|
Name: CVE-1999-0002
Description:
Buffer overflow in NFS mountd gives root access to
remote attackers, mostly in Linux systems. Status:
Entry
Reference: SGI:19981006-01-I
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/19981006-01-I
Reference: CERT:CA-98.12.mountd
Reference: CIAC:J-006
Reference: URL:http://www.ciac.org/ciac/bulletins/j-006.shtml
Reference: BID:121
Reference: URL:http://www.securityfocus.com/bid/121
Reference: XF:linux-mountd-bo
Name: CVE-1999-0003
Description:
Execute commands as root via buffer overflow in Tooltalk
database server (rpc.ttdbserverd). Status: Entry
Reference: NAI:NAI-29
Reference: CERT:CA-98.11.tooltalk
Reference: SGI:19981101-01-A
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19981101-01-A
Reference: SGI:19981101-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19981101-01-PX
Reference: XF:aix-ttdbserver
Reference: XF:tooltalk
Reference: BID:122
Reference:
URL:http://www.securityfocus.com/bid/122
Name: CVE-1999-0005
Description:
Arbitrary command execution via IMAP buffer overflow in
authenticate command. Status: Entry
Reference: CERT:CA-98.09.imapd
Reference: SUN:00177
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/177
Reference: BID:130
Reference:
URL:http://www.securityfocus.com/bid/130
Reference: XF:imap-authenticate-bo
Name: CVE-1999-0006
Description:
Buffer overflow in POP servers based on BSD/Qualcomm's
qpopper allows remote attackers to gain root access
using a long PASS command. Status: Entry
Reference: CERT:CA-98.08.qpopper_vul
Reference: SGI:19980801-01-I
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I
Reference: AUSCERT:AA-98.01
Reference: XF:qpopper-pass-overflow
Reference: BID:133
Reference:
URL:http://www.securityfocus.com/bid/133
Name: CVE-1999-0007
Description:
Information from SSL-encrypted sessions via PKCS #1.
Status: Entry
Reference: CERT:CA-98.07.PKCS
Reference: MS:MS98-002
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms98-002.mspx
Reference: XF:nt-ssl-fix
Name: CVE-1999-0008
Description:
Buffer overflow in NIS+, in Sun's rpc.nisd program.
Status: Entry
Reference: CERT:CA-98.06.nisd
Reference: SUN:00170
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/170
Reference: ISS:June10,1998
Reference: XF:nisd-bo-check
Name: CVE-1999-0009
Description:
Inverse query buffer overflow in BIND 4.9 and BIND 8
Releases. Status: Entry
Reference: SGI:19980603-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX
Reference: HP:HPSBUX9808-083
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083
Reference: SUN:00180
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/180
Reference: CERT:CA-98.05.bind_problems
Reference: XF:bind-bo
Reference: BID:134
Reference:
URL:http://www.securityfocus.com/bid/134
Name: CVE-1999-0010
Description:
Denial of Service vulnerability in BIND 8 Releases via
maliciously formatted DNS messages. Status: Entry
Reference: CERT:CA-98.05.bind_problems
Reference: SGI:19980603-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX
Reference: HP:HPSBUX9808-083
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083
Reference: XF:bind-dos
Name: CVE-1999-0011
Description:
Denial of Service vulnerabilities in BIND 4.9 and BIND 8
Releases via CNAME record and zone transfer. Status:
Entry
Reference: CERT:CA-98.05.bind_problems
Reference: SGI:19980603-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX
Reference: HP:HPSBUX9808-083
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083
Reference: SUN:00180
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/180
Reference: XF:bind-axfr-dos
Name: CVE-1999-0012
Description:
Some web servers under Microsoft Windows allow remote
attackers to bypass access restrictions for files with
long file names. Status: Entry
Reference: CERT:CA-98.04.Win32.WebServers
Reference: XF:nt-web8.3
Name: CVE-1999-0013
Description:
Stolen credentials from SSH clients via ssh-agent
program, allowing other local users to access remote
accounts belonging to the ssh-agent user. Status:
Entry
Reference: CERT:CA-98.03.ssh-agent
Reference: NAI:NAI-24
Reference: XF:ssh-agent
Name: CVE-1999-0014
Description:
Unauthorized privileged access or denial of service via
dtappgather program in CDE. Status: Entry
Reference: HP:HPSBUX9801-075
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-075
Reference: SUN:00185
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/185
Reference: CERT:CA-98.02.CDE
Name: CVE-1999-0016
Description:
Land IP denial of service. Status: Entry
Reference: CERT:CA-97.28.Teardrop_Land
Reference: FREEBSD:FreeBSD-SA-98:01
Reference: HP:HPSBUX9801-076
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-076
Reference:
CISCO:http://www.cisco.com/warp/public/770/land-pub.shtml
Reference: XF:cisco-land
Reference: XF:land
Reference: XF:95-verv-tcp
Reference: XF:land-patch
Reference: XF:ver-tcpip-sys
Name: CVE-1999-0017
Description:
FTP servers can allow an attacker to connect to
arbitrary ports on machines other than the FTP client,
aka FTP bounce. Status: Entry
Reference: CERT:CA-97.27.FTP_bounce
Reference: XF:ftp-bounce
Reference: XF:ftp-privileged-port
Name: CVE-1999-0018
Description:
Buffer overflow in statd allows root privileges.
Status: Entry
Reference: CERT:CA-97.26.statd
Reference: AUSCERT:AA-97.29
Reference: XF:statd
Reference: BID:127
Reference:
URL:http://www.securityfocus.com/bid/127
Name: CVE-1999-0019
Description:
Delete or create a file via rpc.statd, due to invalid
information. Status: Entry
Reference: CERT:CA-96.09.rpc.statd
Reference: XF:rpc-stat
Reference: SUN:00135
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/135
Name: CVE-1999-0021
Description:
Arbitrary command execution via buffer overflow in
Count.cgi (wwwcount) cgi-bin program. Status:
Entry
Reference: BUGTRAQ:19971010 Security flaw in
Count.cgi (wwwcount)
Reference: CERT:CA-97.24.Count_cgi
Reference: XF:http-cgi-count
Reference: BID:128
Reference:
URL:http://www.securityfocus.com/bid/128
Name: CVE-1999-0022
Description:
Local user gains root privileges via buffer overflow in
rdist, via expstr() function. Status: Entry
Reference: CERT:CA-97.23.rdist
Reference: SUN:00179
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/179
Reference: XF:rdist-bo3
Reference: XF:rdist-sept97
Name: CVE-1999-0023
Description:
Local user gains root privileges via buffer overflow in
rdist, via lookup() function. Status: Entry
Reference: CERT:CA-96.14.rdist_vul
Reference: XF:rdist-bo
Reference: XF:rdist-bo2
Name: CVE-1999-0024
Description:
DNS cache poisoning via BIND, by predictable query IDs.
Status: Entry
Reference: CERT:CA-97.22.bind
Reference: XF:bind
Reference: NAI:NAI-11
Name: CVE-1999-0025
Description:
root privileges via buffer overflow in df command on SGI
IRIX systems. Status: Entry
Reference: CERT:CA-1997-21
Reference:
URL:http://www.cert.org/advisories/CA-1997-21.html
Reference:
AUSCERT:AA-97.19.IRIX.df.buffer.overflow.vul
Reference: SGI:SGI:19970505-01-A
Reference: SGI:SGI:19970505-02-PX
Reference: CERT-VN:VU#20851
Reference:
URL:http://www.kb.cert.org/vuls/id/20851
Reference: BID:346
Reference:
URL:http://www.securityfocus.com/bid/346
Reference: XF:df-bo(440)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/440
Name: CVE-1999-0026
Description:
root privileges via buffer overflow in pset command on
SGI IRIX systems. Status: Entry
Reference: CERT:CA-97.21.sgi_buffer_overflow
Reference:
AUSCERT:AA-97.20.IRIX.pset.buffer.overflow.vul
Reference: XF:pset-bo
Name: CVE-1999-0027
Description:
root privileges via buffer overflow in eject command on
SGI IRIX systems. Status: Entry
Reference: CERT:CA-97.21.sgi_buffer_overflow
Reference:
AUSCERT:AA-97.21.IRIX.eject.buffer.overflow.vul
Reference: XF:eject-bo
Name: CVE-1999-0028
Description:
root privileges via buffer overflow in login/scheme
command on SGI IRIX systems. Status: Entry
Reference: CERT:CA-97.21.sgi_buffer_overflow
Reference:
AUSCERT:AA-97.22.IRIX.login.scheme.buffer.overflow.vul
Reference: XF:sgi-schemebo
Name: CVE-1999-0029
Description:
root privileges via buffer overflow in ordist command on
SGI IRIX systems. Status: Entry
Reference: CERT:CA-97.21.sgi_buffer_overflow
Reference:
AUSCERT:AA-97.23-IRIX.ordist.buffer.overflow.vul
Reference: XF:ordist-bo
Name: CVE-1999-0031
Description:
JavaScript in Internet Explorer 3.x and 4.x, and
Netscape 2.x, 3.x and 4.x, allows remote attackers to
monitor a user's web activities, aka the Bell Labs
vulnerability. Status: Entry
Reference: CERT:CA-97.20.javascript
Reference: HP:HPSBUX9707-065
Reference:
URL:http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html
Name: CVE-1999-0032
Description:
Buffer overflow in lpr, as used in BSD-based systems
including Linux, allows local users to execute arbitrary
code as root via a long -C (classification) command line
option. Status: Entry
Reference: BUGTRAQ:19960813 Possible
bufferoverflow condition in lpr, xterm and xload
Reference: BUGTRAQ:19961025 Linux & BSD's lpr
exploit
Reference: MLIST:[freebsd-security] 19961025
Vadim Kolontsov: BoS: Linux & BSD's lpr exploit
Reference: MLIST:[linux-security] 19961122 LSF
Update#14: Vulnerability of the lpr program.
Reference: CERT:CA-97.19.bsdlp
Reference: AUSCERT:AA-96.12
Reference: CIAC:H-08
Reference: CIAC:I-042
Reference:
URL:http://www.ciac.org/ciac/bulletins/i-042.shtml
Reference: SGI:19980402-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX
Reference: BID:707
Reference:
URL:http://www.securityfocus.com/bid/707
Reference: XF:bsd-lprbo2
Reference: XF:bsd-lprbo
Reference: XF:lpr-bo
Name: CVE-1999-0034
Description:
Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.
Status: Entry
Reference: CERT:CA-97.17.sperl
Reference: XF:perl-suid
Name: CVE-1999-0035
Description:
Race condition in signal handling routine in ftpd,
allowing read/write arbitrary files. Status:
Entry
Reference: XF:ftp-ftpd
Reference: CERT:CA-97.16.ftpd
Reference: AUSCERT:AA-97.03
Name: CVE-1999-0036
Description:
IRIX login program with a nonzero LOCKOUT parameter
allows creation or damage to files. Status: Entry
Reference: CERT:CA-97.15.sgi_login
Reference: AUSCERT:AA-97.12
Reference: CIAC:H-106
Reference:
URL:http://www.ciac.org/ciac/bulletins/h-106.shtml
Reference: SGI:19970508-02-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX
Reference: OSVDB:990
Reference: URL:http://www.osvdb.org/990
Reference: XF:sgi-lockout(557)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/557
Name: CVE-1999-0037
Description:
Arbitrary command execution via metamail package using
message headers, when user processes attacker's message
using metamail. Status: Entry
Reference: CERT:CA-97.14.metamail
Reference: XF:metamail-header-commands
Name: CVE-1999-0038
Description:
Buffer overflow in xlock program allows local users to
execute commands as root. Status: Entry
Reference: CERT:CA-97.13.xlock
Reference: XF:xlock-bo
Name: CVE-1999-0039
Description:
webdist CGI program (webdist.cgi) in SGI IRIX allows
remote attackers to execute arbitrary commands via shell
metacharacters in the distloc parameter. Status:
Entry
Reference: BUGTRAQ:19970507 Re: SGI Security
Advisory 19970501-01-A - Vulnerability in
Reference: BUGTRAQ:19970507 Re: SGI Advisory:
webdist.cgi
Reference: CERT:CA-1997-12
Reference:
URL:http://www.cert.org/advisories/CA-1997-12.html
Reference: AUSCERT:AA-97.14
Reference: SGI:19970501-02-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX
Reference: BID:374
Reference:
URL:http://www.securityfocus.com/bid/374
Reference: OSVDB:235
Reference: URL:http://www.osvdb.org/235
Reference: XF:http-sgi-webdist(333)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/333
Name: CVE-1999-0040
Description:
Buffer overflow in Xt library of X Windowing System
allows local users to execute commands with root
privileges. Status: Entry
Reference: CERT:CA-97.11.libXt
Reference: XF:libXt-bo
Name: CVE-1999-0041
Description:
Buffer overflow in NLS (Natural Language Service).
Status: Entry
Reference: CERT:CA-97.10.nls
Reference: XF:nls-bo
Name: CVE-1999-0042
Description:
Buffer overflow in University of Washington's
implementation of IMAP and POP servers. Status:
Entry
Reference: NAI:NAI-21
Reference: CERT:CA-97.09.imap_pop
Reference: XF:popimap-bo
Name: CVE-1999-0043
Description:
Command execution via shell metachars in INN daemon
(innd) 1.5 using "newgroup" and "rmgroup" control
messages, and others. Status: Entry
Reference: CERT:CA-97.08.innd
Reference: XF:inn-controlmsg
Name: CVE-1999-0044
Description:
fsdump command in IRIX allows local users to obtain root
access by modifying sensitive files. Status:
Entry
Reference: SGI:19970301-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19970301-01-P
Reference: XF:sgi-fsdump
Name: CVE-1999-0045
Description:
List of arbitrary files on Web host via nph-test-cgi
script. Status: Entry
Reference: CERT:CA-97.07.nph-test-cgi_script
Reference: XF:http-cgi-nph
Name: CVE-1999-0046
Description:
Buffer overflow of rlogin program using TERM
environmental variable. Status: Entry
Reference: CERT:CA-97.06.rlogin-term
Reference: XF:rlogin-termbo
Name: CVE-1999-0047
Description:
MIME conversion buffer overflow in sendmail versions
8.8.3 and 8.8.4. Status: Entry
Reference: CERT:CA-97.05.sendmail
Reference: BID:685
Reference:
URL:http://www.securityfocus.com/bid/685
Reference: XF:sendmail-mime-bo2
Name: CVE-1999-0048
Description:
Talkd, when given corrupt DNS information, can be used
to execute arbitrary commands with root privileges.
Status: Entry
Reference: CERT:CA-97.04.talkd
Reference: FREEBSD:FreeBSD-SA-96:21
Reference: AUSCERT:AA-97.01
Reference: SUN:00147
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/147
Reference: XF:talkd-bo
Reference: XF:netkit-talkd
Name: CVE-1999-0049
Description:
Csetup under IRIX allows arbitrary file creation or
overwriting. Status: Entry
Reference: XF:sgi-csetup
Reference: CERT:CA-97.03.csetup
Name: CVE-1999-0050
Description:
Buffer overflow in HP-UX newgrp program. Status:
Entry
Reference: CERT:CA-97.02.hp_newgrp
Reference:
AUSCERT:AA-96.16.HP-UX.newgrp.Buffer.Overrun.Vulnerability
Reference: XF:hp-newgrpbo
Name: CVE-1999-0051
Description:
Arbitrary file creation and program execution using
FLEXlm LicenseManager, from versions 4.0 to 5.0, in
IRIX. Status: Entry
Reference: XF:sgi-licensemanager
Reference: CERT:CA-97.01.flex_lm
Reference: AUSCERT:AA-96.03
Name: CVE-1999-0052
Description:
IP fragmentation denial of service in FreeBSD allows a
remote attacker to cause a crash. Status: Entry
Reference: FREEBSD:FreeBSD-SA-98:08
Reference: OSVDB:908
Reference: URL:http://www.osvdb.org/908
Reference: XF:freebsd-ip-frag-dos(1389)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/1389
Name: CVE-1999-0053
Description:
TCP RST denial of service in FreeBSD. Status:
Entry
Reference: FREEBSD:FreeBSD-SA-98:07
Reference: OSVDB:6094
Reference: URL:http://www.osvdb.org/6094
Name: CVE-1999-0054
Description:
Sun's ftpd daemon can be subjected to a denial of
service. Status: Entry
Reference: SUN:00171
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/171
Reference: XF:sun-ftpd
Name: CVE-1999-0055
Description:
Buffer overflows in Sun libnsl allow root access.
Status: Entry
Reference: SUN:00172
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/172
Reference: AIXAPAR:IX80543
Reference:
URL:http://www-1.ibm.com/support/search.wss?rs=0&q=IX80543&apar=only
Reference: RSI:RSI.0005.05-14-98.SUN.LIBNSL
Reference: XF:sun-libnsl
Name: CVE-1999-0056
Description:
Buffer overflow in Sun's ping program can give root
access to local users. Status: Entry
Reference: SUN:00174
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/174
Reference: XF:sun-ping
Name: CVE-1999-0057
Description:
Vacation program allows command execution by remote
users through a sendmail command. Status: Entry
Reference: NAI:NAI-19
Reference: XF:vacation
Reference: HP:HPSBUX9811-087
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9811-087
Name: CVE-1999-0058
Description:
Buffer overflow in PHP cgi program, php.cgi allows shell
access. Status: Entry
Reference: NAI:NAI-12
Reference: BID:712
Reference:
URL:http://www.securityfocus.com/bid/712
Reference: XF:http-cgi-phpbo
Name: CVE-1999-0059
Description:
IRIX fam service allows an attacker to obtain a list of
all files on the server. Status: Entry
Reference: NAI:NAI-16
Reference: BID:353
Reference:
URL:http://www.securityfocus.com/bid/353
Reference: OSVDB:164
Reference: URL:http://www.osvdb.org/164
Reference: XF:irix-fam(325)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/325
Name: CVE-1999-0060
Description:
Attackers can cause a denial of service in Ascend MAX
and Pipeline routers with a malformed packet to the
discard port, which is used by the Java Configurator
tool. Status: Entry
Reference: NAI:NAI-26
Reference: XF:ascend-config-kill
Reference: ASCEND:http://www.ascend.com/2695.html
Name: CVE-1999-0062
Description:
The chpass command in OpenBSD allows a local user to
gain root access through file descriptor leakage.
Status: Entry
Reference: XF:openbsd-chpass
Reference: NAI:NAI-28
Reference: OSVDB:7559
Reference: URL:http://www.osvdb.org/7559
Name: CVE-1999-0063
Description:
Cisco IOS 12.0 and other versions can be crashed by
malicious UDP packets to the syslog port. Status:
Entry
Reference: AUSCERT:ESB-98.197
Reference:
CISCO:http://www.cisco.com/warp/public/770/iossyslog-pub.shtml
Reference: XF:cisco-syslog-crash
Name: CVE-1999-0064
Description:
Buffer overflow in AIX lquerylv program gives root
access to local users. Status: Entry
Reference: BUGTRAQ:May28,1997
Reference: XF:lquerylv-bo
Name: CVE-1999-0065
Description:
Multiple buffer overflows in how dtmail handles
attachments allows a remote attacker to execute
commands. Status: Entry
Reference: SUN:00181
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/181
Reference: XF:hp-dtmail
Name: CVE-1999-0066
Description:
AnyForm CGI remote execution. Status: Entry
Reference: BUGTRAQ:19950731 SECURITY HOLE:
"AnyForm" CGI
Reference: BID:719
Reference:
URL:http://www.securityfocus.com/bid/719
Reference: XF:http-cgi-anyform
Name: CVE-1999-0067
Description:
phf CGI program allows remote command execution through
shell metacharacters. Status: Entry
Reference: BUGTRAQ:19960923 PHF Attacks - Fun and
games for the whole family
Reference: CERT:CA-1996-06
Reference:
URL:http://www.cert.org/advisories/CA-1996-06.html
Reference: AUSCERT:AA-96.01
Reference: BID:629
Reference:
URL:http://www.securityfocus.com/bid/629
Reference: OSVDB:136
Reference: URL:http://www.osvdb.org/136
Reference: XF:http-cgi-phf
Name: CVE-1999-0068
Description:
CGI PHP mylog script allows an attacker to read any file
on the target server. Status: Entry
Reference: BUGTRAQ:19971019 Vulnerability in PHP
Example Logging Scripts
Reference: XF:http-cgi-php-mylog
Reference: BID:713
Reference:
URL:http://www.securityfocus.com/bid/713
Reference: OSVDB:3396
Reference: URL:http://www.osvdb.org/3396
Name: CVE-1999-0069
Description:
Solaris ufsrestore buffer overflow. Status: Entry
Reference: SUN:00169
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/169
Reference: XF:sun-ufsrestore
Reference: OSVDB:8158
Reference: URL:http://www.osvdb.org/8158
Name: CVE-1999-0070
Description:
test-cgi program allows an attacker to list files on the
server. Status: Entry
Reference: XF:http-cgi-test
Name: CVE-1999-0071
Description:
Apache httpd cookie buffer overflow for versions 1.1.1
and earlier. Status: Entry
Reference: XF:http-apache-cookie
Reference: NAI:NAI-2
Name: CVE-1999-0072
Description:
Buffer overflow in AIX xdat gives root access to local
users. Status: Entry
Reference: ERS:ERS-SVA-E01-1997:004.1
Reference: XF:ibm-xdat
Name: CVE-1999-0073
Description:
Telnet allows a remote client to specify environment
variables including LD_LIBRARY_PATH, allowing an
attacker to bypass the normal system libraries and gain
root access. Status: Entry
Reference:
CERT:CA-95:14.Telnetd_Environment_Vulnerability
Reference: XF:linkerbug
Name: CVE-1999-0074
Description:
Listening TCP ports are sequentially allocated, allowing
spoofing attacks. Status: Entry
Reference: XF:seqport
Name: CVE-1999-0075
Description:
PASV core dump in wu-ftpd daemon when attacker uses a
QUOTE PASV command after specifying a username and
password. Status: Entry
Reference: BUGTRAQ:19961016 Re: ftpd bug? Was:
bin/1805: Bug in ftpd
Reference: XF:ftp-pasvcore
Reference: OSVDB:5742
Reference: URL:http://www.osvdb.org/5742
Name: CVE-1999-0077
Description:
Predictable TCP sequence numbers allow spoofing.
