CVE-2000-0332

UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a dot dot (..) and ends with a null byte.

CVE-2000-0303

Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.

CVE-2000-0433

The SuSE aaa_base package installs some system accounts with home directories set to /tmp, which allows local users to gain privileges to those accounts by creating standard user startup scripts such as profiles.

CVE-2000-0386

FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email.

CVE-2000-0385

FileMaker Pro 5 Web Companion allows remote attackers to bypass Field-Level database security restrictions via the XML publishing or email capabilities.