CVE-2000-0240
medium
📛 Threat Title
CVE-2000-0240
Description
vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a .. (dot dot) attack.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (5)
-
NVD detail: CVE-2000-0240
NVD Recent CVEs
vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a .. (dot dot) attack.
- cve@mitre.org NVD Recent CVEs
- cve@mitre.org NVD Recent CVEs
- cve@mitre.org NVD Recent CVEs
- cve@mitre.org NVD Recent CVEs
Remediations (10)
-
web:0patch.com
What is 0patch? 0patch is a microscopic solution for a huge security problem. 0patch delivers miniature patches of code ("micropatches") to computers and other devices worldwide in order to fix software vulnerabilities in various, even closed source products. With 0patch, there are no reboots or downtime when patching and no fear that a huge official update will break production. Corporate ...
-
web:attack.mitre.org
This mitigation can be implemented through the following measures: Remove Legacy Software: Use Case: Disable or remove older versions of software that no longer receive updates or security patches (e.g., legacy Java, Adobe Flash). Implementation: A company removes Flash Player from all employee systems after it has reached its end-of-life date.
-
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
-
web:security.paloaltonetworks.com
Palo Alto Networks Security Advisory: CVE -2026- 0240 Trust Protection Foundation: Sensitive Information Disclosure Vulnerability An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment ...
-
web:support.servicenow.com
Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...
-
web:www.cisa.gov
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.
-
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
-
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
-
web:www.tenable.com
With another year of Patch Tuesday releases behind us, Microsoft has yet to break its 2020 record with 1,245 CVE's patched. However, this is the second year in a row that Microsoft crossed the 1,000 CVE threshold, and the third time since Patch Tuesday's inception. In 2025, Microsoft broke its record for the most CVEs patched in a month twice.
-
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.