| OSVDB ID | Disclosure Date | Title |
|
1586
Description:
(Description Provided by CVE) : Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.
|
2000-09-30
|
sshd scp Traversal Arbitrary File Overwrite
|
|
13767
Description:
(Description Provided by CVE) : userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).
|
2000-09-30
|
Red Hat Linux usermode Package userhelper glibc Security Meausre Bypass
|
|
76072
Description:
(Description Provided by CVE) : The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.
|
2000-09-29
|
Apache JServ jserv.conf jserv-status Handler jserv/ URI Request Parsing Local Information Disclosure
|
|
1577
Description:
(Description Provided by CVE) : mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
|
2000-09-29
|
Apache HTTP Server mod_rewrite RewriteRule Expansion Arbitrary File Access
|
|
1578
Description:
(Description Provided by CVE) : The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability.
|
2000-09-29
|
Microsoft Windows 2000 Simplified Chinese IME Local Privilege Escalation
|
|
1581
Description:
(Description Provided by CVE) : The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an "xhost + localhost" command, which allows local users to sniff X Windows events and gain privileges.
|
2000-09-29
|
Mandrake Xsession Default Config Local Xauthority Bypass
|
|
1582
Description:
(Description Provided by CVE) : The default configuration of XFCE 3.5.1 bypasses the Xauthority access control mechanism with an "xhost + localhost" command in the xinitrc program, which allows local users to sniff X Windows traffic and gain privileges.
|
2000-09-29
|
Xfce xinitrc Default Config Local Xauthority Bypass
|
|
13748
Description:
(Description Provided by CVE) : The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode priviliges and possibly execute arbitrary commands.
|
2000-09-29
|
Slashcode Default Administrator Password
|
|
2266
Description:
Unknown / Incomplete
|
2000-09-28
|
IRCnet IRCD s_bsd.c summon() Function Overflow
|
|
1584
Description:
(Description Provided by CVE) : Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.
|
2000-09-28
|
LBNL traceroute -g Option Local Overflow
|
|
1575
Description:
(Description Provided by CVE) : WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions.
|
2000-09-28
|
WQuinn QuotaAdvisor Alternative Data Stream Disk Quota Bypass
|
|
1576
Description:
(Description Provided by CVE) : Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
|
2000-09-28
|
Siemens HiNet LP5100 IP-phone Overflow DoS
|
|
6776
Description:
Web+ contains a flaw related to the example applications that may allow an attacker to gain access to root privileges and manipulate files. No further details have been provided.
|
2000-09-27
|
talentsoft Web+ webping.wml Example Application Arbitrary File Access
|
|
1573
Description:
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
|
2000-09-27
|
GNU C Library (glibc2) LD_DEBUG Arbitrary File Overwrite
|
|
4415
Description:
Check Point VPN-1/FireWall-1 contains a flaw that may allow a remote attacker to send traffic that bypasses the ruleset. The issue is due to a flaw in the FWZ client processing that may allow spoofed packets through despite anti-spoofing checks being present. If an attacker sends specially crafted packets encapsulated as FWZ packets, the firewall may let them pass.
|
2000-09-27
|
Check Point FireWall-1 fwz Client Spoof Bypass
|
|
4419
Description:
Check Point VPN-1/FireWall-1 contains a flaw that may allow a remote attacker to bypass the ruleset. The issue is due to the firewall not properly filtering specially fragmented TCP connections that will bypass the directionality checks implemented. If an attacker sends the right requests by closing and reopening one-way connections, they may be able to initiate traffic otherwise denied.
|
2000-09-27
|
Check Point VPN-1/FireWall-1 One-way Connection Enforcement Bypass
|
|
6042
Description:
FreeBSD contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a malicious user misuses the catopen() function. A valid locale file or message catalog containing specially formatted characters can be read by poorly coded privileged applications to execute arbitrary code. This flaw may lead to a loss of integrity.
|
2000-09-27
|
FreeBSD catopen() Arbitrary Code Execution
|
|
6043
Description:
FreeBSD contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a malicious user misuses the setlocale() function by creating a file which is a valid locale file or message catalog but contains special formatting characters which may allow certain badly written privileged applications to be exploited to execute arbitrary code. This flaw may lead to a loss of integrity.
|
2000-09-27
|
FreeBSD setlocale() Arbitrary Code Execution
|
|
6070
Description:
A local overflow exists in FreeBSD. The catopen() function fails to check bounds of an internal buffer which could be indirectly overflowed by the setting of an environment variable. With a specially crafted request, a privileged application which uses catopen() could be made to execute arbitrary code by an unprivileged local user resulting in a loss of integrity.
