| OSVDB ID | Disclosure Date | Title |
|
12141
Description:
(Description Provided by CVE) : quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request.
|
2000-11-20
|
QuikStore Shopping Cart quikstore.cgi category Parameter Arbitrary Command Execution
|
|
1660
Description:
(Description Provided by CVE) : elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack.
|
2000-11-20
|
elvis-tiny Symlink Arbitrary File Overwrite
|
|
7823
Description:
Microsoft Internet Explorer contains a flaw that may allow a remote attacker to execute arbitrary commands. Internet Explorer allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.
|
2000-11-20
|
Microsoft IE Cached Content .chm Arbitrary Program Execution
|
|
12209
Description:
(Description Provided by CVE) : The installation of AdCycle banner management system leaves the build.cgi program in a web-accessible directory, which allows remote attackers to execute the program and view passwords or delete databases.
|
2000-11-20
|
AdCycle build.cgi Remote Password Disclosure
|
|
60896
Description:
Unknown / Incomplete
|
2000-11-20
|
HP-UX pppd Local Overflow
|
|
1654
Description:
Multiple buffer overflows in AFS ACL parser for Ethereal 0.8.13 and earlier allows remote attackers to execute arbitrary commands via a packet with a long username.
|
2000-11-18
|
Ethereal AFS ACL Packet Parsing Overflow
|
|
452
Description:
(Description Provided by CVE) : WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to read and modify sensitive information such as passwords and gain access to the system.
|
2000-11-18
|
WinVNC Registry Key Permission Weakness Local Privilege Escalation
|
|
85828
Description:
NetcPlus SmartServer and BrowseGate contain a flaw that is triggered by the applications storing user credential information in the dialsrv.ini file, which is accessible by all windows authenticated users. This may make it easier for an attacker to gain access to a user's password information.
|
2000-11-18
|
NetcPlus Multiple Product dialsrv.ini User Password Encoding Weakness
|
|
60675
Description:
Unknown / Incomplete
|
2000-11-17
|
Slackware Linux /usr/bin/ppp-off Insecure /tmp File Access
|
|
60676
Description:
Unknown / Incomplete
|
2000-11-17
|
xsplumber strcopy() Local Overflow
|
|
60868
Description:
ListMail contains a flaw that may allow an attacker to execute arbitrary commands. The issue is caused by an insecure call within the lmail.pl script.
|
2000-11-17
|
ListMail lmail.pl Insecure Call Command Execution
|
|
60895
Description:
Unknown / Incomplete
|
2000-11-17
|
Mailing List & News maillist.cgi Remote Command Execution
|
|
61291
Description:
Unknown / Incomplete
|
2000-11-16
|
ModLogAn gzprintf Block Handling Buffer Overflow
|
|
1646
Description:
DCForum contains a flaw that allows a remote attacker to view any arbitrary file on the web server. The issue is due to a lack of sanity checking on the "$r_in" variable in the dcboard.cgi and dcadmin.cgi scripts. Further, if an attacker attempts to view the source code of the dcforum.cgi script, it deletes itself.
|
2000-11-16
|
DCForum dcboard.cgi forum Variable Arbitrary File Disclosure
|
|
453
Description:
(Description Provided by CVE) : Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including sensitive information, by accessing the /admin/includes/ URL.
|
2000-11-16
|
RealServer /admin/includes/ Remote Memory Content Disclosure
|
|
1647
Description:
(Description Provided by CVE) : Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control characters.
|
2000-11-16
|
Netopia 650-T ISDN Router Credentials Disclosure
|
|
1648
Description:
WatchGuard Firebox II contains a flaw that may allow a remote denial of service. The issue is triggered when a remote attacker floods the server with FTP or SMTP requests, disabling subsequent proxy handling.
|
2000-11-16
|
WatchGuard Firebox II FTP/SMTP Proxy DoS
|
|
1650
Description:
By default, Exchange creates a user account with a default password. The EUSR_EXSTOREEVENT account has a password of xyxx1x#y which is publicly known and documented. This allows attackers to trivially access the program or system.
|
2000-11-16
|
Microsoft Exchange Server EUSR_EXSTOREEVENT Default Account
|
|
1651
Description:
(Description Provided by CVE) : Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an abnormal exit, which allows local users to overwrite the files of other users whose joe session crashes.