Status: Entry
Reference: XF:tcp-seq-predict(139)
Reference:
URL:http://xforce.iss.net/static/139.php
Name: CVE-1999-0079
Description:
Remote attackers can cause a denial of service in FTP by
issuing multiple PASV commands, causing the server to
run out of available ports. Status: Entry
Reference: XF:ftp-pasv-dos
Reference: XF:ftp-pasvdos
Name: CVE-1999-0080
Description:
Certain configurations of wu-ftp FTP server 2.4 use a
_PATH_EXECPATH setting to a directory with dangerous
commands, such as /bin, which allows remote
authenticated users to gain root access via the "site
exec" command. Status: Entry
Reference: BUGTRAQ:19950531 SECURITY: problem
with some wu-ftpd-2.4 binaries (fwd)
Reference: CERT:CA-95:16.wu-ftpd.vul
Reference: XF:ftp-execdotdot
Name: CVE-1999-0081
Description:
wu-ftp allows files to be overwritten via the rnfr
command. Status: Entry
Reference: XF:ftp-rnfr
Name: CVE-1999-0082
Description:
CWD ~root command in ftpd allows root access. Status:
Entry
Reference: XF:ftp-cwd
Reference: FarmerVenema:Improving the Security of
Your Site by Breaking Into it
Reference:
URL:http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html
Name: CVE-1999-0083
Description:
getcwd() file descriptor leak in FTP. Status:
Entry
Reference: XF:cwdleak
Name: CVE-1999-0084
Description:
Certain NFS servers allow users to use mknod to gain
privileges by creating a writable kmem device and
setting the UID to 0. Status: Entry
Reference: XF:nfs-mknod(78)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/78
Name: CVE-1999-0085
Description:
Buffer overflow in rwhod on AIX and other operating
systems allows remote attackers to execute arbitrary
code via a UDP packet with a long hostname. Status:
Entry
Reference: BUGTRAQ:19960821 rwhod buffer overflow
Reference: XF:rwhod(119)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/119
Reference: XF:rwhod-vuln(118)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/118
Name: CVE-1999-0087
Description:
Denial of service in AIX telnet can freeze a system and
prevent users from accessing the server. Status:
Entry
Reference: XF:ibm-telnetdos
Reference: ERS:ERS-SVA-E01-1998:003.1
Reference: OSVDB:7992
Reference: URL:http://www.osvdb.org/7992
Name: CVE-1999-0090
Description:
Buffer overflow in AIX rcp command allows local users to
obtain root access. Status: Entry
Reference: ERS:ERS-SVA-E01-1997:005.1
Reference: XF:ibm-rcp
Name: CVE-1999-0091
Description:
Buffer overflow in AIX writesrv command allows local
users to obtain root access. Status: Entry
Reference: ERS:ERS-SVA-E01-1997:005.1
Reference: XF:ibm-writesrv
Name: CVE-1999-0093
Description:
AIX nslookup command allows local users to obtain root
access by not dropping privileges correctly. Status:
Entry
Reference: ERS:ERS-SVA-E01-1997:008.1
Reference: XF:ibm-nslookup
Name: CVE-1999-0094
Description:
AIX piodmgrsu command allows local users to gain
additional group privileges. Status: Entry
Reference: ERS:ERS-SVA-E01-1997:007.1
Reference: XF:ibm-piodmgrsu
Name: CVE-1999-0095
Description:
The debug command in Sendmail is enabled, allowing
attackers to execute commands as root. Status:
Entry
Reference: CERT:CA-88.01
Reference: CERT:CA-93.14
Reference: BID:1
Reference: URL:http://www.securityfocus.com/bid/1
Reference: OSVDB:195
Reference: URL:http://www.osvdb.org/195
Reference: XF:smtp-debug
Name: CVE-1999-0096
Description:
Sendmail decode alias can be used to overwrite sensitive
files. Status: Entry
Reference: CERT:CA-93.16
Reference: CERT:CA-95.05
Reference: CIAC:A-13
Reference: CIAC:A-14
Reference: SUN:00122
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/122&type=0&nav=sec.sba
Reference: XF:smtp-dcod
Name: CVE-1999-0097
Description:
The AIX FTP client can be forced to execute commands
from a malicious server through shell metacharacters
(e.g. a pipe character). Status: Entry
Reference: ERS:ERS-SVA-E01-1997:009.1
Reference: XF:ibm-ftp
Name: CVE-1999-0099
Description:
Buffer overflow in syslog utility allows local or remote
attackers to gain root privileges. Status: Entry
Reference: CERT:CA-95.13.syslog.vul
Reference: XF:smtp-syslog
Name: CVE-1999-0100
Description:
Remote access in AIX innd 1.5.1, using control messages.
Status: Entry
Reference: ERS:ERS-SVA-E01-1997:002.1
Reference: XF:inn-controlmsg
Name: CVE-1999-0101
Description:
Buffer overflow in AIX and Solaris "gethostbyname"
library call allows root access through corrupt DNS host
names. Status: Entry
Reference: ERS:ERS-SVA-E01-1997:001.1
Reference: ERS:ERS-SVA-E01-1996:007.1
Reference: SUN:00137a
Reference: CIAC:H-13
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/h-13.shtml
Reference: NAI:NAI-1
Reference: XF:ghbn-bo
Name: CVE-1999-0102
Description:
Buffer overflow in SLmail 3.x allows attackers to
execute commands using a large FROM line. Status:
Entry
Reference: XF:slmail-fromheader-overflow
Name: CVE-1999-0103
Description:
Echo and chargen, or other combinations of UDP services,
can be used in tandem to flood the server, a.k.a. UDP
bomb or UDP packet storm. Status: Entry
Reference: CERT:CA-96.01.UDP_service_denial
Reference: XF:echo
Reference: XF:chargen
Reference: XF:chargen-patch
Name: CVE-1999-0108
Description:
The printers program in IRIX has a buffer overflow that
gives root access to local users. Status: Entry
Reference: BUGTRAQ:another day, another buffer
overflow...
Reference: XF:printers-bo
Name: CVE-1999-0109
Description:
Buffer overflow in ffbconfig in Solaris 2.5.1.
Status: Entry
Reference: SUN:00140
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/140
Reference: AUSCERT:AA-97.06
Reference: XF:ffbconfig-bo
Name: CVE-1999-0111
Description:
RIP v1 is susceptible to spoofing. Status: Entry
Reference: XF:rip
Name: CVE-1999-0112
Description:
Buffer overflow in AIX dtterm program for the CDE.
Status: Entry
Reference: BUGTRAQ:19970520 AIX 4.2 dtterm
exploit
Reference: XF:dtterm-bo(878)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/878
Name: CVE-1999-0113
Description:
Some implementations of rlogin allow root access if
given a -froot parameter. Status: Entry
Reference: BUGTRAQ:19940729 -froot??? (AIX rlogin
bug)
Reference: CERT:CA-94.09.bin.login.vulnerability
Reference: CIAC:E-26
Reference: BID:458
Reference:
URL:http://www.securityfocus.com/bid/458
Reference: XF:rlogin-froot
Name: CVE-1999-0115
Description:
AIX bugfiler program allows local users to gain root
access. Status: Entry
Reference: BUGTRAQ:19970909 AIX bugfiler
Reference: XF:ibm-bugfiler
Reference: BID:1800
Reference:
URL:http://www.securityfocus.com/bid/1800
Name: CVE-1999-0116
Description:
Denial of service when an attacker sends many SYN
packets to create multiple connections without ever
sending an ACK to complete the connection, aka SYN
flood. Status: Entry
Reference: CERT:CA-96.21.tcp_syn.flooding
Reference: SGI:19961202-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19961202-01-PX
Reference: SUN:00136
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/136
Name: CVE-1999-0117
Description:
AIX passwd allows local users to gain root access.
Status: Entry
Reference: XF:ibm-passwd
Reference: CERT:CA-92:07.AIX.passwd.vulnerability
Name: CVE-1999-0118
Description:
AIX infod allows local users to gain root access through
an X display. Status: Entry
Reference: BUGTRAQ:19981119
RSI.0011.11-09-98.AIX.INFOD
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91158980826979&w=2
Reference: XF:aix-infod
Name: CVE-1999-0120
Description:
Sun/Solaris utmp file allows local users to gain root
access if it is writable by users other than root.
Status: Entry
Reference: SUN:00126
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/126
Reference: CERT:CA-94.06.utmp.vulnerability
Reference: XF:utmp-write
Name: CVE-1999-0122
Description:
Buffer overflow in AIX lchangelv gives root access.
Status: Entry
Reference: BUGTRAQ:Jul21,1999
Reference: XF:lchangelv-bo
Name: CVE-1999-0124
Description:
Vulnerabilities in UMN gopher and gopher+ versions 1.12
and 2.0x allow an intruder to read any files that can be
accessed by the gopher daemon. Status: Entry
Reference:
CERT:CA-93:11.UMN.UNIX.gopher.vulnerability
Reference: XF:gopher-vuln
Name: CVE-1999-0125
Description:
Buffer overflow in SGI IRIX mailx program. Status:
Entry
Reference: XF:sgi-mailx-bo
Reference: SGI:19980605-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980605-01-PX
Name: CVE-1999-0126
Description:
SGI IRIX buffer overflow in xterm and Xaw allows root
access. Status: Entry
Reference: CERT:VB-98.04.xterm.Xaw
Reference: CIAC:J-010
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-010.shtml
Reference: XF:xfree86-xterm-xaw
Reference: XF:xfree86-xaw
Name: CVE-1999-0128
Description:
Oversized ICMP ping packets can result in a denial of
service, aka Ping o' Death. Status: Entry
Reference: XF:ping-death
Reference: CERT:CA-96.26.ping
Name: CVE-1999-0129
Description:
Sendmail allows local users to write to a file and gain
group permissions via a .forward or :include: file.
Status: Entry
Reference: CERT:CA-96.25.sendmail_groups
Name: CVE-1999-0130
Description:
Local users can start Sendmail in daemon mode and gain
root privileges. Status: Entry
Reference: CERT:CA-96.24.sendmail.daemon.mode
Reference: BID:716
Reference:
URL:http://www.securityfocus.com/bid/716
Reference: XF:sendmail-daemon-mode
Name: CVE-1999-0131
Description:
Buffer overflow and denial of service in Sendmail 8.7.5
and earlier through GECOS field gives root access to
local users. Status: Entry
Reference: CERT:CA-96.20.sendmail_vul
Reference: XF:smtp-875bo
Reference: BID:717
Reference:
URL:http://www.securityfocus.com/bid/717
Name: CVE-1999-0132
Description:
Expreserve, as used in vi and ex, allows local users to
overwrite arbitrary files and gain root access.
Status: Entry
Reference: CERT:CA-1996-19
Reference:
URL:http://www.cert.org/advisories/CA-1996-19.html
Reference: OSVDB:11723
Reference: URL:http://www.osvdb.org/11723
Reference: XF:expreserve(401)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/401
Name: CVE-1999-0133
Description:
fm_fls license server for Adobe Framemaker allows local
users to overwrite arbitrary files and gain root access.
Status: Entry
Reference: CERT:CA-96.18.fm_fls
Reference: XF:fmaker-logfile
Name: CVE-1999-0134
Description:
vold in Solaris 2.x allows local users to gain root
access. Status: Entry
Reference: XF:sol-voldtmp
Reference: CERT:CA-96.17.Solaris_vold_vul
Reference: AUSCERT:AL-96.04
Reference: OSVDB:8159
Reference: URL:http://www.osvdb.org/8159
Name: CVE-1999-0135
Description:
admintool in Solaris allows a local user to write to
arbitrary files and gain root access. Status:
Entry
Reference: XF:sun-admintool
Reference: CERT:CA-96.16.Solaris_admintool_vul
Reference: AUSCERT:AL-96.03
Name: CVE-1999-0136
Description:
Kodak Color Management System (KCMS) on Solaris allows a
local user to write to arbitrary files and gain root
access. Status: Entry
Reference: XF:sol-KCMSvuln
Reference: AUSCERT:AL-96.02
Reference: CERT:CA-96.15.Solaris_KCMS_vul
Name: CVE-1999-0137
Description:
The dip program on many Linux systems allows local users
to gain root access via a buffer overflow. Status:
Entry
Reference: XF:linux-dipbo
Reference: CERT:CA-96.13.dip_vul
Reference: XF:dip-bo
Name: CVE-1999-0138
Description:
The suidperl and sperl program do not give up root
privileges when changing UIDs back to the original
users, allowing root access. Status: Entry
Reference: CERT:CA-96.12.suidperl_vul
Reference: XF:sperl-suid
Name: CVE-1999-0139
Description:
Buffer overflow in Solaris x86 mkcookie allows local
users to obtain root access. Status: Entry
Reference: XF:sol-mkcookie
Reference: RSI:RSI.0012.12-03-98.SOLARIS.MKCOOKIE
Reference: OSVDB:8205
Reference: URL:http://www.osvdb.org/8205
Name: CVE-1999-0141
Description:
Java Bytecode Verifier allows malicious applets to
execute arbitrary commands as the user of the applet.
Status: Entry
Reference: XF:http-java-applet
Reference: CERT:CA-96.07.java_bytecode_verifier
Reference: SUN:00134
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/134
Name: CVE-1999-0142
Description:
The Java Applet Security Manager implementation in
Netscape Navigator 2.0 and Java Developer's Kit 1.0
allows an applet to connect to arbitrary hosts.
Status: Entry
Reference: CERT:CA-96.05.java_applet_security_mgr
Reference: XF:http-java-appletsecmgr
Name: CVE-1999-0143
Description:
Kerberos 4 key servers allow a user to masquerade as
another by breaking and generating session keys.
Status: Entry
Reference: CERT:CA-96.03.kerberos_4_key_server
Reference: XF:kerberos-bf
Name: CVE-1999-0145
Description:
Sendmail WIZ command enabled, allowing root access.
Status: Entry
Reference: CERT:CA-1990-11
Reference:
URL:http://www.cert.org/advisories/CA-1990-11.html
Reference: CERT:CA-1993-14
Reference:
URL:http://www.cert.org/advisories/CA-1993-14.html
Reference: BUGTRAQ:19950206 sendmail wizard
thing...
Reference:
URL:http://www2.dataguard.no/bugtraq/1995_1/0332.html
Reference: FarmerVenema:Improving the Security of
Your Site by Breaking Into it
Reference:
URL:http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html
Name: CVE-1999-0146
Description:
The campas CGI program provided with some NCSA web
servers allows an attacker to execute arbitrary commands
via encoded carriage return characters in the query
string, as demonstrated by reading the password file.
Status: Entry
Reference: BUGTRAQ:19970715 Bug CGI campas
Reference: BID:1975
Reference:
URL:http://www.securityfocus.com/bid/1975
Reference: XF:http-cgi-campas(298)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/298
Name: CVE-1999-0147
Description:
The aglimpse CGI program of the Glimpse package allows
remote execution of arbitrary commands. Status:
Entry
Reference: XF:http-cgi-glimpse
Reference: AUSCERT:AA-97.28
Name: CVE-1999-0148
Description:
The handler CGI program in IRIX allows arbitrary command
execution. Status: Entry
Reference: SGI:19970501-02-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX
Reference: BID:380
Reference:
URL:http://www.securityfocus.com/bid/380
Reference: XF:http-sgi-handler
Name: CVE-1999-0149
Description:
The wrap CGI program in IRIX allows remote attackers to
view arbitrary directory listings via a .. (dot dot)
attack. Status: Entry
Reference: BUGTRAQ:19970420 IRIX 6.x
/cgi-bin/wrap bug
Reference: SGI:19970501-02-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX
Reference: BID:373
Reference:
URL:http://www.securityfocus.com/bid/373
Reference: OSVDB:247
Reference: URL:http://www.osvdb.org/247
Reference: XF:http-sgi-wrap(290)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/290
Name: CVE-1999-0150
Description:
The Perl fingerd program allows arbitrary command
execution from remote users. Status: Entry
Reference: XF:perl-fingerd
Name: CVE-1999-0151
Description:
The SATAN session key may be disclosed if the user
points the web browser to other sites, possibly allowing
root access. Status: Entry
Reference: CERT:CA-95.07a.REVISED.satan.vul
Reference: CERT:CA-95.06.satan.vul
Name: CVE-1999-0152
Description:
The DG/UX finger daemon allows remote command execution
through shell metacharacters. Status: Entry
Reference: BUGTRAQ:19970811 dgux in.fingerd
vulnerability
Reference: XF:dgux-fingerd
Name: CVE-1999-0153
Description:
Windows 95/NT out of band (OOB) data denial of service
through NETBIOS port, aka WinNuke. Status: Entry
Reference: XF:win-oob
Reference: OSVDB:1666
Reference: URL:http://www.osvdb.org/1666
Name: CVE-1999-0155
Description:
The ghostscript command with the -dSAFER option allows
remote attackers to execute commands. Status:
Entry
Reference: XF:gscript-dsafer
Reference: CERT:CA-95.10.ghostscript
Name: CVE-1999-0157
Description:
Cisco PIX firewall and CBAC IP fragmentation attack
results in a denial of service. Status: Entry
Reference:
CISCO:http://www.cisco.com/warp/public/770/nifrag.shtml
Reference: XF:cisco-fragmented-attacks
Reference: OSVDB:1097
Reference: URL:http://www.osvdb.org/1097
Name: CVE-1999-0158
Description:
Cisco PIX firewall manager (PFM) on Windows NT allows
attackers to connect to port 8080 on the PFM server and
retrieve any file whose name and location is known.
Status: Entry
Reference: CISCO:20010913 Cisco PIX Firewall
Manager File Exposure
Reference:
URL:http://www.cisco.com/warp/public/770/pixmgrfile-pub.shtml
Reference: XF:cisco-pix-file-exposure
Reference: OSVDB:685
Reference: URL:http://www.osvdb.org/685
Name: CVE-1999-0159
Description:
Attackers can crash a Cisco IOS router or device,
provided they can get to an interactive prompt (such as
a login). This applies to some IOS 9.x, 10.x, and 11.x
releases. Status: Entry
Reference:
CISCO:http://www.cisco.com/warp/public/770/ioslogin-pub.shtml
Reference: XF:cisco-ios-crash
Name: CVE-1999-0160
Description:
Some classic Cisco IOS devices have a vulnerability in
the PPP CHAP authentication to establish unauthorized
PPP connections. Status: Entry
Reference: CISCO:19971001 Vulnerabilities in
Cisco CHAP Authentication
Reference: CIAC:I-002A
Reference: OSVDB:1099
Reference: URL:http://www.osvdb.org/1099
Reference: XF:cisco-chap
Name: CVE-1999-0161
Description:
In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword,
an extended IP access control list could bypass
filtering. Status: Entry
Reference:
CISCO:http://www.cisco.com/warp/public/707/1.html
Reference: XF:cisco-acl-tacacs
Reference: OSVDB:797
Reference: URL:http://www.osvdb.org/797
Name: CVE-1999-0162
Description:
The "established" keyword in some Cisco IOS software
allowed an attacker to bypass filtering. Status:
Entry
Reference: CISCO:19950601 "Established" Keyword
May Allow Packets to Bypass Filter
Reference: XF:cisco-acl-established
Name: CVE-1999-0164
Description:
A race condition in the Solaris ps command allows an
attacker to overwrite critical files. Status:
Entry
Reference: XF:sol-pstmprace
Reference: AUSCERT:AA-95.07
Reference: CERT:CA-95.09.Solaris.ps.vul
Reference: OSVDB:8346
Reference: URL:http://www.osvdb.org/8346
Name: CVE-1999-0166
Description:
NFS allows users to use a "cd .." command to access
other directories besides the exported file system.
Status: Entry
Reference: XF:nfs-cd
Name: CVE-1999-0167
Description:
In SunOS, NFS file handles could be guessed, giving
unauthorized access to the exported file system.
Status: Entry
Reference: XF:nfs-guess
Reference:
CERT:CA-91.21.SunOS.NFS.Jumbo.and.fsirand
Name: CVE-1999-0168
Description:
The portmapper may act as a proxy and redirect service
requests from an attacker, making the request appear to
come from the local host, possibly bypassing
authentication that would otherwise have taken place.
For example, NFS file systems could be mounted through
the portmapper despite export restrictions. Status:
Entry
Reference: XF:nfs-portmap
Name: CVE-1999-0170
Description:
Remote attackers can mount an NFS file system in Ultrix
or OSF, even if it is denied on the access list.
Status: Entry
Reference: XF:nfs-ultrix
Name: CVE-1999-0172
Description:
FormMail CGI program allows remote execution of
commands. Status: Entry
Reference: XF:http-cgi-formmail-exe
Reference: BUGTRAQ:Aug02,1995
Name: CVE-1999-0173
Description:
FormMail CGI program can be used by web servers other
than the host server that the program resides on.
Status: Entry
Reference: XF:http-cgi-formmail-use
Name: CVE-1999-0174
Description:
The view-source CGI program allows remote attackers to
read arbitrary files via a .. (dot dot) attack.
Status: Entry
Reference: BUGTRAQ:19970208 view-source
Reference: XF:http-cgi-viewsrc
Name: CVE-1999-0175
Description:
The convert.bas program in the Novell web server allows
a remote attackers to read any file on the system that
is internally accessible by the web server. Status:
Entry
Reference: XF:http-nov-convert
Name: CVE-1999-0176
Description:
The Webgais program allows a remote user to execute
arbitrary commands. Status: Entry
Reference: BUGTRAQ:Jul10,1997
Reference: XF:http-webgais-query
Name: CVE-1999-0177
Description:
The uploader program in the WebSite web server allows a
remote attacker to execute arbitrary programs.