|
2000-09-27
|
FreeBSD catopen() Local Overflow
|
|
7199
Description:
(Description Provided by CVE) : Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, in the SNMP service (snmp.exe), aka the "Java SNMP MIB Browser Object ID parsing problem."
|
2000-09-26
|
HP OpenView Network Node Manager (OV NNM) OverView5 snmp.exe Remote Overflow DoS
|
|
1571
Description:
(Description Provided by CVE) : Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.
|
2000-09-26
|
Microsoft Windows Media Player Malformed Embedded OCX Control DoS
|
|
3111
Description:
(Description Provided by CVE) : Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.
|
2000-09-26
|
Microsoft IE Windows Scripting Host (WSH) GetObject Javascript Function Arbitrary File Access
|
|
3240
Description:
SCO UnixWare contains a flaw that allows a remote attacker to execute arbitrary code on a vulnerable system under the "nobody" ID. By sending a specially-crafted URL to the "scohelp" application (port 457), an attacker can take advantage of a format string vulnerability to execute arbitrary code.
|
2000-09-26
|
SCO Help search97cgi/vtopic Format String Arbitrary Command Execution
|
|
10055
Description:
(Description Provided by CVE) : PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device to decrypt the password and gain access to the device.
|
2000-09-26
|
Palm OS Password Storage Encryption Weakness
|
|
478
Description:
(Description Provided by CVE) : Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.
|
2000-09-26
|
Netscape Messaging Server IMAP LIST Command Remote Overflow
|
|
1572
Description:
(Description Provided by CVE) : Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary commands via format characters in the queryText parameter.
|
2000-09-26
|
SCO UnixWare SCOhelp search97.cgi queryText Parameter Arbitrary Command Execution
|
|
1595
Description:
(Description Provided by CVE) : WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares.
|
2000-09-26
|
WQuinn DiskAdvisor Targeted Share Arbitrary File / Directory Disclosure
|
|
5832
Description:
(Description Provided by CVE) : Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive information, or remote web servers to obtain the information via a telnet: URL.
|
2000-09-26
|
Telnet Client Allows Server to Retrieve Environment Variables
|
|
13765
Description:
(Description Provided by CVE) : Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.
|
2000-09-26
|
BSD-based lpr Package startprinting() Function Local Format String
|
|
421
Description:
LPRng is prone to a format string flaw. The use_syslog() function fails to properly sanitize user-supplied input. With a specially crafted request, a remote attacker can potentially cause arbitrary code execution.
|
2000-09-25
|
LPRng use_syslog() Remote Format String
|
|
12083
Description:
(Description Provided by CVE) : EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands.
|
2000-09-25
|
Etype Eserv Multiple Mail Command Remote Overflow
|
|
88229
Description:
Sybase Adaptive Server Enterprise contains an unspecified flaw. No further details have been provided.
|
2000-09-25
|
Sybase Adaptive Server Enterprise Unspecified Issue
|
|
88228
Description:
Sybase Adaptive Server Enterprise contains an unspecified flaw related to the Enterprise Portal (EP) component. No further details have been provided.
|
2000-09-25
|
Sybase Adaptive Server Enterprise Enterprise Portal (EP) Component Unspecified Issue
|
|
13750
Description:
(Description Provided by CVE) : The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name information via the nsManager.cgi CGI program.
|
2000-09-24
|
Alabanza Control Panel nsManager.cgi Unauthorized Domain Name Modification
|
|
1567
Description:
(Description Provided by CVE) : Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.
|
2000-09-22
|
Pine Automatic Mail Check From Header Overflow
|
|
1579
Description:
(Description Provided by CVE) : SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable.
|
2000-09-22
|
Smartwin Technology CyberOffice Shopping Cart Price Modification
|
|
1580
Description:
(Description Provided by CVE) : The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.
|
2000-09-22
|
SmartWin CyberOffice Shopping Cart Client Information Disclosure
|
|
285
Description:
This host is running Microsoft IIS web server and the file /scripts/repost.asp is installed. This APS file contains a configuration flaw that allows an attacker to upload files to the /users directory. An attacker could use this to upload arbitrary files onto this host.
|
2000-09-22
|
Microsoft IIS repost.asp File Upload
|
|
6775
Description:
Unknown / Incomplete
|
2000-09-21
|
talentsoft Web+ ::$DATA Stream Request WML Source Disclosure
|
|
417
Description:
(Description Provided by CVE) : The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.
|
2000-09-21
|
Apache HTTP Server on SuSE Linux /doc/packages Remote Information Disclosure
|