| OSVDB ID | Disclosure Date | Title |
|
13635
Description:
(Description Provided by CVE) : The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
|
2000-01-30
|
Red Hat Linux su Failed Password Logging Weakness
|
|
1212
Description:
Check Point FireWall-1 contains a flaw that allows a remote attacker to use malformed script tags that will bypass the firewall filter. The issue is due to Firewall-1 not properly recognizing certain malformed script tags and acting on them. Rather than block the traffic as it should, the firewall passes it.
|
2000-01-29
|
Check Point FireWall-1 Script Tag Check Bypass
|
|
88573
Description:
NetBSD contains a flaw in /proc/<pid>/mem in the procfs file system. The issue is triggered when a setuid binary is tricked in to writing from or reading the memory image of the process. This may allow a local privileged attacker to execute arbitrary commands.
|
2000-01-29
|
NetBSD procfs /proc/<pid>/mem Manipulation Privileged Command Execution
|
|
1210
Description:
Microsoft IIS contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the webhits.dll library not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the "CiWebHitsFile" variable. By supplying a crafted request to an htw script, it is possible to read arbitrary files on the system.
|
2000-01-27
|
Microsoft IIS WebHits.dll ISAPI Filter Traversal Arbitrary File Access
|
|
201
Description:
(Description Provided by CVE) : The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).
|
2000-01-27
|
Cobalt RaQ siteUserMod.cgi Arbitrary Password Modification
|
|
216
Description:
(Description Provided by CVE) : The SyGate Remote Management program does not properly restrict access to its administration service, which allows remote attackers to cause a denial of service, or access network traffic statistics.
|
2000-01-27
|
Sygate Open Remote Administration
|
|
12483
Description:
(Description Provided by CVE) : Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command.
|
2000-01-26
|
Qpopper LIST Command Local Overflow
|
|
7467
Description:
(Description Provided by CVE) : Buffer overflow in SCO scohelp program allows remote attackers to execute commands.
|
2000-01-26
|
SCO UnixWare scohelp Remote Overflow
|
|
7608
Description:
Microsoft Index Server in Microsoft Windows contains a flaw that may lead to an unauthorized information disclosure. By providing a request to a non-existent Internet Data Query file, a remote attacker could reveal the physical path to the web directory that was contained in the request resulting in a loss of confidentiality.
|
2000-01-26
|
Microsoft Index Server Internet Data Query Path Disclosure
|
|
1206
Description:
(Description Provided by CVE) : The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier.
|
2000-01-24
|
HP Path MTU Discovery DoS
|
|
85834
Description:
Oracle on Windows contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the a.jsp script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack would allow the attacker to gain access to arbitrary files.
|
2000-01-22
|
Oracle on Windows a.jsp Traversal Arbitrary File Access
|
|
85835
Description:
Oracle on Windows contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the bb.sqljsp script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack would allow the attacker to gain access to arbitrary files.
|
2000-01-22
|
Oracle on Windows bb.sqljsp Traversal Arbitrary File Access
|
|
1204
Description:
(Description Provided by CVE) : Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.
|
2000-01-22
|
vchkpw/vpopmail POP Authentication Multiple Field Overflow
|
|
1209
Description:
(Description Provided by CVE) : The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.
|
2000-01-22
|
Microsoft Terminal Server rdisk Registry Information Disclosure
|
|
11226
Description:
A remote overflow exists in zgv. zgv fails to perform proper boundary checking of TIFF filenames in the vgadisp.c readpicture function, which could potentially cause a buffer overflow. Using a TIFF image with a filename longer than 256 characters an attacker can execute arbitrary code or cause a denial of service resulting in a loss of integrity or availability.
|
2000-01-22
|
zgv Long TIFF Filename Overflow
|
|
11227
Description:
A remote overflow exists in zgv. zgv fails to perform boundary checking of the colname char array in readxpm.c, which may result in a stack overflow. Using a specially crafted XPM image an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2000-01-22
|
zgv XPM Image Long Color Name Overflow
|
|
1203
Description:
(Description Provided by CVE) : procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.
|
2000-01-21
|
Multiple BSD /proc File Sytem mem Interface Modification Privilege Escalation
|
|
13630
Description:
(Description Provided by CVE) : An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.
|
2000-01-21
|
Red Hat Linux crypt() Function DES Use Weakness
|
|
20760
Description:
Multiple BSD OSs contain a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a malicious user modifies the /proc/pid/mem interface via a modified file descriptor for stderr. This flaw may lead to a loss of integrity.
|
2000-01-21
|
Multiple BSD procfs /proc/[pid]/ setuid Binary Privileged Command Execution
|
|
59360
Description:
(Description Provided by CVE) : IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page.