Status: Entry
Reference: NTBUGTRAQ:19970904 [Alert] Website's
uploader.exe (from demo) vulnerable
Reference: NTBUGTRAQ:19970905 Re: FW: [Alert]
Website's uploader.exe (from demo) vulnerable
Reference: BUGTRAQ:19970904 [Alert] Website's
uploader.exe (from demo) vulnerable
Reference: XF:http-website-uploader
Name: CVE-1999-0178
Description:
Buffer overflow in the win-c-sample program
(win-c-sample.exe) in the WebSite web server 1.1e allows
remote attackers to execute arbitrary code via a long
query string. Status: Entry
Reference: BUGTRAQ:19970106 Re: signal handling
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/1997_1/0021.html
Reference: BID:2078
Reference:
URL:http://www.securityfocus.com/bid/2078
Reference: OSVDB:8
Reference: URL:http://www.osvdb.org/8
Reference: XF:http-website-winsample(295)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/295
Name: CVE-1999-0179
Description:
Windows NT crashes or locks up when a Samba client
executes a "cd .." command on a file share. Status:
Entry
Reference: MSKB:Q140818
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q140818
Reference: XF:nt-samba-dotdot
Reference: XF:nt-351
Reference: XF:nt-35
Name: CVE-1999-0180
Description:
in.rshd allows users to login with a NULL username and
execute commands. Status: Entry
Reference: XF:rsh-null
Name: CVE-1999-0181
Description:
The wall daemon can be used for denial of service,
social engineering attacks, or to execute remote
commands. Status: Entry
Reference: XF:walld
Name: CVE-1999-0182
Description:
Samba has a buffer overflow which allows a remote
attacker to obtain root access by specifying a long
password. Status: Entry
Reference: CIAC:H-110
Reference:
URL:http://www.ciac.org/ciac/bulletins/h-110.shtml
Reference: CERT:VB-97.10.samba
Reference: XF:nt-samba-bo
Name: CVE-1999-0183
Description:
Linux implementations of TFTP would allow access to
files outside the restricted directory. Status:
Entry
Reference: XF:linux-tftp
Name: CVE-1999-0184
Description:
When compiled with the -DALLOW_UPDATES option, bind
allows dynamic updates to the DNS server, allowing for
malicious modification of DNS records. Status:
Entry
Reference: XF:dns-updates
Name: CVE-1999-0185
Description:
In SunOS or Solaris, a remote user could connect from an
FTP server's data port to an rlogin server on a host
that trusts the FTP server, allowing remote command
execution. Status: Entry
Reference: SUN:00156
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/156
Reference: XF:sun-ftpd/logind
Name: CVE-1999-0188
Description:
The passwd command in Solaris can be subjected to a
denial of service. Status: Entry
Reference: SUN:00182
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/182
Reference: XF:sun-passwd-dos
Name: CVE-1999-0189
Description:
Solaris rpcbind listens on a high numbered UDP port,
which may not be filtered since the standard port number
is 111. Status: Entry
Reference: NAI:NAI-15
Reference: SUN:00142
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/142
Reference: XF:rpc-32771
Name: CVE-1999-0190
Description:
Solaris rpcbind can be exploited to overwrite arbitrary
files and gain root access. Status: Entry
Reference: SUN:00167
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/167
Reference: XF:sun-rpcbind
Name: CVE-1999-0191
Description:
IIS newdsn.exe CGI script allows remote users to
overwrite files. Status: Entry
Reference: XF:http-cgi-newdsn
Reference: OSVDB:275
Reference: URL:http://www.osvdb.org/275
Name: CVE-1999-0192
Description:
Buffer overflow in telnet daemon tgetent routing allows
remote attackers to gain root access via the TERMCAP
environmental variable. Status: Entry
Reference: SNI:SNI-20
Reference: XF:bsd-tel-tgetent
Name: CVE-1999-0194
Description:
Denial of service in in.comsat allows attackers to
generate messages. Status: Entry
Reference: XF:comsat
Name: CVE-1999-0196
Description:
websendmail in Webgais 1.0 allows a remote user to
access arbitrary files and execute arbitrary code via
the receiver parameter ($VAR_receiver variable).
Status: Entry
Reference: BUGTRAQ:19970704 Vulnerability in
websendmail
Reference: BID:2077
Reference:
URL:http://www.securityfocus.com/bid/2077
Reference: OSVDB:237
Reference: URL:http://www.osvdb.org/237
Reference: XF:http-webgais-smail
Name: CVE-1999-0201
Description:
A quote cwd command on FTP servers can reveal the full
path of the home directory of the "ftp" user. Status:
Entry
Reference: XF:ftp-home
Name: CVE-1999-0202
Description:
The GNU tar command, when used in FTP sessions, may
allow an attacker to execute arbitrary commands.
Status: Entry
Reference: XF:ftp-exectar
Name: CVE-1999-0203
Description:
In Sendmail, attackers can gain root privileges via SMTP
by specifying an improper "mail from" address and an
invalid "rcpt to" address that would cause the mail to
bounce to a program. Status: Entry
Reference: CERT:CA-95.08
Reference: CIAC:E-03
Reference: XF:smtp-sendmail-version5
Name: CVE-1999-0204
Description:
Sendmail 8.6.9 allows remote attackers to execute root
commands, using ident. Status: Entry
Reference: XF:ident-bo
Reference: CIAC:F-13
Name: CVE-1999-0206
Description:
MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives
root access. Status: Entry
Reference: XF:sendmail-mime-bo
Reference: AUSCERT:AA-96.06a
Name: CVE-1999-0207
Description:
Remote attacker can execute commands through Majordomo
using the Reply-To field and a "lists" command.
Status: Entry
Reference: XF:majordomo-exe
Reference:
CERT:CA-94.11.majordomo.vulnerabilities
Name: CVE-1999-0208
Description:
rpc.ypupdated (NIS) allows remote users to execute
arbitrary commands. Status: Entry
Reference: XF:rpc-update
Reference: CERT:CA-95.17.rpc.ypupdated.vul
Name: CVE-1999-0209
Description:
The SunView (SunTools) selection_svc facility allows
remote users to read files. Status: Entry
Reference:
CERT:CA-90.05.sunselection.vulnerability
Reference: BID:8
Reference: URL:http://www.securityfocus.com/bid/8
Reference: XF:selsvc
Name: CVE-1999-0210
Description:
Automount daemon automountd allows local or remote users
to gain privileges via shell metacharacters. Status:
Entry
Reference: BUGTRAQ:19971126 Solaris 2.5.1
automountd exploit (fwd)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88053459921223&w=2
Reference: BUGTRAQ:19990103 SUN almost has a
clue! (automountd)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91547759121289&w=2
Reference: HP:HPSBUX9910-104
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9910-104
Reference: CERT:CA-99-05
Reference:
URL:http://www.cert.org/advisories/CA-99-05-statd-automountd.html
Reference: BID:235
Reference:
URL:http://www.securityfocus.com/bid/235
Name: CVE-1999-0211
Description:
Extra long export lists over 256 characters in some
mount daemons allows NFS directories to be mounted by
anyone. Status: Entry
Reference:
CERT:CA-94.02.REVISED.SunOS.rpc.mountd.vulnerability
Reference: BID:24
Reference:
URL:http://www.securityfocus.com/bid/24
Name: CVE-1999-0212
Description:
Solaris rpc.mountd generates error messages that allow a
remote attacker to determine what files are on the
server. Status: Entry
Reference: SUN:00168
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/168
Reference: CIAC:I-048
Reference:
URL:http://www.ciac.org/ciac/bulletins/i-048.shtml
Reference: XF:sun-mountd
Name: CVE-1999-0214
Description:
Denial of service by sending forged ICMP unreachable
packets. Status: Entry
Reference: XF:icmp-unreachable
Name: CVE-1999-0215
Description:
Routed allows attackers to append data to files.
Status: Entry
Reference: SGI:19981004-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19981004-01-PX
Reference: CIAC:J-012
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-012.shtml
Reference: XF:ripapp
Name: CVE-1999-0217
Description:
Malicious option settings in UDP packets could force a
reboot in SunOS 4.1.3 systems. Status: Entry
Reference: XF:udp-bomb
Name: CVE-1999-0218
Description:
Livingston portmaster machines could be rebooted via a
series of commands. Status: Entry
Reference: XF:portmaster-reboot
Name: CVE-1999-0219
Description:
Buffer overflow in FTP Serv-U 2.5 allows remote
authenticated users to cause a denial of service (crash)
via a long (1) CWD or (2) LS (list) command. Status:
Entry
Reference: NTBUGTRAQ:19990503 Buffer overflows in
FTP Serv-U 2.5
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92574916930144&w=2
Reference: NTBUGTRAQ:19990504 Re: Buffer
overflows in FTP Serv-U 2.5
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92582581330282&w=2
Reference: BUGTRAQ:19990909 Exploit: Serv-U
Ver2.5 FTPd Win9x/NT
Reference: BID:269
Reference:
URL:http://www.securityfocus.com/bid/269
Reference: XF:ftp-servu(205)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/205
Name: CVE-1999-0221
Description:
Denial of service of Ascend routers through port 150
(remote administration). Status: Entry
Reference: XF:ascend-150-kill
Name: CVE-1999-0223
Description:
Solaris syslogd crashes when receiving a message from a
host that doesn't have an inverse DNS entry. Status:
Entry
Reference: BUGTRAQ:19961109 Syslogd and Solaris
2.4
Reference: SUNBUG:1249320
Reference:
CONFIRM:http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&collection=fpatches
Reference: XF:sol-syslogd-crash
Reference: BID:1878
Reference:
URL:http://www.securityfocus.com/bid/1878
Name: CVE-1999-0224
Description:
Denial of service in Windows NT messenger service
through a long username. Status: Entry
Reference: XF:nt-messenger
Name: CVE-1999-0225
Description:
Windows NT 4.0 allows remote attackers to cause a denial
of service via a malformed SMB logon request in which
the actual data size does not match the specified size.
Status: Entry
Reference: NAI:19980214 Windows NT Logon Denial
of Service
Reference:
URL:http://www.nai.com/nai_labs/asp_set/advisory/25_windows_nt_dos_adv.asp
Reference: MSKB:Q180963
Reference:
URL:http://www.microsoft.com/technet/support/kb.asp?ID=180963
Reference: XF:nt-logondos
Name: CVE-1999-0227
Description:
Access violation in LSASS.EXE (LSA/LSARPC) program in
Windows NT allows a denial of service. Status:
Entry
Reference: MSKB:Q154087
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q154087
Reference: XF:nt-lsass-crash
Name: CVE-1999-0228
Description:
Denial of service in RPCSS.EXE program (RPC Locator) in
Windows NT. Status: Entry
Reference: XF:nt-rpc-ver
Reference: MSKB:Q162567
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q162567
Name: CVE-1999-0230
Description:
Buffer overflow in Cisco 7xx routers through the telnet
service. Status: Entry
Reference:
CISCO:http://www.cisco.com/warp/public/770/pwbuf-pub.shtml
Reference: OSVDB:1102
Reference: URL:http://www.osvdb.org/1102
Name: CVE-1999-0233
Description:
IIS 1.0 allows users to execute arbitrary commands using
.bat or .cmd files. Status: Entry
Reference: MSKB:Q148188
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q148188
Reference: MSKB:Q155056
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q155056
Reference: XF:http-iis-cmd
Name: CVE-1999-0234
Description:
Bash treats any character with a value of 255 as a
command separator. Status: Entry
Reference: XF:bash-cmd
Reference: CERT:CA-96.22.bash_vuls
Name: CVE-1999-0236
Description:
ScriptAlias directory in NCSA and Apache httpd allowed
attackers to read CGI programs. Status: Entry
Reference: XF:http-scriptalias
Name: CVE-1999-0237
Description:
Remote execution of arbitrary commands through Guestbook
CGI program. Status: Entry
Reference: XF:http-cgi-guestbook
Reference: CERT:VB-97.02
Name: CVE-1999-0239
Description:
Netscape FastTrack Web server lists files when a
lowercase "get" command is used instead of an uppercase
GET. Status: Entry
Reference: XF:fastrack-get-directory-list
Reference: OSVDB:122
Reference: URL:http://www.osvdb.org/122
Name: CVE-1999-0244
Description:
Livingston RADIUS code has a buffer overflow which can
allow remote execution of commands as root. Status:
Entry
Reference: NAI:NAI-23
Reference: XF:radius-accounting-overflow
Name: CVE-1999-0245
Description:
Some configurations of NIS+ in Linux allowed attackers
to log in as the user "+". Status: Entry
Reference: BUGTRAQ:19950907 Linux NIS security
problem hole and fix
Reference: XF:linux-plus
Name: CVE-1999-0247
Description:
Buffer overflow in nnrpd program in INN up to version
1.6 allows remote users to execute arbitrary commands.
Status: Entry
Reference: NAI:19970721 INN news server
vulnerabilities
Reference:
URL:http://www.nai.com/nai_labs/asp_set/advisory/17_inn_avd.asp
Reference: BID:1443
Reference:
URL:http://www.securityfocus.com/bid/1443
Reference: XF:inn-bo
Name: CVE-1999-0248
Description:
A race condition in the authentication agent mechanism
of sshd 1.2.17 allows an attacker to steal another
user's credentials. Status: Entry
Reference:
MISC:http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html
Reference:
CONFIRM:http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1
Name: CVE-1999-0251
Description:
Denial of service in talk program allows remote
attackers to disrupt a user's display. Status:
Entry
Reference: XF:talkd-flash
Name: CVE-1999-0252
Description:
Buffer overflow in listserv allows arbitrary command
execution. Status: Entry
Reference: XF:smtp-listserv
Name: CVE-1999-0256
Description:
Buffer overflow in War FTP allows remote execution of
commands. Status: Entry
Reference: XF:war-ftpd
Reference: OSVDB:875
Reference: URL:http://www.osvdb.org/875
Name: CVE-1999-0259
Description:
cfingerd lists all users on a system via
search.**@target. Status: Entry
Reference: BUGTRAQ:19970523 cfingerd
vulnerability
Reference: XF:cfinger-user-enumeration
Name: CVE-1999-0260
Description:
The jj CGI program allows command execution via shell
metacharacters. Status: Entry
Reference: BUGTRAQ:19961224 jj cgi
Reference: XF:http-cgi-jj
Name: CVE-1999-0262
Description:
Hylafax faxsurvey CGI script on Linux allows remote
attackers to execute arbitrary commands via shell
metacharacters in the query string. Status: Entry
Reference: BUGTRAQ:19980804 remote exploit in
faxsurvey cgi-script
Reference: BUGTRAQ:19980804 PATCH: faxsurvey
Reference: BID:2056
Reference:
URL:http://www.securityfocus.com/bid/2056
Reference: XF:http-cgi-faxsurvey(1532)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/1532
Name: CVE-1999-0263
Description:
Solaris SUNWadmap can be exploited to obtain root
access. Status: Entry
Reference: SUN:00173
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/173
Reference: XF:sun-sunwadmap
Name: CVE-1999-0264
Description:
htmlscript CGI program allows remote read access to
files. Status: Entry
Reference: XF:http-htmlscript-file-access
Reference: BUGTRAQ:Jan27,1998
Name: CVE-1999-0265
Description:
ICMP redirect messages may crash or lock up a host.
Status: Entry
Reference: MSKB:Q154174
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q154174
Reference: ISS:ICMP Redirects Against Embedded
Controllers
Reference: XF:icmp-redirect
Name: CVE-1999-0266
Description:
The info2www CGI script allows remote file access or
remote command execution. Status: Entry
Reference: BUGTRAQ:19980303 Vulnerabilites in
some versions of info2www CGI
Reference: BID:1995
Reference:
URL:http://www.securityfocus.com/bid/1995
Reference: XF:http-cgi-info2www
Name: CVE-1999-0267
Description:
Buffer overflow in NCSA HTTP daemon v1.3 allows remote
command execution. Status: Entry
Reference: XF:http-port
Reference:
CERT:CA-95.04.NCSA.http.daemon.for.unix.vulnerability
Name: CVE-1999-0268
Description:
MetaInfo MetaWeb web server allows users to upload,
execute, and read scripts. Status: Entry
Reference: BUGTRAQ:19980630 Security
vulnerabilities in MetaInfo products
Reference: BUGTRAQ:19980703 Followup to MetaInfo
vulnerabilities
Reference: OSVDB:110
Reference: URL:http://www.osvdb.org/110
Reference: OSVDB:3969
Reference: URL:http://www.osvdb.org/3969
Reference: XF:metaweb-server-dot-attack
Name: CVE-1999-0269
Description:
Netscape Enterprise servers may list files through the
PageServices query. Status: Entry
Reference: XF:netscape-server-pageservices
Name: CVE-1999-0270
Description:
Directory traversal vulnerability in pfdispaly.cgi
program (sometimes referred to as "pfdisplay") for SGI's
Performer API Search Tool (performer_tools) allows
remote attackers to read arbitrary files. Status:
Entry
Reference: BUGTRAQ:19980317 IRIX performer_tools
bug
Reference: SGI:19980401-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980401-01-P
Reference: CIAC:I-041
Reference:
URL:http://www.ciac.org/ciac/bulletins/i-041.shtml
Reference: BID:64
Reference:
URL:http://www.securityfocus.com/bid/64
Reference: OSVDB:134
Reference: URL:http://www.osvdb.org/134
Reference: XF:sgi-pfdispaly(810)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/810
Name: CVE-1999-0272
Description:
Denial of service in Slmail v2.5 through the POP3 port.
Status: Entry
Reference: XF:slmail-username-bo
Name: CVE-1999-0273
Description:
Denial of service through Solaris 2.5.1 telnet by
sending ^D characters. Status: Entry
Reference: XF:sun-telnet-kill
Name: CVE-1999-0274
Description:
Denial of service in Windows NT DNS servers through
malicious packet which contains a response to a query
that wasn't made. Status: Entry
Reference: NAI:NAI-5
Reference: XF:nt-dns-dos
Name: CVE-1999-0275
Description:
Denial of service in Windows NT DNS servers by flooding
port 53 with too many characters. Status: Entry
Reference: XF:nt-dnscrash
Reference: XF:nt-dnsver
Reference: MS:Q169461
Name: CVE-1999-0276
Description:
mSQL v2.0.1 and below allows remote execution through a
buffer overflow. Status: Entry
Reference: XF:msql-debug-bo
Reference: SEKURE:sekure.01-99.msql
Name: CVE-1999-0277
Description:
The WorkMan program can be used to overwrite any file to
get root access. Status: Entry
Reference: XF:workman
Reference: CERT:CA-96.23.workman_vul
Name: CVE-1999-0278
Description:
In IIS, remote attackers can obtain source code for ASP
files by appending "::$DATA" to the URL. Status:
Entry
Reference: MS:MS98-003
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms98-003.mspx
Reference: XF:iis-asp-data-check
Reference: OVAL:oval:org.mitre.oval:def:913
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:913
Name: CVE-1999-0279
Description:
Excite for Web Servers (EWS) allows remote command
execution via shell metacharacters. Status: Entry
Reference: BUGTRAQ:19971217 CGI security hole in
EWS (Excite for Web Servers)
Reference: BUGTRAQ:19980115 Excite announcement
Reference: CERT:VB-98.01.excite
Reference: XF:excite-cgi-search-vuln
Name: CVE-1999-0280
Description:
Remote command execution in Microsoft Internet Explorer
using .lnk and .url files. Status: Entry
Reference: NTBUGTRAQ:19970317 Internet Explorer
Bug #4
Reference: CIAC:H-38
Reference: XF:http-ie-lnkurl
Name: CVE-1999-0281
Description:
Denial of service in IIS using long URLs. Status:
Entry
Reference: XF:http-iis-longurl
Name: CVE-1999-0288
Description:
The WINS server in Microsoft Windows NT 4.0 before SP4
allows remote attackers to cause a denial of service
(process termination) via invalid UDP frames to port 137
(NETBIOS Name Service), as demonstrated via a flood of
random packets. Status: Entry
Reference: NTBUGTRAQ:19970801 WINS flooding
Reference: BUGTRAQ:19970801 WINS flooding
Reference: BUGTRAQ:19970815 Re: WINS flooding
Reference:
MISC:http://safenetworks.com/Windows/wins.html
Reference: MSKB:155701
Reference: XF:nt-winsupd-fix(1233)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/1233
Name: CVE-1999-0289
Description:
The Apache web server for Win32 may provide access to
restricted files when a . (dot) is appended to a
requested URL. Status: Entry
Name: CVE-1999-0290
Description:
The WinGate telnet proxy allows remote attackers to
cause a denial of service via a large number of
connections to localhost. Status: Entry
Reference: BUGTRAQ:19980221 WinGate DoS
Reference: BUGTRAQ:19980326 WinGate Intermediary
Fix/Update
Reference: XF:wingate-dos
Name: CVE-1999-0291
Description:
The WinGate proxy is installed without a password, which
allows remote attackers to redirect connections without
authentication. Status: Entry
Reference: XF:wingate-unpassworded
Name: CVE-1999-0292
Description:
Denial of service through Winpopup using large user
names. Status: Entry
Reference: XF:nt-winpopup
Name: CVE-1999-0293
Description:
AAA authentication on Cisco systems allows attackers to
execute commands without authorization. Status:
Entry
Reference:
CISCO:http://www.cisco.com/warp/public/770/aaapair-pub.shtml
Reference: XF:cisco-ios-aaa-auth
Name: CVE-1999-0294
Description:
All records in a WINS database can be deleted through
SNMP for a denial of service. Status: Entry
Reference: XF:nt-wins-snmp2
Name: CVE-1999-0295
Description:
Solaris sysdef command allows local users to read kernel
memory, potentially leading to root privileges.
