CVE detail
CVE-2000-0680 — CVE-2000-0680
Published 2000-10-20 · Modified 2026-06-16 · Vendor cvs · Product cvs · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0134
EPSS probability
exploitation probability, 30d
69.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References