| OSVDB ID | Disclosure Date | Title |
|
1165
Description:
(Description Provided by CVE) : Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.
|
1999-12-16
|
NT SYSKEY Reused Keystream
|
|
1166
Description:
(Description Provided by CVE) : Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request."
|
1999-12-16
|
Microsoft Windows NT LsaLookupSids() DoS
|
|
8890
Description:
(Description Provided by CVE) : Cisco Cache Engine allows a remote attacker to gain access via a null username and password.
|
1999-12-16
|
Cisco Cache Engine Null Authentication Credential Access
|
|
8891
Description:
(Description Provided by CVE) : The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics.
|
1999-12-16
|
Cisco Cache Engine Web Admin Interface Statistics Information Disclosure
|
|
8892
Description:
(Description Provided by CVE) : Cisco Cache Engine allows an attacker to replace content in the cache.
|
1999-12-16
|
Cisco Cache Engine Content Modification
|
|
8023
Description:
(Description Provided by CVE) : xsoldier program allows local users to gain root access via a long argument.
|
1999-12-15
|
xsoldier -display Option Local Overflow
|
|
7693
Description:
(Description Provided by CVE) : The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.
|
1999-12-15
|
wvdial PPP wvdial.lxdialog .config Login Credential Disclosure
|
|
83866
Description:
NetKit (ntalk) contains a flaw that may allow a remote denial of service. The issue is triggered when the talkd announce message is passed as a format string containing percent signs(%). This will result in a loss of availability for the program.
|
1999-12-14
|
NetKit (ntalk) talkd Announce Message Format String Remote DoS
|
|
83865
Description:
NetKit (netkit-ftp) contains and unspecified issue related to Passive Mode (PASV). No further details have been provided.
|
1999-12-14
|
NetKit (netkit-ftp) Passive Mode (PASV) Unspecified Issue
|
|
83864
Description:
NetKit (netkit-base) contains a flaw that may allow a local denial of service. The issue is triggered when a user sends a SIGPIPE signal to the inetd process, which will result in loss of availability for the program.
|
1999-12-14
|
NetKit (netkit-base) inetd SIGPIPE Handling Local DoS
|
|
83863
Description:
NetKit (netkit-base) contains a flaw related to the inetd service that may allow a local denial of service. This issue is triggered during the handling of a spoofed UDP packet. This will result in a loss of availability for the program.
|
1999-12-14
|
NetKit (netkit-base) inetd Spoofed UDP Packet Handling Remote DoS
|
|
83862
Description:
NetKit (netkit-base) contains a flaw that may allow a denial of service. The issue is triggered when an unspecified error occurs in inetd. This will result in a minor loss of availability for the program.
|
1999-12-14
|
NetKit (netkit-base) inetd Unspecified Minor DoS
|
|
4680
Description:
War FTP Daemon version 1.70 contains a flaw that may allow a remote denial of service. The issue is triggered when sixty or more connections are established when certain characters are used in the logon name. This will result in loss of availability for the service.
|
1999-12-14
|
WarFTPd Connection Flood DoS
|
|
8024
Description:
(Description Provided by CVE) : An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.
|
1999-12-14
|
SSH Client Encrypted Session Policy Bypass
|
|
11074
Description:
(Description Provided by CVE) : HP VirtualVault with the PHSS_17692 patch allows unprivileged processes to bypass access restrictions via the Trusted Gateway Proxy (TGP).
|
1999-12-14
|
HP VirtualVault Trusted Gateway Proxy Process Restriction Bypass
|
|
1164
Description:
(Description Provided by CVE) : Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file.
|
1999-12-13
|
VDO Live Player Crafted .vdo File Handling Overflow
|
|
59258
Description:
(Description Provided by CVE) : Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.
|
1999-12-13
|
Microsoft Exchange ACL Modification Update Weakness
|
|
90022
Description:
Libxml2 contains a flaw in HTMLparser.c that may allow a denial of service. The issue is triggered during the handling of malformed input. This may allow a context-dependent attacker to crash the program.
|
1999-12-12
|
Libxml2 HTMLparser.c Malformed Input DoS
|
|
7573
Description:
NetBSD on VAX contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a malicious user constructs a wrapper program using the ptrace system call that can modify the hardware privileges of a process. This flaw may lead to a loss of integrity.
|
1999-12-12
|
NetBSD on VAX ptrace Call PSL Content Modification
|
|
9825
Description:
(Description Provided by CVE) : The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system.