Status: Entry
Reference: XF:sun-sysdef
Reference: SUN:00157
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/157
Name: CVE-1999-0296
Description:
Solaris volrmmount program allows attackers to read any
file. Status: Entry
Reference: SUN:00162
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/162
Reference: XF:sun-volrmmount
Name: CVE-1999-0297
Description:
Buffer overflow in Vixie Cron library up to version 3.0
allows local users to obtain root access via a long
environmental variable. Status: Entry
Reference: NAI:NAI-3
Reference: AUSCERT:AA-96.21
Reference: CIAC:H-17
Reference: XF:vixie-cron
Name: CVE-1999-0299
Description:
Buffer overflow in FreeBSD lpd through long DNS
hostnames. Status: Entry
Reference: NAI:NAI-9
Reference: OSVDB:6093
Reference: URL:http://www.osvdb.org/6093
Name: CVE-1999-0300
Description:
nis_cachemgr for Solaris NIS+ allows attackers to add
malicious NIS+ servers. Status: Entry
Reference: SUN:00155
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/155
Reference: XF:sun-niscache
Name: CVE-1999-0301
Description:
Buffer overflow in SunOS/Solaris ps command. Status:
Entry
Reference: SUN:00149
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/149
Reference: AUSCERT:AUSCERT-97.17
Reference: XF:sun-ps2bo
Name: CVE-1999-0302
Description:
SunOS/Solaris FTP clients can be forced to execute
arbitrary commands from a malicious FTP server.
Status: Entry
Reference: SUN:00176
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/176
Reference: XF:sun-ftp-server
Name: CVE-1999-0303
Description:
Buffer overflow in BNU UUCP daemon (uucpd) through long
hostnames. Status: Entry
Reference: XF:bnu-uucpd-bo
Reference: RSI:RSI.0002.05-18-98.BNU.UUCPD
Name: CVE-1999-0304
Description:
mmap function in BSD allows local attackers in the kmem
group to modify memory through devices. Status:
Entry
Reference: XF:bsd-mmap
Reference: FREEBSD:FreeBSD-SA-98:02
Name: CVE-1999-0305
Description:
The system configuration control (sysctl) facility in
BSD based operating systems OpenBSD 2.2 and earlier, and
FreeBSD 2.2.5 and earlier, does not properly restrict
source routed packets even when the (1) dosourceroute or
(2) forwarding variables are set, which allows remote
attackers to spoof TCP connections. Status: Entry
Reference: OPENBSD:Feb15,1998 "IP Source Routing
Problem"
Reference:
MISC:http://www.openbsd.org/advisories/sourceroute.txt
Reference: OSVDB:11502
Reference: URL:http://www.osvdb.org/11502
Reference: XF:bsd-sourceroute(736)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/736
Name: CVE-1999-0308
Description:
HP-UX gwind program allows users to modify arbitrary
files. Status: Entry
Reference: HP:HPSBUX9410-018
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9410-018
Reference: XF:hpux-gwind-overwrite
Reference: CIAC:H-03: HP-UX suid Vulnerabilities
Name: CVE-1999-0309
Description:
HP-UX vgdisplay program gives root access to local
users. Status: Entry
Reference: HP:HPSBUX9702-056
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-056
Reference: XF:hpux-vgdisplay
Reference: CIAC:H-27: HP-UX vgdisplay Buffer
Overrun Vulnerability
Name: CVE-1999-0310
Description:
SSH 1.2.25 on HP-UX allows access to new user accounts.
Status: Entry
Reference: XF:ssh-1225
Name: CVE-1999-0311
Description:
fpkg2swpk in HP-UX allows local users to gain root
access. Status: Entry
Reference: XF:hpux-fpkg2swpk
Reference: HP:HPSBUX9612-042
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9612-042
Name: CVE-1999-0312
Description:
HP ypbind allows attackers with root privileges to
modify NIS data. Status: Entry
Reference: XF:nis-ypbind
Reference:
CERT:CA-93:01.REVISED.HP.NIS.ypbind.vulnerability
Name: CVE-1999-0313
Description:
disk_bandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2
allows local users to gain root access using relative
pathnames. Status: Entry
Reference:
MISC:http://www.securityfocus.com/bid/213/exploit
Reference: SGI:19980701-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P
Reference: BID:214
Reference:
URL:http://www.securityfocus.com/bid/214
Reference: OSVDB:936
Reference: URL:http://www.osvdb.org/936
Reference: XF:sgi-disk-bandwidth(1441)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/1441
Name: CVE-1999-0314
Description:
ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows
local users to gain root access using relative
pathnames. Status: Entry
Reference:
MISC:http://www.securityfocus.com/bid/213/exploit
Reference: SGI:19980701-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P
Reference: BID:213
Reference:
URL:http://www.securityfocus.com/bid/213
Reference: OSVDB:6788
Reference: URL:http://www.osvdb.org/6788
Reference: XF:sgi-ioconfig(1199)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/1199
Name: CVE-1999-0315
Description:
Buffer overflow in Solaris fdformat command gives root
access to local users. Status: Entry
Reference: XF:fdformat-bo
Reference: SUN:00138
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/138
Name: CVE-1999-0316
Description:
Buffer overflow in Linux splitvt command gives root
access to local users. Status: Entry
Reference: XF:linux-splitvt
Reference: CIAC:G-08
Name: CVE-1999-0318
Description:
Buffer overflow in xmcd 2.0p12 allows local users to
gain access through an environmental variable.
Status: Entry
Reference: BUGTRAQ:19961125 Security Problems in
XMCD
Reference: BUGTRAQ:19961125 XMCD v2.1 released
(was: Security Problems in XMCD)
Reference: XF:xmcd-envbo
Name: CVE-1999-0320
Description:
SunOS rpc.cmsd allows attackers to obtain root access by
overwriting arbitrary files. Status: Entry
Reference: SUN:00166
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/166
Reference: XF:sun-rpc.cmsd
Name: CVE-1999-0321
Description:
Buffer overflow in Solaris kcms_configure command allows
local users to gain root access. Status: Entry
Reference: XF:sun-kcms-configure-bo
Name: CVE-1999-0322
Description:
The open() function in FreeBSD allows local attackers to
write to arbitrary files. Status: Entry
Reference: FREEBSD:FreeBSD-SA-97:05
Reference: XF:freebsd-open
Reference: OSVDB:6092
Reference: URL:http://www.osvdb.org/6092
Name: CVE-1999-0323
Description:
FreeBSD mmap function allows users to modify append-only
or immutable files. Status: Entry
Reference: FREEBSD:FreeBSD-SA-98:04
Reference: NETBSD:1998-003
Reference:
URL:ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1998-003.txt.asc
Reference: XF:bsd-mmap
Name: CVE-1999-0324
Description:
ppl program in HP-UX allows local users to create root
files through symlinks. Status: Entry
Reference: HP:HPSBUX9702-053
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-053
Reference: CIAC:H-31
Reference: XF:hp-ppllog
Name: CVE-1999-0325
Description:
vhe_u_mnt program in HP-UX allows local users to create
root files through symlinks. Status: Entry
Reference: XF:hp-vhe
Reference: HP:HPSBUX9406-013
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9406-013
Name: CVE-1999-0326
Description:
Vulnerability in HP-UX mediainit program. Status:
Entry
Reference: HP:HPSBUX9710-071
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9710-071
Reference: XF:hp-mediainit
Name: CVE-1999-0327
Description:
SGI syserr program allows local users to corrupt files.
Status: Entry
Reference: SGI:19971103-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX
Reference: XF:sgi-syserr
Name: CVE-1999-0328
Description:
SGI permissions program allows local users to gain root
privileges. Status: Entry
Reference: SGI:19971103-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX
Reference: XF:sgi-permtool
Name: CVE-1999-0329
Description:
SGI mediad program allows local users to gain root
access. Status: Entry
Reference: SGI:19980602-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980602-01-PX
Reference: XF:sgi-mediad
Name: CVE-1999-0332
Description:
Buffer overflow in NetMeeting allows denial of service
and remote command execution. Status: Entry
Reference: XF:nt-netmeeting
Reference: MSKB:Q184346
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q184346
Name: CVE-1999-0334
Description:
In Solaris 2.2 and 2.3, when fsck fails on startup, it
allows a local user with physical access to obtain root
access. Status: Entry
Reference: XF:sol-startup
Reference:
CERT:CA-93.19.Solaris.Startup.vulnerability
Name: CVE-1999-0335
Description:
DEPRECATED. This entry has been deprecated. It is a
duplicate of CVE-1999-0032. Status: Entry
Name: CVE-1999-0337
Description:
AIX batch queue (bsh) allows local and remote users to
gain additional privileges when network printing is
enabled. Status: Entry
Reference:
CERT:CA-94.10.IBM.AIX.bsh.vulnerability.html
Reference: XF:ibm-bsh
Name: CVE-1999-0338
Description:
AIX Licensed Program Product performance tools allow
local users to gain root access. Status: Entry
Reference: XF:ibm-perf-tools
Reference: CERT:CA-94.03.AIX.performance.tools
Name: CVE-1999-0339
Description:
Buffer overflow in the libauth library in Solaris allows
local users to gain additional privileges, possibly root
access. Status: Entry
Reference: XF:sol-sun-libauth
Reference: RSI:RSI.0007.05-26-98
Name: CVE-1999-0340
Description:
Buffer overflow in Linux Slackware crond program allows
local users to gain root access. Status: Entry
Reference: KSRT:005
Reference: XF:linux-crond
Name: CVE-1999-0341
Description:
Buffer overflow in the Linux mail program "deliver"
allows local users to gain root access. Status:
Entry
Reference: KSRT:006
Reference: XF:linux-deliver
Name: CVE-1999-0342
Description:
Linux PAM modules allow local users to gain root access
using temporary files. Status: Entry
Reference:
REDHAT:http://www.redhat.com/corp/support/errata/rh42-errata-general.html#pam
Reference: XF:linux-pam-passwd-tmprace
Name: CVE-1999-0343
Description:
A malicious Palace server can force a client to execute
arbitrary programs. Status: Entry
Reference: BUGTRAQ:19981002 Announcements from
The Palace (fwd)
Reference: XF:palace-malicious-servers-vuln
Name: CVE-1999-0344
Description:
NT users can gain debug-level access on a system process
using the Sechole exploit. Status: Entry
Reference: MS:MS98-009
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms98-009.mspx
Reference: MSKB:Q190288
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q190288
Reference: XF:nt-priv-fix
Name: CVE-1999-0346
Description:
CGI PHP mlog script allows an attacker to read any file
on the target server. Status: Entry
Reference: BUGTRAQ:19971019 Vulnerability in PHP
Example Logging Scripts
Reference: BID:713
Reference:
URL:http://www.securityfocus.com/bid/713
Reference: XF:http-cgi-php-mlog
Reference: OSVDB:3397
Reference: URL:http://www.osvdb.org/3397
Name: CVE-1999-0348
Description:
IIS ASP caching problem releases sensitive information
when two virtual servers share the same physical
directory. Status: Entry
Reference: NTBUGTRAQ:Jan27,1999
Reference: MSKB:Q197003
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q197003
Reference: OSVDB:930
Reference: URL:http://www.osvdb.org/930
Name: CVE-1999-0349
Description:
A buffer overflow in the FTP list (ls) command in IIS
allows remote attackers to conduct a denial of service
and, in some cases, execute arbitrary commands.
Status: Entry
Reference: EEYE:IIS Remote FTP Exploit/DoS Attack
Reference:
URL:http://www.eeye.com/html/Research/Advisories/IIS
Remote FTP Exploit/DoS Attack.html
Reference: MS:MS99-003
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-003.mspx
Reference: MSKB:Q188348
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q188348
Reference: BUGTRAQ:Jan27,1999
Reference: XF:iis-remote-ftp
Name: CVE-1999-0350
Description:
Race condition in the db_loader program in ClearCase
gives local users root access by setting SUID bits.
Status: Entry
Reference: L0PHT:Feb8,1999
Reference: XF:clearcase-temp-race
Name: CVE-1999-0351
Description:
FTP PASV "Pizza Thief" denial of service and
unauthorized data access. Attackers can steal data by
connecting to a port that was intended for use by a
client. Status: Entry
Reference: INFOWAR:01
Reference:
MISC:http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt
Reference: XF:pasv-pizza-thief-dos(3389)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/3389
Name: CVE-1999-0353
Description:
rpc.pcnfsd in HP gives remote root access by changing
the permissions on the main printer spool directory.
Status: Entry
Reference: HP:HPSBUX9902-091
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9902-091
Reference: CIAC:J-026
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-026.shtml
Reference: XF:pcnfsd-world-write
Name: CVE-1999-0355
Description:
Local or remote users can force ControlIT 4.5 to reboot
or force a user to log out, resulting in a denial of
service. Status: Entry
Reference: ISS:Multiple vulnerabilities in
ControlIT(tm) (formerly Remotely Possible/32) enterprise
management software
Reference: XF:controlit-reboot
Name: CVE-1999-0357
Description:
Windows 98 and other operating systems allows remote
attackers to cause a denial of service via crafted
"oshare" packets, possibly involving invalid
fragmentation offsets. Status: Entry
Reference: BUGTRAQ:19990125 Win98 crash?
Reference: XF:win98-oshare-dos
Name: CVE-1999-0358
Description:
Digital Unix 4.0 has a buffer overflow in the inc
program of the mh package. Status: Entry
Reference: BUGTRAQ:19990125 Digital Unix 4.0
exploitable buffer overflows
Reference:
URL:http://www.securityfocus.com/archive/1/12121
Reference: COMPAQ:SSRT0583U
Reference: XF:du-inc
Reference: CIAC:J-027
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-027.shtml
Name: CVE-1999-0362
Description:
WS_FTP server remote denial of service through cwd
command. Status: Entry
Reference: EEYE:AD02021999
Reference:
URL:http://www.eeye.com/html/Research/Advisories/AD02021999.html
Reference: XF:wsftp-remote-dos
Reference: BID:217
Reference:
URL:http://www.securityfocus.com/bid/217
Name: CVE-1999-0363
Description:
SuSE 5.2 PLP lpc program has a buffer overflow that
leads to root compromise. Status: Entry
Reference: BUGTRAQ:Feb02,1999
Reference: XF:plp-lpc-bo
Reference: BID:328
Reference:
URL:http://www.securityfocus.com/bid/328
Name: CVE-1999-0365
Description:
The metamail package allows remote command execution
using shell metacharacters that are not quoted in a
mailcap entry. Status: Entry
Reference: BUGTRAQ:Feb04,1999
Reference: XF:metamail-header-commands
Name: CVE-1999-0366
Description:
In some cases, Service Pack 4 for Windows NT 4.0 can
allow access to network shares using a blank password,
through a problem with a null NT hash value. Status:
Entry
Reference: MS:MS99-004
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-004.mspx
Reference: MSKB:Q214840
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q214840
Reference: XF:nt-sp4-auth-error
Name: CVE-1999-0367
Description:
NetBSD netstat command allows local users to access
kernel memory. Status: Entry
Reference: NETBSD:1999-002
Reference: OSVDB:7571
Reference: URL:http://www.osvdb.org/7571
Name: CVE-1999-0368
Description:
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD
lead to remote root access, a.k.a. palmetto. Status:
Entry
Reference: NETECT:palmetto.ftpd
Reference: CERT:CA-99.03
Reference: XF:palmetto-ftpd-bo
Name: CVE-1999-0369
Description:
The Sun sdtcm_convert calendar utility for OpenWindows
has a buffer overflow which can gain root access.
Status: Entry
Reference: SUN:00183
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/183
Reference: XF:sun-sdtcm-convert-bo
Name: CVE-1999-0371
Description:
Lynx allows a local user to overwrite sensitive files
through /tmp symlinks. Status: Entry
Reference: BUGTRAQ:19990211 Lynx /tmp problem
Reference: CERT:VB-97.05.lynx
Reference: XF:lynx-temp-files-race
Name: CVE-1999-0372
Description:
The installer for BackOffice Server includes account
names and passwords in a setup file (reboot.ini) which
is not deleted. Status: Entry
Reference: MS:MS99-005
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-005.mspx
Reference: XF:nt-backoffice-setup
Reference: MSKB:Q217004
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q217004
Name: CVE-1999-0373
Description:
Buffer overflow in the "Super" utility in Debian
GNU/Linux, and other operating systems, allows local
users to execute commands as root. Status: Entry
Reference: ISS:Buffer Overflow in "Super" package
in Debian Linux
Reference: XF:linux-super-bo
Reference: XF:linux-super-logging-bo
Name: CVE-1999-0374
Description:
Debian GNU/Linux cfengine package is susceptible to a
symlink attack. Status: Entry
Reference: DEBIAN:19990215
Reference: BUGTRAQ:Feb16,1999
Reference: XF:linux-cfengine-symlinks
Name: CVE-1999-0375
Description:
Buffer overflow in webd in Network Flight Recorder (NFR)
2.0.2-Research allows remote attackers to execute
commands. Status: Entry
Reference: NAI:February 16, 1999
Reference: BUGTRAQ:Feb16,1999
Reference: XF:nfr-webd-overflow
Name: CVE-1999-0376
Description:
Local users in Windows NT can obtain administrator
privileges by changing the KnownDLLs list to reference
malicious programs. Status: Entry
Reference: MS:MS99-006
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-006.mspx
Reference: BUGTRAQ:Feb20,1999
Reference: L0PHT:Feb18,1999
Reference: XF:nt-knowndlls-list
Name: CVE-1999-0377
Description:
Process table attack in Unix systems allows a remote
attacker to perform a denial of service by filling a
machine's process tables through multiple connections to
network services. Status: Entry
Reference: BUGTRAQ:Feb22,1999
Name: CVE-1999-0378
Description:
InterScan VirusWall for Solaris doesn't scan files for
viruses when a single HTTP request includes two GET
commands. Status: Entry
Reference: BUGTRAQ:19990222 BlackHats Advisory --
InterScan VirusWall
Reference: BUGTRAQ:19990225 Patch for InterScan
VirusWall for Unix now available
Reference: XF:viruswall-http-request
Reference: OSVDB:6167
Reference: URL:http://www.osvdb.org/6167
Name: CVE-1999-0379
Description:
Microsoft Taskpads allows remote web sites to execute
commands on the visiting user's machine via certain
methods that are marked as Safe for Scripting.
Status: Entry
Reference: MS:MS99-007
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-007.mspx
Reference: BUGTRAQ:19990223 Microsoft Security
Bulletin (MS99-007)
Reference: BID:498
Reference:
URL:http://www.securityfocus.com/bid/498
Reference: OSVDB:1019
Reference: URL:http://www.osvdb.org/1019
Reference: XF:win-resourcekit-taskpads
Name: CVE-1999-0380
Description:
SLMail 3.1 and 3.2 allows local users to access any file
in the NTFS file system when the Remote Administration
Service (RAS) is enabled by setting a user's Finger File
to point to the target file, then running finger on the
user. Status: Entry
Reference: NTBUGTRAQ:199902225 ALERT: SLMail 3.2
(and 3.1) with the Remote Administration Service
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91999015212415&w=2
Reference: BUGTRAQ:19990225 ALERT: SLMail 3.2
(and 3.1) with the Remote Administration Service
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91996412724720&w=2
Reference: NTBUGTRAQ:SLmail 3.2 Build 3113 (Web
Administration Security Fix)
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92110501504997&w=2
Reference: BID:497
Reference:
URL:http://www.securityfocus.com/bid/497
Reference: XF:slmail-ras-ntfs-bypass(5392)
Reference:
URL:http://xforce.iss.net/static/5392.php
Name: CVE-1999-0382
Description:
The screen saver in Windows NT does not verify that its
security context has been changed properly, allowing
attackers to run programs with elevated privileges.
Status: Entry
Reference: MS:MS99-008
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-008.mspx
Reference: XF:nt-screen-saver
Name: CVE-1999-0383
Description:
ACC Tigris allows public access without a login.
Status: Entry
Reference: BUGTRAQ:19990103 Tigris vulnerability
Reference: BID:183
Reference:
URL:http://www.securityfocus.com/bid/183
Reference: OSVDB:267
Reference: URL:http://www.osvdb.org/267
Reference: XF:acc-tigris-login
Name: CVE-1999-0384
Description:
The Forms 2.0 ActiveX control (included with Visual
Basic for Applications 5.0) can be used to read text
from a user's clipboard when the user accesses documents
with ActiveX content. Status: Entry
Reference: XF:forms-vuln-patch
Reference: MS:MS99-001
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-001.mspx
Name: CVE-1999-0385
Description:
The LDAP bind function in Exchange 5.5 has a buffer
overflow that allows a remote attacker to conduct a
denial of service or execute commands. Status:
Entry
Reference: MS:MS99-009
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-009.mspx
Reference: ISS:LDAP Buffer overflow against
Microsoft Directory Services
Reference: XF:ldap-exchange-overflow
Reference: XF:ldap-mds-dos
Name: CVE-1999-0386
Description:
Microsoft Personal Web Server and FrontPage Personal Web
Server in some Windows systems allows a remote attacker
to read files on the server by using a nonstandard URL.
Status: Entry
Reference: MS:MS99-010
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-010.mspx
Reference: XF:pws-file-access
Reference: OSVDB:111
Reference: URL:http://www.osvdb.org/111
Name: CVE-1999-0387
Description:
A legacy credential caching mechanism used in Windows 95
and Windows 98 systems allows attackers to read
plaintext network passwords. Status: Entry
Reference: MS:MS99-052
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-052.asp
Reference: MSKB:Q168115
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q168115
Reference: BID:829
Reference:
URL:http://www.securityfocus.com/bid/829
Reference: XF:9x-plaintext-pwd
Name: CVE-1999-0388
Description:
DataLynx suGuard trusts the PATH environment variable to
execute the ps command, allowing local users to execute
commands as root. Status: Entry
Reference: XF:datalynx-suguard-relative-paths
Reference: L0PHT:Jan3,1999
Reference: OSVDB:3186
Reference: URL:http://www.osvdb.org/3186
Name: CVE-1999-0390
Description:
Buffer overflow in Dosemu Slang library in Linux.
