Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2000-12-19 CVE-2000-0939 Unspecified vulnerability in Samba 2.0.7
Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart.
network
low complexity
samba
5.0
2000-12-19 CVE-2000-0938 Unspecified vulnerability in Samba 2.0.7
Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server.
network
low complexity
samba
5.0
2000-12-19 CVE-2000-0933 Unspecified vulnerability in Microsoft Windows 2000
The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability.
local
low complexity
microsoft
4.6
2000-12-19 CVE-2000-0932 Unspecified vulnerability in Clearswift Mailsweeper for Smtp 3.X
MAILsweeper for SMTP 3.x does not properly handle corrupt CDA documents in a ZIP file and hangs, which allows remote attackers to cause a denial of service.
network
low complexity
clearswift
5.0
2000-12-19 CVE-2000-0930 Unspecified vulnerability in David Harris Pegasus Mail 3.12
Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.
network
low complexity
david-harris
5.0
2000-12-19 CVE-2000-0929 Unspecified vulnerability in Microsoft Windows Media Player 7
Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.
network
low complexity
microsoft
5.0
2000-12-19 CVE-2000-0927 Unspecified vulnerability in Wquinn Quotaadvisor 4.1
WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions.
local
low complexity
wquinn
4.6
2000-12-19 CVE-2000-0925 Unspecified vulnerability in Smartwin Technology Cyberoffice Shopping Cart 2.0
The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.
network
low complexity
smartwin-technology
5.0
2000-12-19 CVE-2000-0924 Unspecified vulnerability in Armada Design Master Index 1.0
Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a ..
network
low complexity
armada-design
5.0
2000-12-19 CVE-2000-0922 Unspecified vulnerability in Bytes Interactive web Shopper 1.0/2.0
Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a ..
network
low complexity
bytes-interactive
5.0