| OSVDB ID | Disclosure Date | Title |
|
13755
Description:
(Description Provided by CVE) : The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request.
|
2000-11-30
|
PostACI Webmail System global.inc Direct Request Information Disclosure
|
|
60974
Description:
BSDIi is prone to an overflow condition. The /usr/contrib/mh/bin/inc binary fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted request, a local attacker can potentially execute arbitrary code with increased privileges.
|
2000-11-30
|
BSDI inc[mh] Local Overflow
|
|
85825
Description:
Linux Kernel contains a flaw that is triggered when ptrace is used to track a child process, which will result in the program not properly checking permissions of the user. This may allow a remote attacker to bypass restrictions and gain access to potentially sensitive information stored within executable files.
|
2000-11-30
|
Linux Kernel ptrace Child Process Restriction Bypass
|
|
462
Description:
(Description Provided by CVE) : Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities. NOTE: this candidate may change significantly as the security community discusses the technical nature of NAPTHA and learns more about the affected applications. This candidate is at a higher level of abstraction than is typical for CVE.
|
2000-11-30
|
Multiple Vendor Crafted TCP/IP Packet DoS (NAPTHA)
|
|
1672
Description:
(Description Provided by CVE) : Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input.
|
2000-11-30
|
Microsoft Windows 2000 Telnet Session Timeout DoS
|
|
7208
Description:
fshd contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an attacker creates a symbolic link to a file owned by the user running fshd. Standard unix commands can be used to exploit this issue. This flaw may lead to a loss of Confidentiality, Integrity and/or Availability.
|
2000-11-30
|
Debian fshd Symlink Arbitrary Command Execution
|
|
60978
Description:
Unknown / Incomplete
|
2000-11-30
|
INND/NNRP From: Field Remote Overflow
|
|
49712
Description:
Unknown / Incomplete
|
2000-11-29
|
Nimbus Algorithm Differential Attack Chosen-plaintext Cryptanalysis Compromise
|
|
1667
Description:
SonicWALL SOHO2 Firewall contains a flaw that may allow a remote denial of service. The issue is triggered when a remote attacker provides an overly long username to the web server, and will result in loss of availability for the firewall.
|
2000-11-29
|
SonicWALL SOHO2 Firewall HTTP Long Username DoS
|
|
6627
Description:
(Description Provided by CVE) : Allaire JRun 2.3 server allows remote attackers to obtain source code for executable content by directly calling the SSIFilter servlet.
|
2000-11-29
|
Allaire JRun SSIFilter Code Retrieval
|
|
7206
Description:
(Description Provided by CVE) : Buffer overflow in pam_localuser PAM module in Red Hat Linux 7.x and 6.x allows attackers to gain privileges.
|
2000-11-29
|
pam_localuser PAM Module Overflow
|
|
7255
Description:
Sun JDK (Java Development Kit) and JRE (Java Runtime Environment) contains a flaw that may allow a malicious user to acces restricted resources. The issue is triggered when an untrusted java class loads other disallowed java classes, which will escape the Java sandbox and conduct unauthorized activities, resulting in a loss of confidentiality and integrity.
|
2000-11-29
|
Sun Java JDK / JRE Disallowed Class Sandbox Bypass
|
|
9483
Description:
(Description Provided by CVE) : document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.
|
2000-11-28
|
IBM Net.Data db2www Package document.d2w Path Disclosure
|
|
460
Description:
Cisco CBOS contains a flaw that may allow a remote denial of service. The issue is triggered when an attacker sends a malicous GET request occurs, and will result in loss of availability for the router.
|
2000-11-28
|
Cisco 600 Series Router HTTP GET DoS
|
|
1668
Description:
(Description Provided by CVE) : Trend Micro InterScan VirusWall creates an "Intscan" share to the "InterScan" directory with permissions that grant Full Control permissions to the Everyone group, which allows attackers to gain privileges by modifying the VirusWall programs.
|
2000-11-28
|
Trend Micro InterScan VirusWall Shared Directory Privilege Escalation
|
|
1670
Description:
(Description Provided by CVE) : in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request, which causes the server to access a NULL pointer and crash.
|
2000-11-28
|
SuSE in.identd Long Request DoS
|
|
1671
Description:
(Description Provided by CVE) : Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed.
|
2000-11-28
|
Midnight Commander Directory Viewing Command Execution
|
|
20987
Description:
(Description Provided by CVE) : BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.
|
2000-11-27
|
BEA WebLogic Restricted Page Multiple Slash Authorization Bypass
|
|
1665
Description:
(Description Provided by CVE) : Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack.
