| OSVDB ID | Disclosure Date | Title |
|
7969
Description:
A local overflow exists in AIX ping. The AIX ping fails to check command line arguments length resulting in a buffer overflow. With a specially crafted request, an attacker can execute arbitrary commands resulting in a loss of integrity.
|
1997-07-21
|
IBM AIX ping Command Line Argument Overflow
|
|
7160
Description:
(Description Provided by CVE) : Buffer overflow in Exim allows local users to gain root privileges via a long :include: option in a .forward file.
|
1997-07-21
|
Exim .forward :include: Option Privilege Escalation
|
|
1450
Description:
(Description Provided by CVE) : Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.
|
1997-07-21
|
INN nnrpd Remote Overflow
|
|
1247
Description:
Unknown / Incomplete
|
1997-07-17
|
IRCnet IRCD send.c Unspecified Overflow
|
|
8218
Description:
A local overflow exists in the 'ld.so' dynamic linkers in some Linux distributions. By forcing an error while calling a dynamically linked setuid program with a long program name (argv[0]), a local attacker can overflow a buffer and execute arbitrary code on the system and use this vulnerability to gain root privileges on the system.
|
1997-07-17
|
Linux ld.so Program Name Overflow
|
|
8219
Description:
A local overflow exists in the 'ld-linux.so' dynamic linkers in some Linux distributions. By forcing an error while calling a dynamically linked setuid program with a long program name (argv[0]), a local attacker can overflow a buffer and execute arbitrary code on the system gaining root privileges.
|
1997-07-17
|
Linux ld-linux.so Program Name Overflow
|
|
83126
Description:
Microsoft Windows NT contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered by the HKeyLocalMachine\SECURITY\Policy\Secrets\ registry key containing plaintext passwords to running services. This may allow a local attacker to gain information to password information.
|
1997-07-16
|
Microsoft Windows NT Registry Plaintext Service Password Local Disclosure
|
|
29
Description:
(Description Provided by CVE) : The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.
|
1997-07-15
|
NCSA campas CGI Arbitrary Command Execution
|
|
164
Description:
IRIX contains a flaw that may allow a malicious attacker to obtain a complete listing of files and directories on vulnerable systems. The issue is triggered when the File Altercation Monitor (fam) daemon is instructed by a program to monitor the root directory. It is possible that the flaw may allow retrieval of all files under the root directory, resulting in a loss of confidentiality.
|
1997-07-14
|
IRIX File Alteration Monitor (fam) Arbitrary Directory Listing
|
|
8423
Description:
A local overflow exists in SGI IRIX. The pset program fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request, a malicious user can cause arbitrary commands execution with root privileges resulting in a loss of integrity.
|
1997-07-10
|
IRIX pset Argument Handling Local Overflow
|
|
236
Description:
(Description Provided by CVE) : The Webgais program allows a remote user to execute arbitrary commands.
|
1997-07-10
|
WebGais webgais CGI Arbitrary Command Execution
|
|
2917
Description:
Microsoft Access has a flaw in the encryption used to protect databases. The RC4 based encryption uses the same key for both encryption and decryption with no password/phrase. By creating a database equal in size as the target database, an attacker can use the XOR'd key stream from the newly created database to decrypt the target database.
|
1997-07-09
|
Microsoft Access Known Database Attack
|
|
7873
Description:
(Description Provided by CVE) : JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.
|
1997-07-08
|
Multiple Browser JavaScript Web Activity Disclosure
|
|
11289
Description:
(Description Provided by CVE) : A remote attacker can read information from a Netscape user's cache via JavaScript.
|
1997-07-08
|
Netscape JavaScript Remote Cache Disclosure
|
|
237
Description:
(Description Provided by CVE) : websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).
|
1997-07-04
|
WebGais websendmail CGI Arbitrary Command Execution
|
|
82
Description:
(Description Provided by CVE) : The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.
|
1997-07-02
|
Glimpse HTTP aglimpse Arbitrary Command Execution
|
|
957
Description:
(Description Provided by CVE) : Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.
|
1997-07-01
|
Serv-U FTP Server CWD Command Overflow
|
|
8422
Description:
A local overflow exists in SGI IRIX. The df program fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request, a malicious user can cause arbitrary commands execution with root privileges resulting in a loss of integrity.
|
1997-07-01
|
IRIX df Local Overflow
|
|
8426
Description:
A local overflow exists in SGI IRIX. The ordist program fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request, a malicious user can cause arbitrary commands execution with root privileges resulting in a loss of integrity.
