| OSVDB ID | Disclosure Date | Title |
|
1169
Description:
WMMon, a FreeBSD port, contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when WMMon is setgid kmem and configured to execute arbitrary commands via the .wmmonrc configuration file. This flaw may lead to a loss of integrity.
|
1999-12-21
|
FreeBSD WMMon Local Privilege Escalation
|
|
50
Description:
Lotus Domino HTTP Server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a URL with a non-existent cgi-bin program is called, which will disclose the actual path information resulting in a loss of confidentiality.
|
1999-12-21
|
IBM Lotus Domino CGI Directory Path Disclosure
|
|
51
Description:
Lotus Domino HTTP Service contains a flaw that may allow a remote denial of service. The issue is triggered when a very long URL is called in the /cgi-bin directory for a non-existent page, and will result in loss of availability for the platform. A hard reboot is required to recover.
|
1999-12-21
|
IBM Lotus Domino HTTP long URL DoS
|
|
1167
Description:
(Description Provided by CVE) : Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database.
|
1999-12-21
|
Solaris DMI dmisp File System DoS
|
|
3327
Description:
Lotus Domino HTTP Service contains a flaw that may allow a malicious user to gain inappropriate access to the cgi-bin directory. The issue is triggered when anonymous access to the cgi-bin directory is disabled. It is possible that the flaw may allow anonymous access to cgi-bin even when it has been turned off resulting in a loss of confidentiality.
|
1999-12-21
|
IBM Lotus Domino HTTP Anonymous CGI Access
|
|
7580
Description:
(Description Provided by CVE) : DNS PRO allows remote attackers to conduct a denial of service via a large number of connections.
|
1999-12-21
|
DNS PRO Connection Saturation DoS
|
|
8098
Description:
Microsoft IIS and Site Server contain a flaw that may allow a remote attacker to gain access to ASP page source code. The issue is triggered when ASP files are stored in virtual directories whose names include extensions such as .com, .exe, .sh, .cgi, or .dll. When an attacker requests such a file, the server will return the source code instead of processing the file normally.
|
1999-12-21
|
Microsoft IIS Virtual Directory ASP Source Disclosure
|
|
92016
Description:
SCO OpenServer contains a flaw in the /bin/hello binary that leads to unauthorized privileges being gained. The issue is due to the device not properly restricting access to privileged devices. This will allow a local attacker to gain access to the device.
|
1999-12-21
|
SCO OpenServer /bin/hello Arbitrary Privileged Device Access
|
|
92017
Description:
SCO OpenServer contains an flaw in the /bin/hello binary that is triggered during the handling of unspecified 'dangerous' characters, which may allow a local attacker to have an unspecified impact. No further details have been provided by the researcher.
|
1999-12-21
|
SCO OpenServer /bin/hello Unspecified 'Dangerous' Character Handling Issue
|
|
92018
Description:
SCO OpenServer contains an flaw in the /bin/write binary that is triggered during the handling of unspecified 'dangerous' characters, which may allow a local attacker to have an unspecified impact. No further details have been provided by the researcher.
|
1999-12-21
|
SCO OpenServer /bin/write Unspecified 'Dangerous' Character Handling Issue
|
|
92019
Description:
SCO OpenServer contains an unspecified flaw in the /bin/login binary that may allow an attacker to have an unspecified impact. No further details have been provided by the researcher.
|
1999-12-21
|
SCO OpenServer /bin/login Unspecified Issue
|
|
92009
Description:
SCO OpenServer contains an overflow condition in the /etc/popper binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /etc/popper Local Overflow
|
|
92008
Description:
SCO OpenServer contains an overflow condition in the /usr/bin/rlogin binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/bin/rlogin Local Overflow
|
|
92007
Description:
SCO OpenServer contains an overflow condition in the /usr/lib/sysadm/termsh binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/lib/sysadm/termsh Local Overflow
|
|
92006
Description:
SCO OpenServer contains an overflow condition in the /usr/lib/libX11.so.5.0 binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/lib/libX11.so.5.0 Local Overflow
|
|
92005
Description:
SCO OpenServer contains an overflow condition in the /usr/lib/libXt.so.5.0 binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/lib/libXt.so.5.0 Local Overflow
|
|
92004
Description:
SCO OpenServer contains an overflow condition in the /usr/lib/libXmu.so.5.0 binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/lib/libXmu.so.5.0 Local Overflow
|
|
92003
Description:
SCO OpenServer contains an overflow condition in the /usr/lib/libXaw.so.5.0 binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/lib/libXaw.so.5.0 Local Overflow
|
|
92002
Description:
SCO OpenServer contains an overflow condition in the /usr/lib/libX11.a binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/lib/libX11.a Local Overflow
|
|
92001
Description:
