Security
Headlines
HeadlinesLatestCVEs

Tag

#ibm

CVE-2000-0143: IBM X-Force Exchange

The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP.

CVE
#auth#ssh#ibm
CVE-2000-0142: IBM X-Force Exchange

The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417.

CVE-2000-0145: IBM X-Force Exchange

The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions.

CVE-2000-0129: IBM X-Force Exchange

Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.

CVE-2000-0114: IBM X-Force Exchange

Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.

CVE-2000-0134: IBM X-Force Exchange

The Check It Out shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

CVE-2000-0137: IBM X-Force Exchange

The CartIt shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

CVE-2000-0136: IBM X-Force Exchange

The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

CVE-2000-0135: IBM X-Force Exchange

The @Retail shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

CVE-2000-0110: IBM X-Force Exchange

The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.