|
1997-07-01
|
IRIX ordist Local Overflow
|
|
198
Description:
Sendmail contains a flaw that may allow a remote attacker to relay mail through the server. In older versions of sendmail, default configurations allowed many methods of e-mail relay. This allowed a remote attacker to send mail through the server and cause the email to appear to come from the victim server. This makes it more difficult to easily spot where the mail comes from and allows basic e-mail spoofing. This practice is typically referred to "sending spam" or "spamming".
|
1997-07-01
|
Sendmail Multiple Method E-mail Relay
|
|
958
Description:
Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.
|
1997-07-01
|
Multiple Vendor FTP Multiple PASV Command Port Exhaustion DoS
|
|
5873
Description:
(Description Provided by CVE) : wu-ftpd FTP daemon allows any user and password combination.
|
1997-07-01
|
WU-FTPD Any User/Password Authentication
|
|
8425
Description:
A local overflow exists in SGI IRIX. The scheme program fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request, a malicious user can cause arbitrary commands execution with root privileges resulting in a loss of integrity.
|
1997-07-01
|
IRIX scheme Local Overflow
|
|
9735
Description:
(Description Provided by CVE) : When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.
|
1997-07-01
|
ISC BIND -DALLOW_UPDATES Option Remote Record Modification
|
|
10604
Description:
(Description Provided by CVE) : The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.
|
1997-07-01
|
Microsoft Windows NT PATH Working Directory Inclusion
|
|
10616
Description:
(Description Provided by CVE) : Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.
|
1997-07-01
|
Microsoft Windows NT Fragmented IP Packet Firewall Restriction Bypass
|
|
59250
Description:
(Description Provided by CVE) : Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
|
1997-07-01
|
Microsoft Windows NT Fragmented Packet Handling Remote DoS (ntfrag)
|
|
59251
Description:
(Description Provided by CVE) : Buffer overflow in ircd allows arbitrary command execution.
|
1997-07-01
|
Dalnet IRCd SERVER Message Remote Overflow
|
|
830
Description:
(Description Provided by CVE) : Buffer overflow in ircd allows arbitrary command execution.
|
1997-06-30
|
IRCnet IRCd s_serv.c SERVER Message Remote Overflow
|
|
59264
Description:
(Description Provided by CVE) : Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.
|
1997-06-29
|
Microsoft Windows Crafted Fragmented Packet Stream Remote DoS (Jolt)
|
|
11477
Description:
Microsoft Windows NT 4.0 contains a flaw that may allow a remote denial of service. The issue is triggered when a remote attacker causes an access violation within LSASS.exe causing the process to stop running, and will result in loss of availability for the operating system.
|
1997-06-28
|
Microsoft Windows NT LSASS.EXE Access Violation DoS
|
|
83446
Description:
Samba is prone to an overflow condition. This issue is triggered when smbmount fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted multiple variable username, a local attacker can potentially execute arbitrary code.
|
1997-06-27
|
Samba smbmount Multiple Variable Username Handling Local Overflow
|
|
11225
Description:
A local overflow exists in SVGAlib/zgv. The product fails to verify the length of the HOME environment variable, resulting in a buffer overflow. By setting this variable to an overly long value, arbitrary code can be executed as root, resulting in a loss of availability.
|
1997-06-27
|
SVGAlib zgv HOME Environment Variable Local Overflow
|
|
935
Description:
(Description Provided by CVE) : ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.
|
1997-06-26
|
Solaris Multicast Address ping -i DoS
|
|
84074
Description:
Ultrix contains a flaw that is triggered by dxterm being given setuid privileges. This may allow a remote attacker to log output data to arbitrary files, which will overwrite pre-existing data on that file.
|
1997-06-26
|
Ultrix dxterm Log Output Arbitrary File Overwrite
|
|
7420
Description:
(Description Provided by CVE) : Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.
|
1997-06-25
|
bootpd bootpd.c handle_request() Function Boot File Location Overflow
|
|
8674
Description:
(Description Provided by CVE) : Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries.
|
1997-06-25
|
Solaris Solstice AdminSuite NIS+ Password Table Modification
|
|
8675
Description:
(Description Provided by CVE) : Solaris Solstice AdminSuite (AdminSuite) 2.1 incorrectly sets write permissions on source files for NIS maps, which could allow local users to gain privileges by modifying /etc/passwd.
|
1997-06-25
|
Solaris Solstice AdminSuite Unauthorized /etc/passwd Modification
|
|
8676
Description:
(Description Provided by CVE) : Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.
|
1997-06-25
|
Solaris Solstice AdminSuite Symlink Arbitrary File Overwrite
|
|
8677
Description:
(Description Provided by CVE) : Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.
|
1997-06-25
|
Solaris Solstice AdminSuite Lock File Privilege Escalation
|