Status: Entry
Reference: BUGTRAQ:19990104 Dosemu/S-Lang
Overflow + sploit
Reference: CALDERA:CSSA-1999-006.1
Reference:
URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-006.1.txt
Reference: BID:187
Reference:
URL:http://www.securityfocus.com/bid/187
Name: CVE-1999-0391
Description:
The cryptographic challenge of SMB authentication in
Windows 95 and Windows 98 can be reused, allowing an
attacker to replay the response and impersonate a user.
Status: Entry
Reference: L0PHT:Jan. 5, 1999
Name: CVE-1999-0392
Description:
Buffer overflow in Thomas Boutell's cgic library version
up to 1.05. Status: Entry
Reference: BUGTRAQ:Jan10,1999
Reference: XF:http-cgic-library-bo
Name: CVE-1999-0393
Description:
Remote attackers can cause a denial of service in
Sendmail 8.8.x and 8.9.2 by sending messages with a
large number of headers. Status: Entry
Reference: BUGTRAQ:19981212 ** Sendmail 8.9.2 DoS
- exploit ** get what you want!
Reference: BUGTRAQ:19990121 Sendmail 8.8.x/8.9.x
bugware
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91694391227372&w=2
Reference: XF:sendmail-parsing-redirection
Name: CVE-1999-0395
Description:
A race condition in the BackWeb Polite Agent Protocol
allows an attacker to spoof a BackWeb server. Status:
Entry
Reference: ISS:19990118 Vulnerability in the
BackWeb Polite Agent Protocol
Reference:
URL:http://xforce.iss.net/alerts/advise17.php
Reference: XF:backweb-polite-agent-protocol
Name: CVE-1999-0396
Description:
A race condition between the select() and accept() calls
in NetBSD TCP servers allows remote attackers to cause a
denial of service. Status: Entry
Reference: NETBSD:1999-001
Reference: OPENBSD:Feb17,1999
Reference: XF:netbsd-tcp-race
Name: CVE-1999-0402
Description:
wget 1.5.3 follows symlinks to change permissions of the
target file instead of the symlink itself. Status:
Entry
Reference: BUGTRAQ:Feb2,1999
Reference: XF:wget-permissions
Reference: DEBIAN:19990220
Name: CVE-1999-0403
Description:
A bug in Cyrix CPUs on Linux allows local users to
perform a denial of service. Status: Entry
Reference: BUGTRAQ:19990204 Cyrix bug: freeze in
hell, badboy
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91821080015725&w=2
Reference: XF:cyrix-hang
Name: CVE-1999-0404
Description:
Buffer overflow in the Mail-Max SMTP server for Windows
systems allows remote command execution. Status:
Entry
Reference: BUGTRAQ:Feb14,1999
Reference: XF:mailmax-bo
Name: CVE-1999-0405
Description:
A buffer overflow in lsof allows local users to obtain
root privilege. Status: Entry
Reference: HERT:002
Reference: BUGTRAQ:Feb18,1999
Reference: DEBIAN:19990220a
Reference: XF:lsof-bo
Reference: OSVDB:3163
Reference: URL:http://www.osvdb.org/3163
Name: CVE-1999-0407
Description:
By default, IIS 4.0 has a virtual directory /IISADMPWD
which contains files that can be used as proxies for
brute force password attacks, or to identify valid users
on the system. Status: Entry
Reference: BUGTRAQ:19990209 ALERT: IIS4 allows
proxied password attacks over NetBIOS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91983486431506&w=2
Reference: BUGTRAQ:19990209 Re: IIS4 allows
proxied password attacks over NetBIOS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92000623021036&w=2
Reference: XF:iis-iisadmpwd
Name: CVE-1999-0408
Description:
Files created from interactive shell sessions in Cobalt
RaQ microservers (e.g. .bash_history) are world
readable, and thus are accessible from the web server.
Status: Entry
Reference: BUGTRAQ:19990225 Cobalt root exploit
Reference: XF:cobalt-raq-history-exposure
Reference: BID:337
Reference:
URL:http://www.securityfocus.com/bid/337
Name: CVE-1999-0409
Description:
Buffer overflow in gnuplot in Linux version 3.5 allows
local users to obtain root access. Status: Entry
Reference: BUGTRAQ:19990304 Linux
/usr/bin/gnuplot overflow
Reference: XF:gnuplot-home-overflow
Reference: BID:319
Reference:
URL:http://www.securityfocus.com/bid/319
Name: CVE-1999-0410
Description:
The cancel command in Solaris 2.6 (i386) has a buffer
overflow that allows local users to obtain root access.
Status: Entry
Reference: BUGTRAQ:Mar5,1999
Reference: XF:sol-cancel
Reference: BID:293
Reference:
URL:http://www.securityfocus.com/bid/293
Name: CVE-1999-0412
Description:
In IIS and other web servers, an attacker can attack
commands as SYSTEM if the server is running as SYSTEM
and loading an ISAPI extension. Status: Entry
Reference: BUGTRAQ:Feb19,1999
Reference: XF:iis-isapi-execute
Reference: BID:501
Reference:
URL:http://www.securityfocus.com/bid/501
Name: CVE-1999-0413
Description:
A buffer overflow in the SGI X server allows local users
to gain root access through the X server font path.
Status: Entry
Reference: SGI:19990301-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19990301-01-PX
Reference: XF:irix-font-path-overflow
Name: CVE-1999-0414
Description:
In Linux before version 2.0.36, remote attackers can
spoof a TCP connection and pass data to the application
layer before fully establishing the connection.
Status: Entry
Reference: NAI:Linux Blind TCP Spoofing
Reference: XF:linux-blind-spoof
Name: CVE-1999-0415
Description:
The HTTP server in Cisco 7xx series routers 3.2 through
4.2 is enabled by default, which allows remote attackers
to change the router's configuration. Status:
Entry
Reference: ISS:19990311 Remote Reconfiguration
and Denial of Service Vulnerabilities in Cisco 700 ISDN
Routers
Reference: CISCO:19990311 Cisco 7xx TCP and HTTP
Vulnerabilities
Reference:
URL:http://www.cisco.com/warp/public/770/7xxconn-pub.shtml
Reference: CIAC:J-034
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/j-034.shtml
Reference: XF:cisco-router-commands
Reference: XF:cisco-web-config
Name: CVE-1999-0416
Description:
Vulnerability in Cisco 7xx series routers allows a
remote attacker to cause a system reload via a TCP
connection to the router's TELNET port. Status:
Entry
Reference: ISS:19990311 Remote Reconfiguration
and Denial of Service Vulnerabilities in Cisco 700 ISDN
Routers
Reference: CISCO:19990311 Cisco 7xx TCP and HTTP
Vulnerabilities
Reference:
URL:http://www.cisco.com/warp/public/770/7xxconn-pub.shtml
Reference: CIAC:J-034
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/j-034.shtml
Reference: XF:cisco-web-crash
Name: CVE-1999-0417
Description:
64 bit Solaris 7 procfs allows local users to perform a
denial of service. Status: Entry
Reference: BUGTRAQ:Mar9,1999
Reference: XF:solaris-psinfo-crash
Reference: BID:448
Reference:
URL:http://www.securityfocus.com/bid/448
Reference: OSVDB:1001
Reference: URL:http://www.osvdb.org/1001
Name: CVE-1999-0420
Description:
umapfs allows local users to gain root privileges by
changing their uid through a malicious mount_umap
program. Status: Entry
Reference: NETBSD:1999-006
Name: CVE-1999-0421
Description:
During a reboot after an installation of Linux Slackware
3.6, a remote attacker can obtain root access by logging
in to the root account without a password. Status:
Entry
Reference: ISS:Short-Term High-Risk Vulnerability
During Slackware 3.6 Network Installations
Reference: XF:linux-slackware-install
Reference: BID:338
Reference:
URL:http://www.securityfocus.com/bid/338
Reference: OSVDB:981
Reference: URL:http://www.osvdb.org/981
Name: CVE-1999-0422
Description:
In some cases, NetBSD 1.3.3 mount allows local users to
execute programs in some file systems that have the
"noexec" flag set. Status: Entry
Reference: NETBSD:1999-007
Name: CVE-1999-0423
Description:
Vulnerability in hpterm on HP-UX 10.20 allows local
users to gain additional privileges. Status:
Entry
Reference: HP:HPSBUX9903-093
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-093
Reference: XF:hp-hpterm-files
Name: CVE-1999-0424
Description:
talkback in Netscape 4.5 allows a local user to
overwrite arbitrary files of another user whose Netscape
crashes. Status: Entry
Reference: SUSE:Mar18,1999
Reference: XF:netscape-talkback-overwrite
Name: CVE-1999-0425
Description:
talkback in Netscape 4.5 allows a local user to kill an
arbitrary process of another user whose Netscape
crashes. Status: Entry
Reference: SUSE:Mar18,1999
Reference: XF:netscape-talkback-kill
Name: CVE-1999-0428
Description:
OpenSSL and SSLeay allow remote attackers to reuse SSL
sessions and bypass access controls. Status:
Entry
Reference: BUGTRAQ:19990322 OpenSSL/SSLeay
Security Alert
Reference: XF:ssl-session-reuse
Reference: OSVDB:3936
Reference: URL:http://www.osvdb.org/3936
Name: CVE-1999-0429
Description:
The Lotus Notes 4.5 client may send a copy of encrypted
mail in the clear across the network if the user does
not set the "Encrypt Saved Mail" preference. Status:
Entry
Reference: BUGTRAQ:19990323
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92221437025743&w=2
Reference: BUGTRAQ:19990324 Re: LNotes encryption
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92241547418689&w=2
Reference: BUGTRAQ:19990326 Lotus Notes
Encryption Bug
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92246997917866&w=2
Reference: BUGTRAQ:19990326 Re: Lotus Notes
security advisory
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92249282302994&w=2
Reference: XF:lotus-client-encryption
Name: CVE-1999-0430
Description:
Cisco Catalyst LAN switches running Catalyst 5000
supervisor software allows remote attackers to perform a
denial of service by forcing the supervisor module to
reload. Status: Entry
Reference: ISS:Remote Denial of Service
Vulnerability in Cisco Catalyst Series Ethernet Switches
Reference: CISCO:Cisco Catalyst Supervisor Remote
Reload
Reference: XF:cisco-catalyst-crash
Reference: OSVDB:1103
Reference: URL:http://www.osvdb.org/1103
Name: CVE-1999-0432
Description:
ftp on HP-UX 11.00 allows local users to gain
privileges. Status: Entry
Reference: HP:HPSBUX9903-094
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-094
Reference: XF:hp-ftp
Name: CVE-1999-0433
Description:
XFree86 startx command is vulnerable to a symlink
attack, allowing local users to create files in
restricted directories, possibly allowing them to gain
privileges or cause a denial of service. Status:
Entry
Reference: SUSE:Mar28,1999
Reference: BUGTRAQ:19990321 X11R6 NetBSD Security
Problem
Reference: XF:xfree86-temp-directories
Name: CVE-1999-0436
Description:
Domain Enterprise Server Management System (DESMS) in
HP-UX allows local users to gain privileges. Status:
Entry
Reference: HP:HPSBUX9903-095
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-095
Reference: XF:hp-desms-servers
Name: CVE-1999-0437
Description:
Remote attackers can perform a denial of service in
WebRamp systems by sending a malicious string to the
HTTP port. Status: Entry
Reference: ISS:WebRamp Denial of Service Attacks
Reference: XF:webramp-device-crash
Name: CVE-1999-0438
Description:
Remote attackers can perform a denial of service in
WebRamp systems by sending a malicious UDP packet to
port 5353, changing its IP address. Status: Entry
Reference: ISS:WebRamp Denial of Service Attacks
Reference: XF:webramp-ipchange
Name: CVE-1999-0439
Description:
Buffer overflow in procmail before version 3.12 allows
remote or local attackers to execute commands via
expansions in the procmailrc configuration file.
Status: Entry
Reference: BUGTRAQ:19990405 Re: [SECURITY] new
version of procmail with security fixes
Reference: DEBIAN:19990422
Reference: CALDERA:CSSA-1999:007
Reference: XF:procmail-overflow
Name: CVE-1999-0440
Description:
The byte code verifier component of the Java Virtual
Machine (JVM) allows remote execution through malicious
web pages. Status: Entry
Reference: BUGTRAQ:19990405 Security Hole in Java
2 (and JDK 1.1.x)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92333596624452&w=2
Reference:
CONFIRM:http://java.sun.com/pr/1999/03/pr990329-01.html
Reference: BID:1939
Reference:
URL:http://www.securityfocus.com/bid/1939
Reference: XF:java-unverified-code
Name: CVE-1999-0441
Description:
Remote attackers can perform a denial of service in
WinGate machines using a buffer overflow in the Winsock
Redirector Service. Status: Entry
Reference: EEYE:AD02221999
Reference:
URL:http://www.eeye.com/html/Research/Advisories/AD02221999.html
Reference: XF:wingate-redirector-dos
Reference: BID:509
Reference:
URL:http://www.securityfocus.com/bid/509
Name: CVE-1999-0442
Description:
Solaris ff.core allows local users to modify files.
Status: Entry
Reference: BUGTRAQ:19990107 really silly ff.core
exploit for Solaris
Reference: BUGTRAQ:19990108 ff.core exploit on
Solaris (2.)7
Reference: BUGTRAQ:19990408 Solaris7 and ff.core
Reference: BID:327
Reference:
URL:http://www.securityfocus.com/bid/327
Name: CVE-1999-0445
Description:
In Cisco routers under some versions of IOS 12.0 running
NAT, some packets may not be filtered by input access
list filters. Status: Entry
Reference: CISCO:Cisco IOS(R) Software Input
Access List Leakage with NAT
Reference: XF:cisco-natacl-leakage
Reference: OSVDB:1104
Reference: URL:http://www.osvdb.org/1104
Name: CVE-1999-0446
Description:
Local users can perform a denial of service in NetBSD
1.3.3 and earlier versions by creating an unusual
symbolic link with the ln command, triggering a bug in
VFS. Status: Entry
Reference: NETBSD:1999-008
Reference: XF:netbsd-vfslocking-panic
Reference: OSVDB:7051
Reference: URL:http://www.osvdb.org/7051
Name: CVE-1999-0447
Description:
Local users can gain privileges using the debug utility
in the MPE/iX operating system. Status: Entry
Reference: HP:HPSBMP9904-006
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMP9904-006
Reference: XF:mpeix-debug
Name: CVE-1999-0448
Description:
IIS 4.0 and Apache log HTTP request methods, regardless
of how long they are, allowing a remote attacker to hide
the URL they really request. Status: Entry
Reference: BUGTRAQ:19990121 IIS 4 Request Logging
Security Advisory
Reference: XF:iis-http-request-logging
Name: CVE-1999-0449
Description:
The ExAir sample site in IIS 4 allows remote attackers
to cause a denial of service (CPU consumption) via a
direct request to the (1) advsearch.asp, (2) query.asp,
or (3) search.asp scripts. Status: Entry
Reference: BUGTRAQ:19990126 IIS 4 Advisory -
ExAir sample site DoS
Reference: NTBUGTRAQ:19990126 IIS 4 Advisory -
ExAir sample site DoS
Reference: BUGTRAQ:19990125 Re: [NTSEC] IIS 4
Advisory - ExAir sample site DoS
Reference: BID:193
Reference:
URL:http://www.securityfocus.com/bid/193
Reference: OSVDB:2
Reference: URL:http://www.osvdb.org/2
Reference: OSVDB:3
Reference: URL:http://www.osvdb.org/3
Reference: OSVDB:4
Reference: URL:http://www.osvdb.org/4
Reference: XF:iis-exair-dos
Name: CVE-1999-0457
Description:
Linux ftpwatch program allows local users to gain root
privileges. Status: Entry
Reference: BUGTRAQ:Jan17,1999
Reference: DEBIAN:19990117
Reference: XF:ftpwatch-vuln
Reference: BID:317
Reference:
URL:http://www.securityfocus.com/bid/317
Name: CVE-1999-0458
Description:
L0phtcrack 2.5 used temporary files in the system TEMP
directory which could contain password information.
Status: Entry
Reference: BUGTRAQ:Jan6,1999
Reference: XF:l0phtcrack-temp-files
Reference: OSVDB:915
Reference: URL:http://www.osvdb.org/915
Name: CVE-1999-0463
Description:
Remote attackers can perform a denial of service using
IRIX fcagent. Status: Entry
Reference: SGI:19981201-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19981201-01-PX
Reference: XF:sgi-fcagent-dos
Name: CVE-1999-0464
Description:
Local users can perform a denial of service in Tripwire
1.2 and earlier using long filenames. Status:
Entry
Reference: BUGTRAQ:19990104 Tripwire mess..
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91553066310826&w=2
Reference:
CONFIRM:http://marc.theaimsgroup.com/?l=bugtraq&m=91592136122066&w=2
Reference: OSVDB:6609
Reference: URL:http://www.osvdb.org/6609
Name: CVE-1999-0466
Description:
The SVR4 /dev/wabi special device file in NetBSD 1.3.3
and earlier allows a local user to read or write
arbitrary files on the disk associated with that device.
Status: Entry
Reference: NETBSD:1999-009
Reference: OSVDB:905
Reference: URL:http://www.osvdb.org/905
Name: CVE-1999-0468
Description:
Internet Explorer 5.0 allows a remote server to read
arbitrary files on the client's file system using the
Microsoft Scriptlet Component. Status: Entry
Reference: MS:MS99-012
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-012.asp
Reference: XF:ie-scriplet-fileread
Reference: BUGTRAQ:Apr9,1999
Name: CVE-1999-0470
Description:
A weak encryption algorithm is used for passwords in
Novell Remote.NLM, allowing them to be easily decrypted.
Status: Entry
Reference: BUGTRAQ:19990409 New Novell Remote.NLM
Password Decryption Algorithm with Exploit
Reference: BID:482
Reference:
URL:http://www.securityfocus.com/bid/482
Reference: XF:netware-remotenlm-passwords
Name: CVE-1999-0471
Description:
The remote proxy server in Winroute allows a remote
attacker to reconfigure the proxy without authentication
through the "cancel" button. Status: Entry
Reference: XF:winroute-config
Reference: BUGTRAQ:Apr9,1999
Name: CVE-1999-0472
Description:
The SNMP default community name "public" is not properly
removed in NetApps C630 Netcache, even if the
administrator tries to disable it. Status: Entry
Reference: XF:netcache-snmp
Reference: BUGTRAQ:Apr7,1999
Name: CVE-1999-0473
Description:
The rsync command before rsync 2.3.1 may inadvertently
change the permissions of the client's working directory
to the permissions of the directory being transferred.
Status: Entry
Reference: BUGTRAQ:19990407 rsync 2.3.1 release -
security fix
Reference: CALDERA:CSSA-1999:010.0
Reference: DEBIAN:19990823
Reference: BID:145
Reference:
URL:http://www.securityfocus.com/bid/145
Reference: XF:rsync-permissions
Name: CVE-1999-0474
Description:
The ICQ Webserver allows remote attackers to use .. to
access arbitrary files outside of the user's personal
directory. Status: Entry
Reference: XF:icq-webserver-read
Reference: BUGTRAQ:Apr5,1999
Name: CVE-1999-0475
Description:
A race condition in how procmail handles .procmailrc
files allows a local user to read arbitrary files
available to the user who is running procmail.
Status: Entry
Reference: XF:procmail-race
Reference: BUGTRAQ:Apr5,1999
Name: CVE-1999-0478
Description:
Denial of service in HP-UX sendmail 8.8.6 related to
accepting connections. Status: Entry
Reference: HP:HPSBUX9904-097
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9904-097
Reference: XF:sendmail-headers-dos
Name: CVE-1999-0479
Description:
Denial of service Netscape Enterprise Server with
VirtualVault on HP-UX VVOS systems. Status: Entry
Reference: HP:HPSBUX9903-092
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-092
Reference: XF:netscape-server-dos
Name: CVE-1999-0481
Description:
Denial of service in "poll" in OpenBSD. Status:
Entry
Reference: OPENBSD:Mar22,1999
Reference: OSVDB:7556
Reference: URL:http://www.osvdb.org/7556
Name: CVE-1999-0482
Description:
OpenBSD kernel crash through TSS handling, as caused by
the crashme program. Status: Entry
Reference: OPENBSD:Mar21,1999
Reference: OSVDB:7557
Reference: URL:http://www.osvdb.org/7557
Name: CVE-1999-0483
Description:
OpenBSD crash using nlink value in FFS and EXT2FS
filesystems. Status: Entry
Reference: OPENBSD:Feb25,1999
Reference: OSVDB:6129
Reference: URL:http://www.osvdb.org/6129
Name: CVE-1999-0484
Description:
Buffer overflow in OpenBSD ping. Status: Entry
Reference: OPENBSD:Feb23,1999
Reference: OSVDB:6130
Reference: URL:http://www.osvdb.org/6130
Name: CVE-1999-0485
Description:
Remote attackers can cause a system crash through
ipintr() in ipq in OpenBSD. Status: Entry
Reference: OPENBSD:Feb19,1999
Reference: XF:openbsd-ipintr-race
Reference: OSVDB:7558
Reference: URL:http://www.osvdb.org/7558
Name: CVE-1999-0487
Description:
The DHTML Edit ActiveX control in Internet Explorer
allows remote attackers to read arbitrary files.
Status: Entry
Reference: MS:MS99-011
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-011.mspx
Reference: XF:ie-dhtml-control
Name: CVE-1999-0491
Description:
The prompt parsing in bash allows a local user to
execute commands as another user by creating a directory
with the name of the command to execute. Status:
Entry
Reference: BUGTRAQ:19990420 Bash Bug
Reference:
URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.10.9904202114070.6623-100000@smooth.Operator.org
Reference: CALDERA:CSSA-1999-008.0
Reference:
URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-008.0.txt
Reference: BID:119
Reference:
URL:http://www.securityfocus.com/bid/119
Name: CVE-1999-0493
Description:
rpc.statd allows remote attackers to forward RPC calls
to the local operating system via the SM_MON and
SM_NOTIFY commands, which in turn could be used to
remotely exploit other bugs such as in automountd.