SCO OpenServer contains an overflow condition in the /usr/lib/libXt.a binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/lib/libXt.a Local Overflow
|
|
92000
Description:
SCO OpenServer contains an overflow condition in the /usr/lib/libXmu.a binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/lib/libXmu.a Local Overflow
|
|
91999
Description:
SCO OpenServer contains an overflow condition in the /usr/lib/libXaw.a binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/lib/libXaw.a Local Overflow
|
|
91998
Description:
SCO OpenServer contains an overflow condition in the /usr/bin/X11/xload binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/bin/X11/xload Local Overflow
|
|
91997
Description:
SCO OpenServer contains an overflow condition in the /usr/bin/X11/scolock binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/bin/X11/scolock Local Overflow
|
|
91996
Description:
SCO OpenServer contains an overflow condition in the /usr/bin/X11/scologin binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/bin/X11/scologin Local Overflow
|
|
91995
Description:
SCO OpenServer contains an overflow condition in the /usr/lpd/remote/rlpstat binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/lpd/remote/rlpstat Local Overflow
|
|
91994
Description:
SCO OpenServer contains an overflow condition in the /usr/lpd/remote/cancel binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/lpd/remote/cancel Local Overflow
|
|
91993
Description:
SCO OpenServer contains an overflow condition in the /usr/lpd/remote/lpmove binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-21
|
SCO OpenServer /usr/lpd/remote/lpmove Local Overflow
|
|
91991
Description:
SCO OpenServer contains an overflow condition in the /usr/mmdf/chans/smtpsrvr binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-20
|
SCO OpenServer /usr/mmdf/chans/smtpsrvr Local Overflow
|
|
92020
Description:
SCO OpenServer contains a flaw in the /usr/bin/X11/Xsco binary. The issue is due to an error in the -config variable. This may allow a local attacker to gain limited access to arbitrary files.
|
1999-12-20
|
SCO OpenServer /usr/bin/X11/Xsco -config Variable Arbitrary Limited File Access
|
|
91992
Description:
SCO OpenServer contains an overflow condition in the etc/killall binary. The issue is triggered as user-supplied input is not properly validated via the command line. With a specially crafted command, a local attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
1999-12-20
|
SCO OpenServer /etc/killall Local Overflow
|
|
85842
Description:
X.Org X Window System (X11) is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a multiple overflow. With a specially crafted call to the LibX11, LibXt, LibXaw or LibXmu libraries, a local attacker can potentially execute arbitrary code.
|
1999-12-20
|
X.Org X Window System (X11) Multiple Libraries Local Overflow
|
|
48430
Description:
Unknown / Incomplete
|
1999-12-19
|
FAAC aac_qc.c Unpsecified Memory Overflow
|
|
1143
Description:
(Description Provided by CVE) : Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.
|
1999-12-19
|
Microsoft SQL Server TDS Header NULL Data Handling Remote DoS
|
|
1736
Description:
(Description Provided by CVE) : wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.
|
1999-12-19
|
WU-FTPD FTP Conversion Service Malformed File Name Handling Arbitrary Command Execution
|
|
3413
Description:
Novell Groupwise contains a vulnerability that allows a remote attacker to read arbitrary files in the web path. The issue is due to a lack of sanity checking for input passed to the HELP variable in the GWWEB.EXE program. By providing a .htm or .html file name and ../../ traversal attack, anyone can view any document within the web server path.
|
1999-12-19
|
Novell GroupWise GWWEB.EXE HELP Parameter Traversal Arbitrary File Access
|
|
3415
Description:
Novell Groupwise contains a flaw that allows a remote attacker to overflow the GWWEB.EXE program. By appending 512 or more characters to the end of a request, the program may crash or execute arbitrary code.
|
1999-12-19
|
Novell GroupWise GWWEB.EXE/GWINTER.NLM Overflow
|
|
3416
Description:
Novell Groupwise contains a flaw that allows a remote attacker to discover the physical path of the web server installation. By providing any bad input for the HELP variable of the GWWEB.EXE program, the attacker will receive an error page with the physical path.
|
1999-12-19
|
Novell GroupWise GWWEB.EXE HELP Web Server Path Disclosure
|
|
9783
Description:
(Description Provided by CVE) : Netscape Navigator uses weak encryption for storing a user's Netscape mail password.
|
1999-12-19
|
Netscape Navigator Mail Password Weak Encryption
|
|
7413
Description:
KAME contains a flaw related to the default directory that many of its daemons write dump files and trace files to, which may allow an attacker to access sensitive system information, or possibly to modify that data. The bgpd, hroute6d, pim6dd, pim6sd, route6d, and rtsold daemons used the world-writeable /var/tmp directory for dump and trace files. No further details have been provided.
|
1999-12-16
|
KAME Dump/Trace Location Issue
|