|
2000-11-27
|
Winsock FTPd Directory Traversal
|
|
7746
Description:
(Description Provided by CVE) : Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.
|
2000-11-27
|
Windows NT FTP Server (WFTP) CD Command Arbitrary File Access
|
|
10889
Description:
(Description Provided by CVE) : 24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request.
|
2000-11-27
|
24Link Web Server Special Character GET Request Access Restriction Bypass
|
|
1664
Description:
(Description Provided by CVE) : Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer.
|
2000-11-26
|
Secure Locate (slocate) Malformed Database Heap Corruption
|
|
11813
Description:
(Description Provided by CVE) : PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode +owgscfxeb" and "oper" commands.
|
2000-11-26
|
PTlink IRCD / Services Malformed Mode DoS
|
|
13756
Description:
BSD contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the rcvtty component fails to properly drop SGID privileges before executing arbitrary commands contained within incoming messages. A malicious user can prepare a shell script containing the commands, which will execute with the privileges of the tty group. This flaw may lead to a loss of integrity.
|
2000-11-26
|
BSD rcvtty Incoming Message Privilege Escalation
|
|
1663
Description:
(Description Provided by CVE) : Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.
|
2000-11-25
|
TWIG index.php3 vhosts Variable Arbitrary Command Execution
|
|
10807
Description:
(Description Provided by CVE) : The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.
|
2000-11-24
|
IBM Lotus Notes Client JVM ECL getSystemResource Method File Existence Disclosure
|
|
53866
Description:
Phorum contains a flaw that allows a remote attacker to traverse and access files outside of the web path. The issue is due to the support/common.php not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'ForumLang' variable.
|
2000-11-23
|
Phorum support/common.php ForumLang Parameter Traversal Arbitrary File Access
|
|
20179
Description:
(Description Provided by CVE) : Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others.
|
2000-11-23
|
Caucho Resin Crafted File Request JSP Source Disclosure
|
|
4741
Description:
(Description Provided by CVE) : McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.
|
2000-11-23
|
McAfee WebShield Malformed Outgoing SMTP Recipient Remote DoS
|
|
1659
Description:
(Description Provided by CVE) : Balabit syslog-ng allows remote attackers to cause a denial of service (application crash) via a malformed log message that does not have a closing > in the priority specifier.
|
2000-11-23
|
Balabit syslog-ng Incomplete Priority String Remote DoS
|
|
1661
Description:
(Description Provided by CVE) : ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.
|
2000-11-23
|
Aladdin Ghostscript Symlink Arbitrary File Overwrite
|
|
4740
Description:
(Description Provided by CVE) : McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment.
|
2000-11-23
|
McAfee WebShield SMTP Filter Bypass
|
|
9672
Description:
(Description Provided by CVE) : IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
|
2000-11-23
|
IBM HTTP Server Long GET Request Overflow
|
|
13476
Description:
(Description Provided by CVE) : Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed in MS:MS00-090.
|
2000-11-23
|
Microsoft Windows Media Player asx Parser Multiple Tag Overflow
|
|
85830
Description:
Microsoft IE contains a flaw that is triggered by an error in index.dat that may allow for the injection of OBJECT DATA tag files. This may allow a remote attacker to execute arbitrary commands.
|
2000-11-23
|
Microsoft IE index.dat OBJECT DATA Tag File Injection Arbitrary Command Execution
|
|
85831
Description:
Phorum contains a flaw that is triggered when certain input passed via the 'f' parameter is not properly sanitized before being used in the list.php script. This may allow a remote attacker to gain access to arbitrary files.
|
2000-11-23
|
Phorum list.php f Parameter Arbitrary File Access
|
|
1656
Description:
(Description Provided by CVE) : Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.
|
2000-11-22
|
Microsoft Windows Media Player .WMS Arbitrary Script Execution
|
|
1658
Description:
(Description Provided by CVE) : Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the ".ASX Buffer Overrun" vulnerability.
|
2000-11-22
|
Microsoft Windows Media Player .ASX File Handling Overflow
|
|
11344
Description:
(Description Provided by CVE) : Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information.
|
2000-11-22
|
Microsys CyberPatrol Weak Encryption Credit Card Disclosure
|
|
1657
Description:
(Description Provided by CVE) : Buffer overflow in remote web administration component (webprox.dll) of 602Pro LAN SUITE before 2000.0.1.33 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
|
2000-11-22
|
602Pro LAN SUITE webprox.dll GET Request Overflow
|