|
2000-01-21
|
Microsoft IIS ASP Page Visual Basic Script Malformed Regex Parsing DoS
|
|
1775
Description:
(Description Provided by CVE) : O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character.
|
2000-01-20
|
O'Reilly Website Professional Malformed Request Path Disclosure
|
|
1202
Description:
(Description Provided by CVE) : The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.
|
2000-01-19
|
Multiple BSD make -j Parameter Symlink Arbitrary File Modification
|
|
872
Description:
This host appears to be the running the Apache Tomcat Servlet engine with the default accounts still configured. A potential intruder could reconfigure this service in a way that grants system access.
|
2000-01-19
|
Apache Tomcat Multiple Default Accounts
|
|
1208
Description:
(Description Provided by CVE) : Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability.
|
2000-01-19
|
Microsoft East Asian Word Conversion Document Arbitrary Command Execution
|
|
7609
Description:
A local overflow exists in SCO UnixWare. The 'ppptalk' command fails to properly check the bounds on command line options resulting in a buffer overflow. With a specially crafted request, a malicious user can gain access to elevated privileges resulting in a loss of integrity.
|
2000-01-19
|
SCO UnixWare ppptalk Long Prompt Overflow
|
|
7364
Description:
thttpd contains a flaw that allows a remote attacker to view arbitrary files outside of the web path. The issue is due to the program not properly sanitizing user input, specifically double-dot ('..') listings of virtual host directories. No further details have been provided.
|
2000-01-18
|
thttpd Double Dot Virtual Host Directory Listing
|
|
31
Description:
(Description Provided by CVE) : The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.
|
2000-01-18
|
CERN httpd Virtual Web Path Disclosure
|
|
1200
Description:
(Description Provided by CVE) : Visual Casel (Vcasel) does not properly prevent users from executing files, which allows local users to use a relative pathname to specify an alternate file which has an approved name and possibly gain privileges.
|
2000-01-18
|
VCasel Filename Trusting
|
|
1139
Description:
(Description Provided by CVE) : Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.
|
2000-01-17
|
Microsoft Rich Text Format (RTF) Reader Malformed Control Word Overflow
|
|
7584
Description:
(Description Provided by CVE) : Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request.
|
2000-01-17
|
InetServ GET Overflow Arbitrary Command Execution
|
|
1201
Description:
(Description Provided by CVE) : cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to cause a denial of service via a malformed URL that includes shell metacharacters.
|
2000-01-17
|
Nortel Contivity HTTP Server cgiproc Special Character DoS
|
|
1205
Description:
VMware for Linux contains a flaw that may allow a malicious user to overwrite arbitrary files. The problem is that VMware creates certain files in the "/tmp" directory on startup, but doesn't check the existence and ownership of the files. It is possible that the flaw may allow a malicious user to create a symlink from a malicious file, which could be overwritten when the application is executed resulting in a loss of integrity.
|
2000-01-17
|
VMware Symlink Arbitrary File Overwrite
|
|
6865
Description:
Yahoo! Messenger contains a flaw that may allow a remote denial of service. The issue is triggered when a text message is sent containing an overly long URL occurs, and will result in loss of availability for the service.
|
2000-01-17
|
Yahoo! Pager/Messenger Long URL Overflow
|
|
7583
Description:
Nortel Contivity's HTTP server contains a flaw that may allow a malicious user to view arbitrary files due a lack of authentication. The issue is triggered when a file known to be on the server is specified using the Nocfile argument in the cgiproc script. The cgiproc script fails to authenticate the attacker therefore allowing the attacker read access to the file resulting in a loss of confidentiality.
|
2000-01-17
|
Nortel Contivity HTTP Server cgiproc Arbitrary File Access
|
|
59293
Description:
(Description Provided by CVE) : Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.
|
2000-01-16
|
Netopia Timbuktu Pro Cleartext Password Remote Disclosure
|
|
1207
Description:
(Description Provided by CVE) : The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program.
|
2000-01-15
|
Microsoft SMS Remote Control Weak Permission Privilege Escalation
|
|
5859
Description:
(Description Provided by CVE) : Progressive Networks Real Video server (pnserver) can be crashed remotely.
|
2000-01-15
|
Real Video Server (pnserver) Malformed Telnet Data Remote Overflow
|
|
56508
Description:
Unknown / Incomplete
|
2000-01-14
|
E-mail Sanitizer for Procmail Unspecified Quoted Strings Remote DoS
|
|
1728
Description:
(Description Provided by CVE) : Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable.
|
2000-01-14
|
Iomega JaZip DISPLAY Environment Variable Local Overflow
|
|
1199
Description:
(Description Provided by CVE) : NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC Port Request."
|
2000-01-13
|
Microsoft Windows NT NtImpersonateClientOfPort LPC Privilege Escalation
|