Status: Entry
Reference: CERT:CA-99-05
Reference:
URL:http://www.cert.org/advisories/CA-99-05-statd-automountd.html
Reference: SUN:00186
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/186&type=0&nav=sec.sba
Reference: CIAC:J-045
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-045.shtml
Reference: BUGTRAQ:19990103 SUN almost has a
clue! (automountd)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91547759121289&w=2
Reference: BID:450
Reference:
URL:http://www.securityfocus.com/bid/450
Name: CVE-1999-0494
Description:
Denial of service in WinGate proxy through a buffer
overflow in POP3. Status: Entry
Reference: XF:wingate-pop3-user-bo
Name: CVE-1999-0496
Description:
A Windows NT 4.0 user can gain administrative rights by
forcing NtOpenProcessToken to succeed regardless of the
user's permissions, aka GetAdmin. Status: Entry
Reference: MSKB:Q146965
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q146965
Reference: XF:nt-getadmin
Reference: XF:nt-getadmin-present
Name: CVE-1999-0513
Description:
ICMP messages to broadcast addresses are allowed,
allowing for a Smurf attack that can cause a denial of
service. Status: Entry
Reference: CERT:CA-98.01.smurf
Reference: FREEBSD:FreeBSD-SA-98:06
Reference: XF:smurf
Name: CVE-1999-0514
Description:
UDP messages to broadcast addresses are allowed,
allowing for a Fraggle attack that can cause a denial of
service by flooding the target. Status: Entry
Reference: XF:fraggle
Name: CVE-1999-0526
Description:
An X server's access control is disabled (e.g. through
an "xhost +" command) and allows anyone to connect to
the server. Status: Entry
Reference: XF:xcheck-keystroke
Reference: CERT-VN:VU#704969
Reference:
URL:http://www.kb.cert.org/vuls/id/704969
Name: CVE-1999-0551
Description:
HP OpenMail can be misconfigured to allow users to run
arbitrary commands using malicious print requests.
Status: Entry
Reference: HP:HPSBUX9804-078
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9804-078
Reference: XF:hp-openmail
Name: CVE-1999-0566
Description:
An attacker can write to syslog files from any location,
causing a denial of service by filling up the logs, and
hiding activities. Status: Entry
Reference: XF:ibm-syslogd
Reference: XF:syslog-flood
Name: CVE-1999-0608
Description:
An incorrect configuration of the PDG Shopping Cart CGI
program "shopper.cgi" could disclose private
information. Status: Entry
Reference: BUGTRAQ:19990420 Shopping Carts
exposing CC data
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92462991805485&w=2
Reference:
CONFIRM:http://www.pdgsoft.com/Security/security.html.
Reference: XF:pdgsoftcart-misconfig(3857)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/3857
Name: CVE-1999-0612
Description:
A version of finger is running that exposes valid user
information to any entity on the network. Status:
Entry
Reference: XF:finger-out
Reference: XF:finger-running
Name: CVE-1999-0626
Description:
A version of rusers is running that exposes valid user
information to any entity on the network. Status:
Entry
Reference: XF:rusersd
Reference: XF:ruser
Name: CVE-1999-0627
Description:
The rexd service is running, which uses weak
authentication that can allow an attacker to execute
commands. Status: Entry
Reference: XF:rexd
Name: CVE-1999-0628
Description:
The rwho/rwhod service is running, which exposes machine
status and user information. Status: Entry
Reference: XF:rwhod
Name: CVE-1999-0668
Description:
The scriptlet.typelib ActiveX control is marked as "safe
for scripting" for Internet Explorer, which allows a
remote attacker to execute arbitrary commands as
demonstrated by Bubbleboy. Status: Entry
Reference: BUGTRAQ:19990821 IE 5.0 allows
executing programs
Reference: MS:MS99-032
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-032.asp
Reference: CIAC:J-064
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/j-064.shtml
Reference: BID:598
Reference:
URL:http://www.securityfocus.com/bid/598
Reference: XF:ms-scriptlet-eyedog-unsafe
Reference: MSKB:Q240308
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q240308
Name: CVE-1999-0671
Description:
Buffer overflow in ToxSoft NextFTP client through CWD
command. Status: Entry
Reference: BID:572
Reference:
URL:http://www.securityfocus.com/bid/572
Reference: XF:toxsoft-nextftp-cwd-bo
Name: CVE-1999-0672
Description:
Buffer overflow in Fujitsu Chocoa IRC client via IRC
channel topics. Status: Entry
Reference: XF:fujitsu-topic-bo
Reference: BID:573
Reference:
URL:http://www.securityfocus.com/bid/573
Name: CVE-1999-0674
Description:
The BSD profil system call allows a local user to modify
the internal data space of a program via profiling and
execve. Status: Entry
Reference: NETBSD:1999-011
Reference: OPENBSD:Aug 9,1999
Reference: FREEBSD:FreeBSD-SA-99:02
Reference: BUGTRAQ:19990809 profil(2) bug, a
simple test program
Reference: BID:570
Reference:
URL:http://www.securityfocus.com/bid/570
Reference: CIAC:J-067
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-067.shtml
Reference: XF:netbsd-profil
Name: CVE-1999-0675
Description:
Check Point FireWall-1 can be subjected to a denial of
service via UDP packets that are sent through VPN-1 to
port 0 of a host. Status: Entry
Reference: BUGTRAQ:19990809 FW1 UDP Port 0 DoS
Reference:
URL:http://www.securityfocus.com/archive/1/23615
Reference: BID:576
Reference:
URL:http://www.securityfocus.com/bid/576
Reference: XF:checkpoint-port
Reference: OSVDB:1038
Reference: URL:http://www.osvdb.org/1038
Name: CVE-1999-0676
Description:
sdtcm_convert in Solaris 2.6 allows a local user to
overwrite sensitive files via a symlink attack.
Status: Entry
Reference: BUGTRAQ:19990808 sdtcm_convert
Reference:
URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=19990809134220.A1191@hades.chaoz.org
Reference: XF:sun-sdtcm-convert
Reference: BID:575
Reference:
URL:http://www.securityfocus.com/bid/575
Name: CVE-1999-0678
Description:
A default configuration of Apache on Debian GNU/Linux
sets the ServerRoot to /usr/doc, which allows remote
users to read documentation files for the entire server.
Status: Entry
Reference: XF:apache-debian-usrdoc
Reference: BUGTRAQ:19990405 An issue with Apache
on Debian
Reference: BID:318
Reference:
URL:http://www.securityfocus.com/bid/318
Name: CVE-1999-0679
Description:
Buffer overflow in hybrid-6 IRC server commonly used on
EFnet allows remote attackers to execute commands via
m_invite invite option. Status: Entry
Reference: BUGTRAQ:19990813 w00w00's efnet ircd
advisory (exploit included)
Reference:
CONFIRM:http://www.efnet.org/archive/servers/hybrid/ChangeLog
Reference: BID:581
Reference:
URL:http://www.securityfocus.com/bid/581
Reference: XF:hybrid-ircd-minvite-bo
Name: CVE-1999-0680
Description:
Windows NT Terminal Server performs extra work when a
client opens a new connection but before it is
authenticated, allowing for a denial of service.
Status: Entry
Reference: MS:MS99-028
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-028.mspx
Reference: MSKB:Q238600
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238600
Reference: CIAC:J-057
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-057.shtml
Reference: BID:571
Reference:
URL:http://www.securityfocus.com/bid/571
Reference: XF:nt-terminal-dos
Name: CVE-1999-0681
Description:
Buffer overflow in Microsoft FrontPage Server Extensions
(PWS) 3.0.2.926 on Windows 95, and possibly other
versions, allows remote attackers to cause a denial of
service via a long URL. Status: Entry
Reference: BUGTRAQ:19990807 Crash FrontPage
Remotely...
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/1999-q3/0381.html
Reference: XF:frontpage-pws-dos
Reference:
URL:http://xforce.iss.net/static/3117.php
Reference: BID:568
Reference:
URL:http://www.securityfocus.com/bid/568
Name: CVE-1999-0682
Description:
Microsoft Exchange 5.5 allows a remote attacker to relay
email (i.e. spam) using encapsulated SMTP addresses,
even if the anti-relaying features are enabled.
Status: Entry
Reference: MS:MS99-027
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-027.mspx
Reference: MSKB:Q237927
Reference: URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237927
Reference: BID:567
Reference:
URL:http://www.securityfocus.com/bid/567
Reference: CIAC:J-056
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-056.shtml
Reference: XF:exchange-relay
Name: CVE-1999-0683
Description:
Denial of service in Gauntlet Firewall via a malformed
ICMP packet. Status: Entry
Reference: XF:gauntlet-dos
Reference: BUGTRAQ:19990729 Remotely Lock Up
Gauntlet 5.0
Reference: BID:556
Reference:
URL:http://www.securityfocus.com/bid/556
Reference: OSVDB:1029
Reference: URL:http://www.osvdb.org/1029
Name: CVE-1999-0685
Description:
Buffer overflow in Netscape Communicator via EMBED tags
in the pluginspage option. Status: Entry
Reference: BUGTRAQ:19991209 Netscape communicator
4.06J, 4.5J-4.6J, 4.61e Buffer Overflow
Reference: BID:618
Reference:
URL:http://www.securityfocus.com/bid/618
Name: CVE-1999-0686
Description:
Denial of service in Netscape Enterprise Server (NES) in
HP Virtual Vault (VVOS) via a long URL. Status:
Entry
Reference: BUGTRAQ:19990514 TGAD DoS
Reference: BUGTRAQ:19990610 Re: VVOS/Netscape Bug
Reference: HP:HPSBUX9906-098
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-098
Reference: CIAC:J-046
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-046.shtml
Reference: XF:hp-tgad-dos
Name: CVE-1999-0687
Description:
The ToolTalk ttsession daemon uses weak RPC
authentication, which allows a remote attacker to
execute commands. Status: Entry
Reference: BUGTRAQ:19990913 Vulnerability in
ttsession
Reference: SUN:00192
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/192
Reference: HP:HPSBUX9909-103
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103
Reference: COMPAQ:SSRT0617U_TTSESSION
Reference: CIAC:K-001
Reference:
URL:http://www.ciac.org/ciac/bulletins/k-001.shtml
Reference: CERT:CA-99-11
Reference: BID:637
Reference:
URL:http://www.securityfocus.com/bid/637
Reference: XF:cde-ttsession-rpc-auth
Name: CVE-1999-0688
Description:
Buffer overflows in HP Software Distributor (SD) for
HPUX 10.x and 11.x. Status: Entry
Reference: HP:HPSBUX9907-101
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-101
Reference: BID:545
Reference:
URL:http://www.securityfocus.com/bid/545
Reference: XF:hp-sd-bo
Name: CVE-1999-0689
Description:
The CDE dtspcd daemon allows local users to execute
arbitrary commands via a symlink attack. Status:
Entry
Reference: BUGTRAQ:19990913 Vulnerability in
dtspcd
Reference: SUN:00192
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/192
Reference: HP:HPSBUX9909-103
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103
Reference: CERT:CA-99-11
Reference: OVAL:oval:org.mitre.oval:def:1880
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1880
Reference: XF:cde-dtspcd-file-auth
Reference: BID:636
Reference:
URL:http://www.securityfocus.com/bid/636
Name: CVE-1999-0690
Description:
HP CDE program includes the current directory in root's
PATH variable. Status: Entry
Reference: HP:HPSBUX9907-100
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-100
Reference: CIAC:J-053
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-053.shtml
Reference: XF:hp-cde-directory
Name: CVE-1999-0691
Description:
Buffer overflow in the AddSuLog function of the CDE
dtaction utility allows local users to gain root
privileges via a long user name. Status: Entry
Reference: BUGTRAQ:19990913 Vulnerability in
dtaction
Reference: SUN:00192
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/192
Reference: HP:HPSBUX9909-103
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103
Reference: COMPAQ:SSRTO615U_DTACTION
Reference: CERT:CA-99-11
Reference: BID:635
Reference:
URL:http://www.securityfocus.com/bid/635
Reference: OVAL:oval:org.mitre.oval:def:3078
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3078
Reference: XF:cde-dtaction-username-bo
Name: CVE-1999-0692
Description:
The default configuration of the Array Services daemon
(arrayd) disables authentication, allowing remote users
to gain root privileges. Status: Entry
Reference: CERT:CA-99-09
Reference: CIAC:J-052
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-052.shtml
Reference: SGI:19990701-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19990701-01-P
Reference: XF:sgi-arrayd
Name: CVE-1999-0693
Description:
Buffer overflow in TT_SESSION environment variable in
ToolTalk shared library allows local users to gain root
privileges. Status: Entry
Reference: CERT:CA-99-11
Reference: SUN:00192
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/192
Reference: HP:HPSBUX9909-103
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103
Reference: BID:641
Reference:
URL:http://www.securityfocus.com/bid/641
Reference: OVAL:oval:org.mitre.oval:def:4374
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4374
Reference: XF:cde-dtsession-env-bo
Name: CVE-1999-0694
Description:
Denial of service in AIX ptrace system call allows local
users to crash the system. Status: Entry
Reference: CIAC:J-055
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-055.shtml
Reference: IBM:ERS-SVA-E01-1999:002.1
Reference: XF:aix-ptrace-halt
Name: CVE-1999-0695
Description:
The Sybase PowerDynamo personal web server allows
attackers to read arbitrary files through a .. (dot dot)
attack. Status: Entry
Reference: BUGTRAQ:19990904 [Sybase] software
vendors do not think about old bugs
Reference: XF:http-powerdynamo-dotdotslash
Reference: BID:620
Reference:
URL:http://www.securityfocus.com/bid/620
Reference: OSVDB:1064
Reference: URL:http://www.osvdb.org/1064
Name: CVE-1999-0696
Description:
Buffer overflow in CDE Calendar Manager Service Daemon
(rpc.cmsd). Status: Entry
Reference: BUGTRAQ:19990709 Exploit of rpc.cmsd
Reference: SCO:SB-99.12
Reference: SUN:00188
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/188
Reference: SUNBUG:4230754
Reference: HP:HPSBUX9908-102
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9908-102
Reference: COMPAQ:SSRT0614U_RPC_CMSD
Reference: CERT:CA-99-08
Reference: CIAC:J-051
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-051.shtml
Reference: XF:sun-cmsd-bo
Name: CVE-1999-0697
Description:
SCO Doctor allows local users to gain root privileges
through a Tools option. Status: Entry
Reference: BUGTRAQ:19990908 SCO 5.0.5 /bin/doctor
nightmare
Reference: BID:621
Reference:
URL:http://www.securityfocus.com/bid/621
Reference: XF:sco-doctor-execute
Name: CVE-1999-0699
Description:
The Bluestone Sapphire web server allows session
hijacking via easily guessable session IDs. Status:
Entry
Reference: BUGTRAQ:19990908 [Security] Spoofed Id
in Bluestone Sapphire/Web
Reference: BID:623
Reference:
URL:http://www.securityfocus.com/bid/623
Name: CVE-1999-0700
Description:
Buffer overflow in Microsoft Phone Dialer (dialer.exe),
via a malformed dialer entry in the dialer.ini file.
Status: Entry
Reference: MSKB:Q237185
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237185
Reference: MS:MS99-026
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-026.mspx
Reference: XF:nt-malformed-dialer
Name: CVE-1999-0701
Description:
After an unattended installation of Windows NT 4.0, an
installation file could include sensitive information
such as the local Administrator password. Status:
Entry
Reference: MS:MS99-036
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-036.mspx
Reference: MSKB:Q173039
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q173039
Reference: BID:626
Reference:
URL:http://www.securityfocus.com/bid/626
Reference: XF:nt-install-unattend-file
Name: CVE-1999-0702
Description:
Internet Explorer 5.0 and 5.01 allows remote attackers
to modify or execute files via the Import/Export
Favorites feature, aka the "ImportExportFavorites"
vulnerability. Status: Entry
Reference: BUGTRAQ:19990909 IE 5.0 security
vulnerabilities - ImportExportFavorites - at least
creating and overwriting files, probably executing
programs
Reference: MS:MS99-037
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-037.mspx
Reference: MSKB:Q241361
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241361
Reference: XF:ie5-import-export-favorites
Reference: BID:627
Reference:
URL:http://www.securityfocus.com/bid/627
Name: CVE-1999-0703
Description:
OpenBSD, BSDI, and other Unix operating systems allow
users to set chflags and fchflags on character and block
devices. Status: Entry
Reference: BUGTRAQ:19990805 4.4 BSD issue --
chflags
Reference: OPENBSD:Jul30,1999
Reference: FREEBSD:FreeBSD-SA-99:01
Reference: CIAC:J-066
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-066.shtml
Reference: XF:openbsd-chflags-fchflags-permitted
Name: CVE-1999-0704
Description:
Buffer overflow in Berkeley automounter daemon (amd)
logging facility provided in the Linux am-utils package
and others. Status: Entry
Reference: REDHAT:RHSA-1999:032-01
Reference: CALDERA:CSSA-1999:024.0
Reference: FREEBSD:SA-99:06
Reference: DEBIAN:19991018
Reference: BID:614
Reference:
URL:http://www.securityfocus.com/bid/614
Reference: CERT:CA-99-12
Reference: XF:amd-bo
Name: CVE-1999-0705
Description:
Buffer overflow in INN inews program. Status:
Entry
Reference: XF:inn-inews-bo
Reference: REDHAT:RHSA1999033_01
Reference: CALDERA:CSSA-1999-026
Reference: SUSE:19990831 Security hole in INN
Reference: DEBIAN:19990907
Reference: BID:616
Reference:
URL:http://www.securityfocus.com/bid/616
Name: CVE-1999-0706
Description:
Linux xmonisdn package allows local users to gain root
privileges by modifying the IFS or PATH environmental
variables. Status: Entry
Reference: DEBIAN:19990807
Reference: SUSE:19990817 Security hole in i4l
(xmonisdn)
Reference: BID:583
Reference:
URL:http://www.securityfocus.com/bid/583
Name: CVE-1999-0707
Description:
The default FTP configuration in HP Visualize Conference
allows conference users to send a file to other
participants without authorization. Status: Entry
Reference: HP:HPSBUX9906-099
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-099
Reference: CIAC:J-050
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-050.shtml
Reference: BID:493
Reference:
URL:http://www.securityfocus.com/bid/493
Reference: XF:hp-visualize-conference-ftp
Name: CVE-1999-0708
Description:
Buffer overflow in cfingerd allows local users to gain
root privileges via a long GECOS field. Status:
Entry
Reference: BUGTRAQ:19990921 BP9909-00: cfingerd
local buffer overflow
Reference: BID:651
Reference:
URL:http://www.securityfocus.com/bid/651
Name: CVE-1999-0710
Description:
The Squid package in Red Hat Linux 5.2 and 6.0, and
other distributions, installs cachemgr.cgi in a public
web directory, which allows remote attackers to use it
as an intermediary to connect to other systems.
Status: Entry
Reference: BUGTRAQ:19990725 Redhat 6.0
cachemgr.cgi lameness
Reference:
CONFIRM:http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid
Reference: DEBIAN:DSA-576
Reference:
URL:http://www.debian.org/security/2004/dsa-576
Reference: FEDORA:FEDORA-2005-373
Reference:
URL:http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html
Reference: FEDORA:FLSA-2006:152809
Reference:
URL:http://fedoranews.org/updates/FEDORA--.shtml
Reference: REDHAT:RHSA-1999:025
Reference:
URL:http://www.redhat.com/support/errata/RHSA-1999-025.html
Reference: REDHAT:RHSA-2005:489
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2005-489.html
Reference: BID:2059
Reference:
URL:http://www.securityfocus.com/bid/2059
Reference: XF:http-cgi-cachemgr(2385)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/2385
Name: CVE-1999-0711
Description:
The oratclsh interpreter in Oracle 8.x Intelligent Agent
for Unix allows local users to execute Tcl commands as
root. Status: Entry
Reference: BUGTRAQ:19990430 *Huge* security hole
in Oracle 8.0.5 with Intellegent agent installed
Reference:
URL:http://marc.theaimsgroup.com/?t=92550157100002&w=2&r=1
Reference: BUGTRAQ:19990506 Oracle Security
Followup, patch and FAQ: setuid on oratclsh
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92609807906778&w=2
Reference: XF:oracle-oratclsh
Name: CVE-1999-0713
Description:
The dtlogin program in Compaq Tru64 UNIX allows local
users to gain root privileges. Status: Entry
Reference: BUGTRAQ:19990404 Digital Unix 4.0E
/var permission
Reference: CIAC:J-044
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-044.shtml
Reference: XF:cde-dtlogin
Reference: COMPAQ:SSRT0600U
Name: CVE-1999-0714
Description:
Vulnerability in Compaq Tru64 UNIX edauth command.
Status: Entry
Reference: COMPAQ:SSRT0588U
Reference: XF:du-edauth
Name: CVE-1999-0715
Description:
Buffer overflow in Remote Access Service (RAS) client
allows an attacker to execute commands or cause a denial
of service via a malformed phonebook entry. Status:
Entry
Reference: BUGTRAQ:19990519 Buffer Overruns in
RAS allows execution of arbitary code as system
Reference: MS:MS99-016
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-016.mspx
Reference: MSKB:Q230677
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q230677
Reference: XF:nt-ras-bo
Name: CVE-1999-0716
Description:
Buffer overflow in Windows NT 4.0 help file utility via
a malformed help file. Status: Entry
Reference: XF:nt-helpfile-bo
Reference: MSKB:Q231605
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231605
Reference: MS:MS99-015
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-015.asp
Name: CVE-1999-0717
Description:
A remote attacker can disable the virus warning
mechanism in Microsoft Excel 97. Status: Entry
Reference: MS:MS99-014
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-014.mspx
Reference: MSKB:Q231304
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231304
Reference: XF:excel-virus-warning
Name: CVE-1999-0718
Description:
IBM GINA, when used for OS/2 domain authentication of
Windows NT users, allows local users to gain
administrator privileges by changing the GroupMapping
registry key. Status: Entry
Reference: NTBUGTRAQ:19990823 IBM Gina security
warning
Reference:
URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9908&L=ntbugtraq&F=&S=&P=5534
Reference: BID:608
Reference:
URL:http://www.securityfocus.com/bid/608
Reference: XF:ibm-gina-group-add
Reference:
URL:http://xforce.iss.net/static/3166.php
Name: CVE-1999-0719
Description:
The Guile plugin for the Gnumeric spreadsheet package
allows attackers to execute arbitrary code. Status:
Entry
Reference: BUGTRAQ:19990802 Gnumeric potential
security hole.
