| OSVDB ID | Disclosure Date | Title |
|
1744
Description:
WU-FTPD contains a flaw that may allow a remote attacker to execute arbitrary code. The issue occurs when the service runs in 'debug' mode and an attacker has control over ident information being returned to the server. By manipulating the ident data returned to the host when requested by RFC 931 based authentication, an attacker can provide custom data with user-supplied format string identifiers that are passed to the syslog facility. This can be abused to overwrite portions of the system memory and execute arbitrary code.
|
2001-01-23
|
WU-FTPD Debug Mode Client Hostname Remote Format String
|
|
22197
Description:
(Description Provided by CVE) : WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.
|
2001-01-23
|
WinVNC Multiple Connection Persistent Challenge String Authentication Bypass
|
|
1742
Description:
(Description Provided by CVE) : Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router's telnet program to connect to the router's IP address, which causes a crash.
|
2001-01-23
|
Netopia R9100 Router DoS
|
|
3321
Description:
A remote overflow exists in Lotus Domino ESMTP Service. The relay policy check fails to limit the length of the incoming domain name resulting in a buffer overflow. With a specially crafted request, an attacker can cause a Notes server crash and possible execution of arbitrary code resulting in a loss of available and possibly integrity.
|
2001-01-23
|
IBM Lotus Domino SMTP Policy Overflow
|
|
5845
Description:
(Description Provided by CVE) : Vulnerability in crontab allows local users to read crontab files of other users by replacing the temporary file that is being edited while crontab is running.
|
2001-01-23
|
crontab Arbitrary User Crontab File Access
|
|
7171
Description:
(Description Provided by CVE) : sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.
|
2001-01-23
|
Debian sash /etc/shadow Content Disclosure
|
|
7174
Description:
(Description Provided by CVE) : kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
|
2001-01-23
|
KDE2 kdesu Insecure Socket Password Disclosure
|
|
7202
Description:
(Description Provided by CVE) : Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.
|
2001-01-23
|
Microsoft PowerPoint 2000 File Loader Overflow
|
|
10893
Description:
(Description Provided by CVE) : Buffer overflow in Easycom/Safecom Print Server Web service, version 404.590 and earlier, allows remote attackers to execute arbitrary commands via (1) a long URL or (2) a long HTTP header field such as "Host:".
|
2001-01-23
|
Easycom/Safecom Print Server Web Service HTTP Request Overflow
|
|
13839
Description:
(Description Provided by CVE) : The Easycom/Safecom Print Server (firmware 404.590) PrintGuide server allows remote attackers to cause a denial of service via a large number of connections that send null characters.
|
2001-01-23
|
Easycom/Safecom Print Server Malformed Connection Saturation DoS
|
|
79045
Description:
Unknown / Incomplete
|
2001-01-23
|
Webmin /tmp Insecure File Permission Weakness
|
|
496
Description:
(Description Provided by CVE) : Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.
|
2001-01-22
|
Icecast utils.c fd_write Function Format String
|
|
1737
Description:
(Description Provided by CVE) : The caching module in Netscape Fasttrack Server 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by requesting a large number of non-existent URLs.
|
2001-01-22
|
Netscape FastTrak Cache Module DoS
|
|
1739
Description:
(Description Provided by CVE) : iPlanet (formerly Netscape) Enterprise Server 4.1 allows remote attackers to cause a denial of service via a long HTTP GET request that contains many "/../" (dot dot) sequences.
|
2001-01-22
|
Netscape Enterprise Server Long Traversal Request Remote DoS
|
|
1741
Description:
(Description Provided by CVE) : Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack.
|
2001-01-22
|
Oracle JSP Traversal Arbitrary .jsp File Execution
|
|
6626
Description:
(Description Provided by CVE) : Directory traversal vulnerability in Allaire JRun 2.3 server allows remote attackers to read arbitrary files via the SSIFilter servlet.
|
2001-01-22
|
Allaire JRun SSIFilter Arbitrary File Retrieval
|
|
6983
Description:
Half Life Dedicated Server contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when a malicious user injects format strings into the changelevel command via the system console or rcon. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
2001-01-22
|
Half Life Server Format String Command Execution
|
|
6985
Description:
(Description Provided by CVE) : pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by specifying the same value to the entered_password and admin_password parameters.
|
2001-01-22
|
Poll It pollit.cgi Administration Authentication Bypass
|
|
6986
Description:
(Description Provided by CVE) : pollit.cgi in Poll It 2.01 and earlier uses data files that are located under the web document root, which allows remote attackers to access sensitive or private information.
|
2001-01-22
|
Poll It pollit.cgi Remote Data File Exposure
|
|
6987
Description:
(Description Provided by CVE) : pollit.cgi in Poll It 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the poll_options parameter.
