low complexity
microsoft
critical
10.0
2000-01-08 CVE-2000-1221 The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.
network
low complexity
sgi debian redhat
critical
10.0
2000-01-08 CVE-2000-1220 The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.
network
low complexity
sgi redhat
critical
10.0
2000-01-07 CVE-2000-0061 Unspecified vulnerability in Microsoft Internet Explorer
Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.
network
low complexity
microsoft
critical
10.0