Reference: REDHAT:RHSA-1999:023-01
Reference: XF:gnu-guile-plugin-export
Reference: BID:563
Reference:
URL:http://www.securityfocus.com/bid/563
Name: CVE-1999-0720
Description:
The pt_chown command in Linux allows local users to
modify TTY terminal devices that belong to other users.
Status: Entry
Reference: BUGTRAQ:19990823 [Linux] glibc 2.1.x /
wu-ftpd <=2.5 / BeroFTPD / lynx / vlock / mc / glibc
2.0.x
Reference:
URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=lcamtuf.4.05.9907041223290.355-300000@nimue.ids.pl
Reference: BID:597
Reference:
URL:http://www.securityfocus.com/bid/597
Reference: XF:linux-pt-chown
Name: CVE-1999-0721
Description:
Denial of service in Windows NT Local Security Authority
(LSA) through a malformed LSA request. Status:
Entry
Reference: BINDVIEW:Phantom Technical Advisory
Reference: MSKB:Q231457
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231457
Reference: MS:MS99-020
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-020.mspx
Reference: CIAC:J-049
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-049.shtml
Reference: XF:msrpc-lsa-lookupnames-dos
Name: CVE-1999-0722
Description:
The default configuration of Cobalt RaQ2 servers allows
remote users to install arbitrary software packages.
Status: Entry
Reference: CERT:CA-99-10
Reference: BID:558
Reference:
URL:http://www.securityfocus.com/bid/558
Reference: XF:cobalt-raq2-default-config
Name: CVE-1999-0723
Description:
The Windows NT Client Server Runtime Subsystem (CSRSS)
can be subjected to a denial of service when all worker
threads are waiting for user input. Status: Entry
Reference: NTBUGTRAQ:19990411 Death by MessageBox
Reference: MS:MS99-021
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-021.mspx
Reference: MSKB:Q233323
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q233323
Reference: CIAC:J-049
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-049.shtml
Reference: BID:478
Reference:
URL:http://www.securityfocus.com/bid/478
Reference: XF:nt-csrss-dos
Name: CVE-1999-0724
Description:
Buffer overflow in OpenBSD procfs and fdescfs file
systems via uio_offset in the readdir() function.
Status: Entry
Reference: OPENBSD:Aug12,1999
Reference: XF:openbsd-uio_offset-bo
Reference: OSVDB:6128
Reference: URL:http://www.osvdb.org/6128
Name: CVE-1999-0725
Description:
When IIS is run with a default language of Chinese,
Korean, or Japanese, it allows a remote attacker to view
the source code of certain files, a.k.a. "Double Byte
Code Page". Status: Entry
Reference: MSKB:Q233335
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q233335
Reference: MS:MS99-022
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-022.mspx
Reference: BID:477
Reference:
URL:http://www.securityfocus.com/bid/477
Reference: XF:iis-double-byte-code-page(2302)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/2302
Name: CVE-1999-0726
Description:
An attacker can conduct a denial of service in Windows
NT by executing a program with a malformed file image
header. Status: Entry
Reference: MS:MS99-023
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-023.mspx
Reference: MSKB:Q234557
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q234557
Reference: BID:499
Reference:
URL:http://www.securityfocus.com/bid/499
Reference: XF:nt-malformed-image-header
Name: CVE-1999-0727
Description:
A kernel leak in the OpenBSD kernel allows IPsec packets
to be sent unencrypted. Status: Entry
Reference: OPENBSD:19990608 Packets that should
have been handled by IPsec may be transmitted as
cleartext
Reference: XF:openbsd-ipsec-cleartext
Reference: OSVDB:6127
Reference: URL:http://www.osvdb.org/6127
Name: CVE-1999-0728
Description:
A Windows NT user can disable the keyboard or mouse by
directly calling the IOCTLs which control them.
Status: Entry
Reference: MS:MS99-024
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-024.mspx
Reference: MSKB:Q236359
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q236359
Reference: XF:nt-ioctl-dos
Name: CVE-1999-0729
Description:
Buffer overflow in Lotus Notes LDAP (NLDAP) allows an
attacker to conduct a denial of service through the
ldap_search request. Status: Entry
Reference: ISS:19990823 Denial of Service Attack
against Lotus Notes Domino Server 4.6
Reference:
URL:http://xforce.iss.net/alerts/advise34.php
Reference: CIAC:J-061
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-061.shtml
Reference: BID:601
Reference:
URL:http://www.securityfocus.com/bid/601
Reference: XF:lotus-ldap-bo
Reference: OSVDB:1057
Reference: URL:http://www.osvdb.org/1057
Name: CVE-1999-0730
Description:
The zsoelim program in the Debian man-db package allows
local users to overwrite files via a symlink attack.
Status: Entry
Reference: DEBIAN:19990612
Name: CVE-1999-0731
Description:
The KDE klock program allows local users to unlock a
session using malformed input. Status: Entry
Reference: BUGTRAQ:19990623 Security flaw in
klock
Reference: CALDERA:CSSA-1999:017
Reference: SUSE:19990629 Security hole in Klock
Reference: BID:489
Reference:
URL:http://www.securityfocus.com/bid/489
Name: CVE-1999-0732
Description:
The logging facilitity of the Debian smtp-refuser
package allows local users to delete arbitrary files
using symbolic links. Status: Entry
Reference: DEBIAN:19990823b
Reference: XF:smtp-refuser-tmp
Name: CVE-1999-0733
Description:
Buffer overflow in VMWare 1.0.1 for Linux via a long
HOME environmental variable. Status: Entry
Reference: BUGTRAQ:19990626 VMWare Advisory -
buffer overflows
Reference: BUGTRAQ:19990626 VMware Security Alert
Reference: BUGTRAQ:19990705 Re: VMWare Advisory..
- exploit
Reference: BID:490
Reference:
URL:http://www.securityfocus.com/bid/490
Reference: XF:vmware-bo
Name: CVE-1999-0734
Description:
A default configuration of CiscoSecure Access Control
Server (ACS) allows remote users to modify the server
database without authentication. Status: Entry
Reference: CISCO: CiscoSecure Access Control
Server for UNIX Remote Administration Vulnerability
Reference: XF:ciscosecure-read-write
Name: CVE-1999-0735
Description:
KDE K-Mail allows local users to gain privileges via a
symlink attack in temporary user directories. Status:
Entry
Reference: ISS:KDE K-Mail File Creation
Vulnerability
Reference: CALDERA:CSSA-1999:016
Reference: REDHAT:RHSA-1999:015-01
Reference:
URL:http://www.redhat.com/support/errata/RHSA1999015_01.html
Reference: BID:300
Reference:
URL:http://www.securityfocus.com/bid/300
Name: CVE-1999-0740
Description:
Remote attackers can cause a denial of service on Linux
in.telnetd telnet daemon through a malformed TERM
environmental variable. Status: Entry
Reference: BID:594
Reference:
URL:http://www.securityfocus.com/bid/594
Reference: XF:linux-telnetd-term
Reference: CALDERA:CSSA-1999:022
Reference: REDHAT:RHSA1999029_01
Name: CVE-1999-0742
Description:
The Debian mailman package uses weak authentication,
which allows attackers to gain privileges. Status:
Entry
Reference: DEBIAN:19990623
Reference: BID:480
Reference:
URL:http://www.securityfocus.com/bid/480
Name: CVE-1999-0743
Description:
Trn allows local users to overwrite other users' files
via symlinks. Status: Entry
Reference: BUGTRAQ:19990819 Insecure use of file
in /tmp by trn
Reference: DEBIAN:19990823c
Reference: SUSE:19990824 Security hole in trn
Reference: XF:trn-symlinks(3144)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/3144
Name: CVE-1999-0744
Description:
Buffer overflow in Netscape Enterprise Server and
FastTrask Server allows remote attackers to gain
privileges via a long HTTP GET request. Status:
Entry
Reference: ISS:Buffer Overflow in Netscape
Enterprise and FastTrack Web Servers
Reference: BID:603
Reference:
URL:http://www.securityfocus.com/bid/603
Name: CVE-1999-0745
Description:
Buffer overflow in Source Code Browser Program Database
Name Server Daemon (pdnsd) for the IBM AIX C Set ++
compiler. Status: Entry
Reference: IBM:ERS-SVA-E01-1999:003.1
Reference: CIAC:J-059
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-059.shtml
Reference: BID:590
Reference:
URL:http://www.securityfocus.com/bid/590
Reference: XF:aix-pdnsd-bo
Name: CVE-1999-0746
Description:
A default configuration of in.identd in SuSE Linux waits
120 seconds between requests, allowing a remote attacker
to conduct a denial of service. Status: Entry
Reference: BUGTRAQ:19990814 DOS against SuSE's
identd
Reference: SUSE:19990824 Security hole in netcfg
Reference: BID:587
Reference:
URL:http://www.securityfocus.com/bid/587
Reference: XF:suse-identd-dos
Name: CVE-1999-0747
Description:
Denial of service in BSDi Symmetric Multiprocessing
(SMP) when an fstat call is made when the system has a
high CPU load. Status: Entry
Reference: BUGTRAQ:19990816 Symmetric
Multiprocessing (SMP) Vulnerbility in BSDi 4.0.1
Reference:
URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.BSI.4.10.9908170253560.19291-100000@saturn.psn.net
Reference: BID:589
Reference:
URL:http://www.securityfocus.com/bid/589
Reference: XF:bsdi-smp-dos
Name: CVE-1999-0749
Description:
Buffer overflow in Microsoft Telnet client in Windows 95
and Windows 98 via a malformed Telnet argument.
Status: Entry
Reference: BUGTRAQ:19990815 telnet.exe heap
overflow - remotely exploitable
Reference: MS:MS99-033
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-033.mspx
Reference: XF:win-ie5-telnet-heap-overflow
Reference: BID:586
Reference:
URL:http://www.securityfocus.com/bid/586
Name: CVE-1999-0751
Description:
Buffer overflow in Accept command in Netscape Enterprise
Server 3.6 with the SSL Handshake Patch. Status:
Entry
Reference: BUGTRAQ:19990913 Accept overflow on
Netscape Enterprise Server 3.6 SP2
Reference: BID:631
Reference:
URL:http://www.securityfocus.com/bid/631
Reference: XF:netscape-accept-bo(3256)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/3256
Name: CVE-1999-0752
Description:
Denial of service in Netscape Enterprise Server via a
buffer overflow in the SSL handshake. Status:
Entry
Reference: BUGTRAQ:19990706 Netscape Enterprise
Server SSL Handshake Bug
Name: CVE-1999-0753
Description:
The w3-msql CGI script provided with Mini SQL allows
remote attackers to view restricted directories.
Status: Entry
Reference: BUGTRAQ:19990817 Stupid bug in W3-msql
Reference: XF:mini-sql-w3-msql-cgi
Reference: BID:591
Reference:
URL:http://www.securityfocus.com/bid/591
Name: CVE-1999-0754
Description:
The INN inndstart program allows local users to gain
privileges by specifying an alternate configuration file
using the INNCONF environmental variable. Status:
Entry
Reference: BUGTRAQ:19990511 INN 2.0 and higher.
Root compromise potential
Reference: CALDERA:CSSA-1999-011.0
Reference:
URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-011.0.txt
Reference: SUSE:19990518 Security hole in INN
Reference:
MISC:http://www.redhat.com/corp/support/errata/inn99_05_22.html
Reference: BID:255
Reference:
URL:http://www.securityfocus.com/bid/255
Reference: XF:inn-innconf-env
Name: CVE-1999-0755
Description:
Windows NT RRAS and RAS clients cache a user's password
even if the user has not selected the "Save password"
option. Status: Entry
Reference: XF:nt-ras-pwcache
Reference: MSKB:Q230681
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q230681
Reference: MS:MS99-017
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-017.mspx
Name: CVE-1999-0756
Description:
ColdFusion Administrator with Advanced Security enabled
allows remote users to stop the ColdFusion server via
the Start/Stop utility. Status: Entry
Reference: ALLAIRE:ASB99-07
Reference:
URL:http://www.allaire.com/handlers/index.cfm?ID=10968&Method=Full
Reference: XF:coldfusion-admin-dos(2207)
Reference:
URL:http://xforce.iss.net/static/2207.php
Name: CVE-1999-0758
Description:
Netscape Enterprise 3.5.1 and FastTrack 3.01 servers
allow a remote attacker to view source code to scripts
by appending a %20 to the script's URL. Status:
Entry
Reference: ALLAIRE:ASB99-06
Reference: XF:netscape-space-view
Name: CVE-1999-0759
Description:
Buffer overflow in FuseMAIL POP service via long USER
and PASS commands. Status: Entry
Reference: BUGTRAQ:19990913 Many kind of
POP3/SMTP server softwares for Windows have buffer
overflow bug
Reference:
CONFIRM:http://www.crosswinds.net/~fuseware/faq.html#8
Reference: BID:634
Reference:
URL:http://www.securityfocus.com/bid/634
Reference: XF:fuseware-popmail-bo
Name: CVE-1999-0760
Description:
Undocumented ColdFusion Markup Language (CFML) tags and
functions in the ColdFusion Administrator allow users to
gain additional privileges. Status: Entry
Reference: ALLAIRE:ASB99-10
Reference:
URL:http://www.allaire.com/handlers/index.cfm?ID=11714&Method=Full
Reference: BID:550
Reference:
URL:http://www.securityfocus.com/bid/550
Reference: XF:coldfusion-server-cfml-tags
Reference:
URL:http://xforce.iss.net/static/3288.php
Name: CVE-1999-0761
Description:
Buffer overflow in FreeBSD fts library routines allows
local user to modify arbitrary files via the periodic
program. Status: Entry
Reference: FREEBSD:FreeBSD-SA-99:05
Reference: XF:freebsd-fts-lib-bo
Reference: BID:644
Reference:
URL:http://www.securityfocus.com/bid/644
Reference: OSVDB:1074
Reference: URL:http://www.osvdb.org/1074
Name: CVE-1999-0762
Description:
When Javascript is embedded within the TITLE tag,
Netscape Communicator allows a remote attacker to use
the "about" protocol to gain access to browser
information. Status: Entry
Reference: XF:netscape-title
Reference: BUGTRAQ:19990524 Netscape Communicator
JavaScript in <TITLE> security vulnerability
Name: CVE-1999-0763
Description:
NetBSD on a multi-homed host allows ARP packets on one
network to modify ARP entries on another connected
network. Status: Entry
Reference: NETBSD:1999-010
Reference: XF:netbsd-arp
Reference: OSVDB:6540
Reference: URL:http://www.osvdb.org/6540
Name: CVE-1999-0764
Description:
NetBSD allows ARP packets to overwrite static ARP
entries. Status: Entry
Reference: NETBSD:1999-010
Reference: XF:netbsd-arp
Reference: OSVDB:6539
Reference: URL:http://www.osvdb.org/6539
Name: CVE-1999-0765
Description:
SGI IRIX midikeys program allows local users to modify
arbitrary files via a text editor. Status: Entry
Reference: BUGTRAQ:19990619 IRIX midikeys root
exploit.
Reference: SGI:19990501-01-A
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19990501-01-A
Reference: BID:262
Reference:
URL:http://www.securityfocus.com/bid/262
Reference: XF:irix-midikeys
Name: CVE-1999-0766
Description:
The Microsoft Java Virtual Machine allows a malicious
Java applet to execute arbitrary commands outside of the
sandbox environment. Status: Entry
Reference: MS:MS99-031
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-031.mspx
Reference: MSKB:Q240346
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q240346
Reference: BID:600
Reference:
URL:http://www.securityfocus.com/bid/600
Reference: XF:msvm-verifier-java
Name: CVE-1999-0768
Description:
Buffer overflow in Vixie Cron on Red Hat systems via the
MAILTO environmental variable. Status: Entry
Reference: BID:602
Reference:
URL:http://www.securityfocus.com/bid/602
Reference: REDHAT:RHSA-1999:030-02
Reference: SUSE:19990829 Security hole in cron
Name: CVE-1999-0769
Description:
Vixie Cron on Linux systems allows local users to set
parameters of sendmail commands via the MAILTO
environmental variable. Status: Entry
Reference: REDHAT:RHSA-1999:030-02
Reference: CALDERA:CSSA-1999:023.0
Reference: SUSE:19990829 Security hole in cron
Reference: DEBIAN:19990830 cron
Reference: BID:611
Reference:
URL:http://www.securityfocus.com/bid/611
Name: CVE-1999-0770
Description:
Firewall-1 sets a long timeout for connections that
begin with ACK or other packets except SYN, allowing an
attacker to conduct a denial of service via a large
number of connection attempts to unresponsive systems.
Status: Entry
Reference: BUGTRAQ:19990729 Simple DOS attack on
FW-1
Reference: BID:549
Reference:
URL:http://www.securityfocus.com/bid/549
Reference: CHECKPOINT:ACK DOS ATTACK
Reference: OSVDB:1027
Reference: URL:http://www.osvdb.org/1027
Name: CVE-1999-0771
Description:
The web components of Compaq Management Agents and the
Compaq Survey Utility allow a remote attacker to read
arbitrary files via a .. (dot dot) attack. Status:
Entry
Reference: BUGTRAQ:19990526
Infosec.19990526.compaq-im.a
Reference: COMPAQ:SSRT0612U
Reference: XF:management-agent-file-read
Name: CVE-1999-0772
Description:
Denial of service in Compaq Management Agents and the
Compaq Survey Utility via a long string sent to port
2301. Status: Entry
Reference: BUGTRAQ:19990527 Re:
Infosec.19990526.compaq-im.a (New DoS and correction to
my previous post)
Reference: COMPAQ:SSRT0612U
Reference: XF:management-agent-dos
Name: CVE-1999-0773
Description:
Buffer overflow in Solaris lpset program allows local
users to gain root access. Status: Entry
Reference: BUGTRAQ:19990511 Solaris2.6 and 2.7
lpset overflow
Reference:
URL:http://www.netspace.org/cgi-bin/wa?A2=ind9905B&L=bugtraq&P=R2017
Reference: XF:sol-lpset-bo
Name: CVE-1999-0774
Description:
Buffer overflows in Mars NetWare Emulation (NWE,
mars_nwe) package via long directory names. Status:
Entry
Reference: BUGTRAQ:19990830 Babcia Padlina Ltd.
security advisory: mars_nwe buffer overf
Reference: REDHAT:RHSA1999037_01
Reference: SUSE:19990916 Security hole in mars
nwe
Reference: BID:617
Reference:
URL:http://www.securityfocus.com/bid/617
Name: CVE-1999-0775
Description:
Cisco Gigabit Switch routers running IOS allow remote
attackers to forward unauthorized packets due to
improper handling of the "established" keyword in an
access list. Status: Entry
Reference: CISCO:19990610 Cisco IOS Software
established Access List Keyword Error
Reference: XF:cisco-gigaswitch
Name: CVE-1999-0777
Description:
IIS FTP servers may allow a remote attacker to read or
delete files on the server, even if they have "No
Access" permissions. Status: Entry
Reference: MS:MS99-039
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-039.asp
Reference: MSKB:Q241407
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241407
Reference: MSKB:Q242559
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242559
Reference: XF:iis-ftp-no-access-files
Reference: BID:658
Reference:
URL:http://www.securityfocus.com/bid/658
Name: CVE-1999-0778
Description:
Buffer overflow in Xi Graphics Accelerated-X server
allows local users to gain root access via a long
display or query parameter. Status: Entry
Reference: BUGTRAQ:19990626 KSR[T] #011:
Accelerated-X
Reference: KSRT:011
Reference: BID:488
Reference:
URL:http://www.securityfocus.com/bid/488
Reference: XF:accelx-display-bo
Name: CVE-1999-0779
Description:
Denial of service in HP-UX SharedX recserv program.
Status: Entry
Reference: HP:HPSBUX9810-086
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9810-086
Reference: XF:hp-sharedx
Name: CVE-1999-0780
Description:
KDE klock allows local users to kill arbitrary processes
by specifying an arbitrary PID in the .kss.pid file.
Status: Entry
Reference: BUGTRAQ:19981118 Multiple KDE security
vulnerabilities (root compromise)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91141486301691&w=2
Reference: XF:kde-klock-process-kill
Name: CVE-1999-0781
Description:
KDE allows local users to execute arbitrary commands by
setting the KDEDIR environmental variable to modify the
search path that KDE uses to locate its executables.
Status: Entry
Reference: BUGTRAQ:19981118 Multiple KDE security
vulnerabilities (root compromise)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91141486301691&w=2
Reference: XF:kde-klock-bindir-trojans
Name: CVE-1999-0782
Description:
KDE kppp allows local users to create a directory in an
arbitrary location via the HOME environmental variable.
Status: Entry
Reference: BUGTRAQ:19981118 Multiple KDE security
vulnerabilities (root compromise)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91141486301691&w=2
Reference: XF:kde-kppp-directory-create
Name: CVE-1999-0783
Description:
FreeBSD allows local users to conduct a denial of
service by creating a hard link from a device special
file to a file on an NFS file system. Status:
Entry
Reference: FREEBSD:FreeBSD-SA-98:05
Reference: CIAC:I-057
Reference:
URL:http://www.ciac.org/ciac/bulletins/i-057.shtml
Reference: XF:freebsd-nfs-link-dos
Reference: OSVDB:6090
Reference: URL:http://www.osvdb.org/6090
Name: CVE-1999-0785
Description:
The INN inndstart program allows local users to gain
root privileges via the "pathrun" parameter in the
inn.conf file. Status: Entry
Reference: BUGTRAQ:19990511 INN 2.0 and higher.