|
2001-01-22
|
Poll It pollit.cgi Command Execution
|
|
7010
Description:
A remote overflow exists in ypserv. The server fails to properly check bounds resulting in an overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2001-01-22
|
ypserv Missing vsyslog Overflow
|
|
13803
Description:
(Description Provided by CVE) : GoodTech FTP server 3.0.1.2.1.0 and earlier allows remote attackers to cause a denial of service via a flood of connections to the server, which causes it to crash.
|
2001-01-22
|
GoodTech FTP Server Connection Saturation DoS
|
|
44617
Description:
(Description Provided by CVE) : Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack.
|
2001-01-22
|
Oracle JSP Crafted .jsp Traversal Arbitrary File Disclosure
|
|
1731
Description:
(Description Provided by CVE) : When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
|
2001-01-21
|
GNU C Library (glibc) LD_PRELOAD Arbitrary File Overwrite
|
|
13124
Description:
(Description Provided by CVE) : eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user views the packet.
|
2001-01-21
|
eEye Iris Malformed TCP Packet Handling Remote DoS
|
|
1740
Description:
Watchguard Firebox II firewall allows users with read-only access to gain read-write access, and administrative privileges, by accessing a file that contains hashed passphrases, and using the hashes during authentication.
|
2001-01-20
|
WatchGuard Firebox II Hashed Passphrase Disclosure Local Privilege Escalation
|
|
825
Description:
LocalWEB2000 contains a flaw that allows a remote attacker to read files outside of the web path. The issue is due to the program not properly sanitizing user input, specifically traversal style attacks (../../) supplied via URL requests.
|
2001-01-19
|
LocalWEB2000 Directory Traversal Arbitrary File Access
|
|
1875
Description:
(Description Provided by CVE) : Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine.
|
2001-01-19
|
lpd Transfer Job Routine Remote Buffer Overflow
|
|
12103
Description:
Fastream FTP++ Server contains a flaw that may lead to unauthorized file access. The issue is triggered when a remote attacker uses "ls" command and includes the drive letter in the requested path name, which will allow a remote attacker to list directories outside of the Faststream FTP++ Server directory, resulting in a loss of confidentiality.
|
2001-01-19
|
Fastream FTP++ Server Malformed ls Command Arbitrary Directory Listing
|
|
1738
Description:
(Description Provided by CVE) : Buffer overflow in bing allows remote attackers to execute arbitrary commands via a long hostname, which is copied to a small buffer after a reverse DNS lookup using the gethostbyaddr function.
|
2001-01-19
|
bing gethostbyaddr Buffer Overflow
|
|
12104
Description:
(Description Provided by CVE) : FaSTream FTP++ Server 2.0 allows remote attackers to obtain the real pathname of the server via the "pwd" command.
|
2001-01-19
|
Fastream FTP++ Server pwd Command Path Disclosure
|
|
59509
Description:
(Description Provided by CVE) : Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.
|
2001-01-19
|
Microsoft Windows 2000 Encrypted File System Cleartext Backup File Local Disclosure
|
|
18234
Description:
(Description Provided by CVE) : SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.
|
2001-01-18
|
SSH RC4 User Session Replay Password Portion Enumeration
|
|
18235
Description:
(Description Provided by CVE) : SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is generated.
|
2001-01-18
|
SSH RC4 with Password Authentication Message Reply Forced Server Key Generation
|
|
18231
Description:
(Description Provided by CVE) : SSH before 2.0 disables host key checking when connecting to the localhost, which allows remote attackers to silently redirect connections to the localhost by poisoning the client's DNS cache.
|
2001-01-18
|
SSH localhost Connection Host Key Check Bypass
|
|
18232
Description:
(Description Provided by CVE) : The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target.
|
2001-01-18
|
SSH-1 Protocol Duplicate Session ID Client Challenge Response Replay
|
|
18229
Description:
(Description Provided by CVE) : The IDEA cipher as implemented by SSH1 does not protect the final block of a message against modification, which allows remote attackers to modify the block without detection by changing its cyclic redundancy check (CRC) to match the modifications to the message.
|
2001-01-18
|
SSH-1 Protocol IDEA Cipher Final Block CRC Modification
|
|
18230
Description:
(Description Provided by CVE) : The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message's cyclic redundancy check (CRC) with the CRC of a mask consisting of all the bits of the original message that were modified.
|
2001-01-18
|
SSH-1 Protocol RC4 Stream Cipher CRC XOR Arbitrary Packet Modification
|
|
19131
Description:
(Description Provided by CVE) : Dallas Semiconductor iButton DS1991 returns predictable values when given an incorrect password, which makes it easier for users with physical access to conduct dictionary attacks against the device password.
|
2001-01-18
|
iButton DS1991 Error Message Password Brute Force Weakness
|
|
9907
Description:
(Description Provided by CVE) : Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.
|
2001-01-18
|
MySQL SELECT Statement String Handling Overflow
|