|
1999-12-12
|
Disney Go Express Search HTTP Information Disclosure
|
|
2558
Description:
A remote overflow exists in Solaris sadmind daemon. The daemon fails to validate intput to the amsl_verify() function during a NETMGT_PROC_SERVICE request resulting in a buffer overflow. With a specially crafted request, an attacker can execute arbitrary code as root resulting in a loss of integrity and confidentiality.
|
1999-12-11
|
Solaris sadmind amsl_verify() Function Remote Overflow
|
|
1162
Description:
(Description Provided by CVE) : The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into _init before the privileged process is executed.
|
1999-12-10
|
SCO Unixware Privileged Program Debugging
|
|
1063
Description:
(Description Provided by CVE) : Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.
|
1999-12-09
|
Netscape Communicator pluginspage Option EMBED Tag Overflow
|
|
1158
Description:
A remote overflow exists in Xshipwars. The game server fails to properly check bounds resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
1999-12-09
|
Xshipwars Command Handling Remote Overflow
|
|
1163
Description:
(Description Provided by CVE) : The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.
|
1999-12-09
|
Linux Kernel Malformed Packet Options Handling Remote DoS
|
|
1159
Description:
(Description Provided by CVE) : Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.
|
1999-12-09
|
Solaris snoop GETQUOTA Remote Overflow
|
|
1160
Description:
(Description Provided by CVE) : htdig allows remote attackers to execute commands via filenames with shell metacharacters.
|
1999-12-09
|
ht://Dig (htdig) Filename Shell Metacharacter Arbitrary Command Execution
|
|
8084
Description:
WebSTAR Admin Application contains a flaw that may allow a remote denial of service. The issue is triggered when an attacker intentionally fails to enter a connection password which disables menu options, and will result in loss of availability for the service.
|
1999-12-08
|
4D WebSTAR Admin Application Connection Password Menu DoS
|
|
8085
Description:
WebSTAR Admin Application contains a flaw that may allow a remote denial of service. The issue is triggered when an attacker established and then quickly cancelled a new connection, and will result in loss of availability for the service.
|
1999-12-08
|
4D WebSTAR Admin Application Connection Cancel DoS
|
|
7832
Description:
(Description Provided by CVE) : Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect."
|
1999-12-08
|
Microsoft IE Client Window Reference Server Side Arbitrary File Access
|
|
1155
Description:
(Description Provided by CVE) : Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.
|
1999-12-07
|
Solaris snoop print_domain_name Function Remote Overflow
|
|
1161
Description:
(Description Provided by CVE) : The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.
|
1999-12-07
|
Microsoft Windows Help System File Manipulation Local Privilege Escalation
|
|
1154
Description:
(Description Provided by CVE) : Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.
|
1999-12-07
|
Sendmail Aliases Database Unprivileged Regeneration DoS
|
|
6267
Description:
A remote overflow exists in POP3 proxy service(POProxy)of Norton Anti-Virus. The POProxy fails to validate the USER command. By sending a username containing more than 264 characters to the USER command to the proxy service, a remote attacker can overflow the buffer and crash the service, resulting in loss of availability.
|
1999-12-07
|
Symantec Norton Anti-Virus NAV2000 POProxy USER Command Remote Overflow
|
|
1157
Description:
(Description Provided by CVE) : Buffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name.
|
1999-12-06
|
GoodTech Telnet Server NT Username Field Overflow Remote DoS
|
|
9824
Description:
(Description Provided by CVE) : Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.
|
1999-12-06
|
GNOME Display Manager (gdm) VerboseAuth Setting Error Message Information Disclosure
|
|
11097
Description:
(Description Provided by CVE) : Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.
|
1999-12-06
|
Windows NT SP2 Passfilt.dll Password Complexity Weakness
|
|
1156
Description:
(Description Provided by CVE) : Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.
|
1999-12-05
|
Microsoft IE MSDXM.OCX vnd.ms.radio URL Handling Overflow
|
|
6490
Description:
A remote overflow exists in Infoseek Ultraseek. Infoseek Ultraseek fails to check the buffer boundary in GET command. By sending a specially crafted GET request via port 8765, a remote attacker can cause cause a buffer overflow and execute arbitrary code, resulting in a loss of integrity.
|
1999-12-05
|
Infoseek Ultraseek GET Request Overflow
|
|
11261
Description:
(Description Provided by CVE) : The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.
|
1999-12-05
|
Sun Web-Based Enterprise Management (WBEM) World Readable Install Password
|