|
2000-11-16
|
Joe's Own Editor (joe) DEADJOE Symbolic Link Arbitrary File Overwrite
|
|
1652
Description:
(Description Provided by CVE) : crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.
|
2000-11-16
|
Vixie Cron /var/spool/cron Temporary Crontab File
|
|
60674
Description:
Unknown / Incomplete
|
2000-11-16
|
HalfLife Linux Server rcon Format String
|
|
88541
Description:
International Components for Unicode for Java (ICU4J) contains a flaw related to the TimeZone.java file. While a cursory review of the code commit does not suggest a security fix, the note with this specifically indicates it fixes a security bug. No further details are available.
|
2000-11-16
|
International Components for Unicode for Java (ICU4J) TimeZone.java Unspecified Issue
|
|
1649
Description:
(Description Provided by CVE) : Buffer overflow in Netsnap webcam HTTP server before 1.2.9 allows remote attackers to execute arbitrary commands via a long GET request.
|
2000-11-15
|
PeleSoft NetSnap Web Server GET Request Overflow
|
|
3672
Description:
AnalogX Proxy contains a flaw that allows a remote attacker to crash the service. The issue is due to poor sanity checking of user supplied input to the FTP, SMTP or POP3 services. If an attacker sends "multiple abnormal strings" to these services, it can crash the entire proxy service.
|
2000-11-15
|
AnalogX Proxy Multiple Service DoS
|
|
6759
Description:
(Description Provided by CVE) : Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a long MIME header.
|
2000-11-15
|
phf CGI MIME Header Remote Overflow
|
|
12221
Description:
(Description Provided by CVE) : Buffer overflow in socks5 server on Linux allows attackers to execute arbitrary commands via a long connection request.
|
2000-11-15
|
socks5 Server Long Connection Request Overflow
|
|
60673
Description:
Unknown / Incomplete
|
2000-11-15
|
gnomehack Unspecified Local Overflow
|
|
11940
Description:
Unknown / Incomplete
|
2000-11-14
|
Microsoft Outlook Blocked Attachment Access
|
|
1643
Description:
(Description Provided by CVE) : Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is completed.
|
2000-11-14
|
Small HTTP Server Nonexistent File Request DoS
|
|
1655
Description:
FreeBSD contains a flaw that may allow a malicious user to bypass the nat gateway. The issue was triggered because code was added to permit certain types of data through the nat gateway. It is possible that the flaw may allow all traffic to pass through, despite the "deny_incoming" directive, resulting in a loss of integrity.
|
2000-11-14
|
FreeBSD ppp deny_incoming Restriction Remote Bypass
|
|
10883
Description:
(Description Provided by CVE) : RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.
|
2000-11-14
|
RobinHood RHConsole HTTP Request Overflow Remote DoS
|
|
703
Description:
Unknown / Incomplete
|
2000-11-14
|
SilverStream Unspecified Default Account
|
|
4731
Description:
Unknown / Incomplete
|
2000-11-14
|
InoculateIT Embedded Message Virus Check Bypass
|
|
4732
Description:
Unknown / Incomplete
|
2000-11-14
|
InoculateIT Blank Message Body Virus Check Bypass
|
|
4734
Description:
(Description Provided by CVE) : AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox.
|
2000-11-14
|
InoculateIT Microsoft Exchange Inbox Folder Tree Moved Message Scanning Bypass
|
|
6083
Description:
FreeBSD contains a flaw that may allow a remote denial of service. The issue is triggered when a malicious user submits a request for an arbitrary large file in the TERMCAP environment variable to telnetd, which consumes cpu resources as the server processes the request, and will result in loss of availability for the platform.
|
2000-11-14
|
FreeBSD telnetd TERMCAP Environment Variable DoS
|
|
10890
Description:
(Description Provided by CVE) : RHDaemon in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.
|
2000-11-14
|
RobinHood RHDaemon Long HTTP Request DoS
|
|
11635
Description:
(Description Provided by CVE) : Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file.
|
2000-11-14
|
Small HTTP Server Null SSI Tag DoS
|
|
11636
Description:
(Description Provided by CVE) : Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests.
|
2000-11-14
|
Small HTTP Server Multiple Incomplete Request DoS
|
|
17113
Description:
Unknown / Incomplete
|
2000-11-14
|
SilverStream Multiple Script Information Disclosure
|