Root compromise potential
Reference: SUSE:19990518 Security hole in INN
Reference: XF:inn-pathrun
Reference: BID:254
Reference:
URL:http://www.securityfocus.com/bid/254
Name: CVE-1999-0786
Description:
The dynamic linker in Solaris allows a local user to
create arbitrary files via the LD_PROFILE environmental
variable and a symlink attack. Status: Entry
Reference: BUGTRAQ:19990922 LD_PROFILE local root
exploit for solaris 2.6
Reference: BID:659
Reference:
URL:http://www.securityfocus.com/bid/659
Name: CVE-1999-0787
Description:
The SSH authentication agent follows symlinks via a UNIX
domain socket. Status: Entry
Reference: BUGTRAQ:19990917 A few bugs...
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93760201002154&w=2
Reference: BUGTRAQ:19990924 [Fwd: Truth about ssh
1.2.27 vulnerability]
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93832856804415&w=2
Reference: XF:ssh-socket-auth-symlink-dos
Reference: BID:660
Reference:
URL:http://www.securityfocus.com/bid/660
Name: CVE-1999-0788
Description:
Arkiea nlservd allows remote attackers to conduct a
denial of service. Status: Entry
Reference: BUGTRAQ:19990924 Multiple vendor Knox
Arkiea local root/remote DoS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93837184228248&w=2
Reference: BID:662
Reference:
URL:http://www.securityfocus.com/bid/662
Reference: XF:arkiea-backup-nlserverd-remote-dos
Name: CVE-1999-0789
Description:
Buffer overflow in AIX ftpd in the libc library.
Status: Entry
Reference: BUGTRAQ:19990928 Remote bufferoverflow
exploit for ftpd from AIX 4.3.2 running on an RS6000
Reference: IBM:ERS-SVA-E01-1999:004.1
Reference: CIAC:J-072
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-072.shtml
Reference: XF:aix-ftpd-bo
Reference: BID:679
Reference:
URL:http://www.securityfocus.com/bid/679
Name: CVE-1999-0790
Description:
A remote attacker can read information from a Netscape
user's cache via JavaScript. Status: Entry
Reference:
MISC:http://home.netscape.com/security/notes/jscachebrowsing.html
Reference: XF:netscape-javascript
Name: CVE-1999-0791
Description:
Hybrid Network cable modems do not include an
authentication mechanism for administration, allowing
remote attackers to compromise the system through the
HSMP protocol. Status: Entry
Reference: BUGTRAQ:19991006 KSR[T] Advisories
#012: Hybrid Network's Cable Modems
Reference: KSRT:012
Reference: BID:695
Reference:
URL:http://www.securityfocus.com/bid/695
Reference: XF:hybrid-anon-cable-modem-reconfig
Name: CVE-1999-0793
Description:
Internet Explorer allows remote attackers to read files
by redirecting data to a Javascript applet. Status:
Entry
Reference: MS:MS99-043
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-043.mspx
Reference: XF:ie-java-redirect
Name: CVE-1999-0794
Description:
Microsoft Excel does not warn a user when a macro is
present in a Symbolic Link (SYLK) format file.
Status: Entry
Reference: MS:MS99-044
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-044.mspx
Reference: XF:excel-sylk
Reference: MSKB:Q241900
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241900
Reference: MSKB:Q241901
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241901
Reference: MSKB:Q241902
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241902
Name: CVE-1999-0796
Description:
FreeBSD T/TCP Extensions for Transactions can be
subjected to spoofing attacks. Status: Entry
Reference: FREEBSD:SA-98.03
Reference: XF:freebsd-ttcp-spoof
Reference: OSVDB:6089
Reference: URL:http://www.osvdb.org/6089
Name: CVE-1999-0797
Description:
NIS finger allows an attacker to conduct a denial of
service via a large number of finger requests, resulting
in a large number of NIS queries. Status: Entry
Reference: ISS:19980629 Distributed DoS attack
against NIS/NIS+ based networks.
Reference: CIAC:I-070
Reference:
URL:http://www.ciac.org/ciac/bulletins/i-070.shtml
Reference: XF:sun-nis-nisplus
Name: CVE-1999-0799
Description:
Buffer overflow in bootpd 2.4.3 and earlier via a long
boot file location. Status: Entry
Reference: BUGTRAQ:19970725 Exploitable buffer
overflow in bootpd (most unices)
Reference: XF:bootpd-bo
Name: CVE-1999-0800
Description:
The GetFile.cfm file in Allaire Forums allows remote
attackers to read files through a parameter to
GetFile.cfm. Status: Entry
Reference: ALLAIRE:ASB99-05
Reference:
URL:http://www.allaire.com/handlers/index.cfm?ID=9602&Method=Full
Reference: NTBUGTRAQ:19990211 ACFUG List: Alert:
Allaire Forums GetFile bug
Reference:
URL:http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00332.html
Reference: XF:allaire-forums-file-read(1748)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/1748
Reference: OSVDB:944
Reference: URL:http://www.osvdb.org/944
Name: CVE-1999-0801
Description:
BMC Patrol allows remote attackers to gain access to an
agent by spoofing frames. Status: Entry
Reference: BUGTRAQ:19990409 Patrol security bugs
Reference:
URL:http://www.securityfocus.com/archive/1/13204
Reference: XF:bmc-patrol-frames(2075)
Reference:
URL:http://www.iss.net/security_center/static/2075.php
Name: CVE-1999-0802
Description:
Buffer overflow in Internet Explorer 5 allows remote
attackers to execute commands via a malformed Favorites
icon. Status: Entry
Reference: BUGTRAQ:19990503 MSIE 5 FAVICON BUG
Reference: MS:MS99-018
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-018.mspx
Reference: MSKB:Q231450
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231450
Reference: XF:ie-favicon
Name: CVE-1999-0803
Description:
The fwluser script in AIX eNetwork Firewall allows local
users to write to arbitrary files via a symlink attack.
Status: Entry
Reference: BUGTRAQ:19990525 IBM eNetwork Firewall
for AIX
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92765973207648&w=2
Reference: XF:ibm-enfirewall-tmpfiles
Reference: OSVDB:962
Reference: URL:http://www.osvdb.org/962
Name: CVE-1999-0804
Description:
Denial of service in Linux 2.2.x kernels via malformed
ICMP packets containing unusual types, codes, and IP
header lengths. Status: Entry
Reference: BUGTRAQ:19990601 Linux kernel 2.2.x
vulnerability/exploit
Reference: DEBIAN:19990607
Reference: CALDERA:CSSA-1999:013
Reference: SUSE:19990602 Denial of Service on the
2.2 kernel
Reference: REDHAT:19990603 Kernel Update
Reference: BID:302
Reference:
URL:http://www.securityfocus.com/bid/302
Name: CVE-1999-0806
Description:
Buffer overflow in Solaris dtprintinfo program.
Status: Entry
Reference: BUGTRAQ:19990510 Solaris2.6,2.7
dtprintinfo exploits
Reference: XF:cde-dtprintinfo
Reference: OSVDB:6552
Reference: URL:http://www.osvdb.org/6552
Name: CVE-1999-0807
Description:
The Netscape Directory Server installation procedure
leaves sensitive information in a file that is
accessible to local users. Status: Entry
Reference: XF:netscape-dirsvc-password
Name: CVE-1999-0809
Description:
Netscape Communicator 4.x with Javascript enabled does
not warn a user of cookie settings, even if they have
selected the option to "Only accept cookies originating
from the same server as the page being viewed".
Status: Entry
Reference: BUGTRAQ:19990709 Communicator 4.[56]x,
JavaScript used to bypass cookie settings
Name: CVE-1999-0810
Description:
Denial of service in Samba NETBIOS name service daemon
(nmbd). Status: Entry
Reference: BUGTRAQ:19990721 Samba 2.0.5 security
fixes
Reference: CALDERA:CSSA-1999:018.0
Reference: DEBIAN:19990731
Reference: DEBIAN:19990804
Reference: REDHAT:RHSA-1999:022-02
Reference: SUSE:19990816 Security hole in Samba
Name: CVE-1999-0811
Description:
Buffer overflow in Samba smbd program via a malformed
message command. Status: Entry
Reference: BUGTRAQ:19990721 Samba 2.0.5 security
fixes
Reference: REDHAT:RHSA-1999:022-02
Reference: CALDERA:CSSA-1999:018.0
Reference: SUSE:19990816 Security hole in Samba
Reference: DEBIAN:19990731 Samba
Reference: XF:samba-message-bo
Reference: BID:536
Reference:
URL:http://www.securityfocus.com/bid/536
Name: CVE-1999-0812
Description:
Race condition in Samba smbmnt allows local users to
mount file systems in arbitrary locations. Status:
Entry
Reference: BUGTRAQ:19990721 Samba 2.0.5 security
fixes
Reference: DEBIAN:19990731
Reference: DEBIAN:19990804
Reference: CALDERA:CSSA-1999:018.0
Reference: REDHAT:RHSA-1999:022-02
Reference: SUSE:19990816 Security hole in Samba
Name: CVE-1999-0813
Description:
Cfingerd with ALLOW_EXECUTION enabled does not properly
drop privileges when it executes a program on behalf of
the user, allowing local users to gain root privileges.
Status: Entry
Reference: BUGTRAQ:19990810 Severe bug in
cfingerd before 1.4.0
Reference: BUGTRAQ:19980724 CFINGERD root
security hole
Reference: DEBIAN:19990814
Reference: XF:cfingerd-privileges
Name: CVE-1999-0814
Description:
Red Hat pump DHCP client allows remote attackers to gain
root access in some configurations. Status: Entry
Reference: REDHAT:RHSA-1999:027
Reference:
URL:http://www.redhat.com/support/errata/RHSA-1999-027.html
Name: CVE-1999-0815
Description:
Memory leak in SNMP agent in Windows NT 4.0 before SP5
allows remote attackers to conduct a denial of service
(memory exhaustion) via a large number of queries.
Status: Entry
Reference: MSKB:Q196270
Reference:
URL:http://support.microsoft.com/support/kb/articles/q196/2/70.asp
Reference: XF:nt-snmpagent-leak(1974)
Reference:
URL:http://xforce.iss.net/static/1974.php
Reference: OVAL:oval:org.mitre.oval:def:952
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:952
Name: CVE-1999-0817
Description:
Lynx WWW client allows a remote attacker to specify
command-line parameters which Lynx uses when calling
external programs to handle certain protocols, e.g.
telnet. Status: Entry
Reference: SUSE:19990915 Security hole in lynx
Name: CVE-1999-0819
Description:
NTMail does not disable the VRFY command, even if the
administrator has explicitly disabled it. Status:
Entry
Reference: NTBUGTRAQ:19991130 NTmail and VRFY
Reference: BUGTRAQ:19991130 NTmail and VRFY
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94398141118586&w=2
Reference: XF:nt-mail-vrfy
Name: CVE-1999-0820
Description:
FreeBSD seyon allows users to gain privileges via a
modified PATH variable for finding the xterm and
seyon-emu commands. Status: Entry
Reference: BUGTRAQ:19991130 Several FreeBSD-3.3
vulnerabilities
Reference: BID:838
Reference:
URL:http://www.securityfocus.com/bid/838
Reference: XF:freebsd-seyon-dir-add
Reference: OSVDB:5996
Reference: URL:http://www.osvdb.org/5996
Name: CVE-1999-0823
Description:
Buffer overflow in FreeBSD xmindpath allows local users
to gain privileges via -f argument. Status: Entry
Reference: BUGTRAQ:19991130 Several FreeBSD-3.3
vulnerabilities
Reference: BID:839
Reference:
URL:http://www.securityfocus.com/bid/839
Reference: XF:freebsd-xmindpath
Reference: OSVDB:1150
Reference: URL:http://www.osvdb.org/1150
Name: CVE-1999-0824
Description:
A Windows NT user can use SUBST to map a drive letter to
a folder, which is not unmapped after the user logs off,
potentially allowing that user to modify the location of
folders accessed by later users. Status: Entry
Reference: BID:833
Reference:
URL:http://www.securityfocus.com/bid/833
Reference: NTBUGTRAQ:19991130 SUBST problem
Reference: BUGTRAQ:19991130 Subst.exe
carelessness (fwd)
Name: CVE-1999-0826
Description:
Buffer overflow in FreeBSD angband allows local users to
gain privileges. Status: Entry
Reference: BUGTRAQ:19991130 Several FreeBSD-3.3
vulnerabilities
Reference: BID:840
Reference:
URL:http://www.securityfocus.com/bid/840
Reference: XF:angband-bo
Reference: OSVDB:1151
Reference: URL:http://www.osvdb.org/1151
Name: CVE-1999-0831
Description:
Denial of service in Linux syslogd via a large number of
connections. Status: Entry
Reference: CALDERA:CSSA-1999-035.0
Reference:
URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-035.0.txt
Reference: REDHAT:RHSA1999055-01
Reference: SUSE:19991118 syslogd-1.3.33 (a1)
Reference: BUGTRAQ:19991130 [david@slackware.com:
New Patches for Slackware 4.0 Available]
Reference: BID:809
Reference:
URL:http://www.securityfocus.com/bid/809
Reference: XF:slackware-syslogd-dos
Name: CVE-1999-0832
Description:
Buffer overflow in NFS server on Linux allows attackers
to execute commands via a long pathname. Status:
Entry
Reference: BUGTRAQ:19991109 undocumented bugs -
nfsd
Reference:
URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.20.9911091058140.12964-100000@mail.zigzag.pl
Reference: DEBIAN:19991111 buffer overflow in nfs
server
Reference:
URL:http://www.debian.org/security/1999/19991111
Reference: SUSE:19991110 Security hole in
nfs-server < 2.2beta47 within nkita
Reference:
URL:http://www.novell.com/linux/security/advisories/suse_security_announce_29.html
Reference: CALDERA:CSSA-1999-033.0
Reference:
URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-033.0.txt
Reference: REDHAT:RHSA-1999:053-01
Reference:
URL:http://www.redhat.com/support/errata/rh42-errata-general.html#NFS
Reference: BUGTRAQ:19991130 [david@slackware.com:
New Patches for Slackware 4.0 Available]
Reference: XF:linux-nfs-maxpath-bo
Reference: BID:782
Reference:
URL:http://www.securityfocus.com/bid/782
Name: CVE-1999-0833
Description:
Buffer overflow in BIND 8.2 via NXT records. Status:
Entry
Reference: SUSE:19991111 Security hole in bind8 <
8.2.2p2 and bind4 < 4.9.7-REL
Reference: DEBIAN:19991116 Denial of service
vulnerabilities in bind
Reference: CALDERA:CSSA-1999-034.1
Reference:
URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt
Reference: REDHAT:RHSA-1999:054-01
Reference: CERT:CA-99-14
Reference: BID:788
Reference:
URL:http://www.securityfocus.com/bid/788
Reference: XF:bind-nxt-bo
Name: CVE-1999-0834
Description:
Buffer overflow in RSAREF2 via the encryption and
decryption functions in the RSAREF library. Status:
Entry
Reference: BUGTRAQ:19991201 Security Advisory:
Buffer overflow in RSAREF2
Reference: BUGTRAQ:19991202 OpenBSD sslUSA26
advisory (Re: CORE-SDI: Buffer overflow in RSAREF2)
Reference: CERT:CA-99-15
Reference: BID:843
Reference:
URL:http://www.securityfocus.com/bid/843
Reference: XF:rsaref-bo
Name: CVE-1999-0835
Description:
Denial of service in BIND named via malformed SIG
records. Status: Entry
Reference: SUSE:19991111 Security hole in bind8 <
8.2.2p2 and bind4 < 4.9.7-REL
Reference: DEBIAN:19991116 Denial of service
vulnerabilities in bind
Reference: CALDERA:CSSA-1999-034.1
Reference:
URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt
Reference: REDHAT:RHSA-1999:054-01
Reference: CERT:CA-99-14
Reference: XF:bind-sigrecord-dos
Reference: BID:788
Reference:
URL:http://www.securityfocus.com/bid/788
Name: CVE-1999-0836
Description:
UnixWare uidadmin allows local users to modify arbitrary
files via a symlink attack. Status: Entry
Reference: BUGTRAQ:19991202 UnixWare 7 uidadmin
exploit + discussion
Reference:
URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=19991202160111.20553.qmail@nwcst282.netaddress.usa.net
Reference: SCO:SB-99.22a
Reference:
URL:ftp://ftp.sco.com/SSE/security_bulletins/SB-99.22a
Reference: BID:842
Reference:
URL:http://www.securityfocus.com/bid/842
Reference: XF:unixware-uid-admin
Name: CVE-1999-0837
Description:
Denial of service in BIND by improperly closing TCP
sessions via so_linger. Status: Entry
Reference: SUSE:19991111 Security hole in bind8 <
8.2.2p2 and bind4 < 4.9.7-REL
Reference: DEBIAN:19991116 Denial of service
vulnerabilities in bind
Reference: CALDERA:CSSA-1999-034.1
Reference:
URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt
Reference: REDHAT:RHSA-1999:054-01
Reference: SUN:00194
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/194
Reference: CERT:CA-99-14
Reference: XF:bind-solinger-dos
Reference: BID:788
Reference:
URL:http://www.securityfocus.com/bid/788
Name: CVE-1999-0838
Description:
Buffer overflow in Serv-U FTP 2.5 allows remote users to
conduct a denial of service via the SITE command.
Status: Entry
Reference: BUGTRAQ:19991202 Remote DoS Attack in
Serv-U FTP-Server v2.5a Vulnerability
Reference: BID:859
Reference:
URL:http://www.securityfocus.com/bid/859
Reference: XF:servu-ftp-site-bo
Name: CVE-1999-0839
Description:
Windows NT Task Scheduler installed with Internet
Explorer 5 allows a user to gain privileges by modifying
the job after it has been scheduled. Status:
Entry
Reference: NTBUGTRAQ:19991130 Windows NT Task
Scheduler vulnerability allows user to administrator
elevation
Reference: MS:MS99-051
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-051.mspx
Reference: MSKB:Q246972
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246972
Reference: XF:ie-task-scheduler-privs
Reference: BID:828
Reference:
URL:http://www.securityfocus.com/bid/828
Name: CVE-1999-0842
Description:
Symantec Mail-Gear 1.0 web interface server allows
remote users to read arbitrary files via a .. (dot dot)
attack. Status: Entry
Reference: NTBUGTRAQ:19991129 Symantec Mail-Gear
1.0 Web interface Server Directory Traversal
Vulnerability
Reference: BUGTRAQ:19991129 Symantec Mail-Gear
1.0 Web interface Server Directory Traversal
Vulnerability
Reference:
URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=NCBBKFKDOLAGKIAPMILPCEAFCBAA.labs@ussrback.com
Reference: BID:827
Reference:
URL:http://www.securityfocus.com/bid/827
Reference: XF:symantec-mail-dir-traversal
Reference: OSVDB:1144
Reference: URL:http://www.osvdb.org/1144
Name: CVE-1999-0847
Description:
Buffer overflow in free internet chess server (FICS)
program, xboard. Status: Entry
Reference: BUGTRAQ:19991129 FICS buffer overflow
Reference: XF:fics-board-bo
Name: CVE-1999-0848
Description:
Denial of service in BIND named via consuming more than
"fdmax" file descriptors. Status: Entry
Reference: SUSE:19991111 Security hole in bind8 <
8.2.2p2 and bind4 < 4.9.7-REL
Reference: DEBIAN:19991116 Denial of service
vulnerabilities in bind
Reference: CALDERA:CSSA-1999-034.1
Reference:
URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt
Reference: REDHAT:RHSA-1999:054-01
Reference: SUN:00194
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/194
Reference: CERT:CA-99-14
Reference: BID:788
Reference:
URL:http://www.securityfocus.com/bid/788
Reference: XF:bind-fdmax-dos
Name: CVE-1999-0849
Description:
Denial of service in BIND named via maxdname. Status:
Entry
Reference: SUSE:19991111 Security hole in bind8 <
8.2.2p2 and bind4 < 4.9.7-REL
Reference: DEBIAN:19991116 Denial of service
vulnerabilities in bind
Reference: CALDERA:CSSA-1999-034.1
Reference:
URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt
Reference: REDHAT:RHSA-1999:054-01
Reference: SUN:00194
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/194
Reference: CERT:CA-99-14
Reference: BID:788
Reference:
URL:http://www.securityfocus.com/bid/788
Reference: XF:bind-maxdname-bo
Name: CVE-1999-0851
Description:
Denial of service in BIND named via naptr. Status:
Entry
Reference: SUSE:19991111 Security hole in bind8 <
8.2.2p2 and bind4 < 4.9.7-REL
Reference: DEBIAN:19991116 Denial of service
vulnerabilities in bind
Reference: CALDERA:CSSA-1999-034.1
Reference:
URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt
Reference: REDHAT:RHSA-1999:054-01
Reference: SUN:00194
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/194
Reference: CERT:CA-99-14
Reference: BID:788
Reference:
URL:http://www.securityfocus.com/bid/788
Reference: XF:bind-naptr-dos
Name: CVE-1999-0853
Description:
Buffer overflow in Netscape Enterprise Server and
Netscape FastTrack Server allows remote attackers to
gain privileges via the HTTP Basic Authentication
procedure. Status: Entry
Reference: BID:847
Reference:
URL:http://www.securityfocus.com/bid/847
Reference: ISS:19991201 Buffer Overflow in
Netscape Enterprise and FastTrack Authentication
Procedure
Reference: XF:netscape-fasttrack-auth-bo
Name: CVE-1999-0854
Description:
Ultimate Bulletin Board stores data files in the cgi-bin
directory, allowing remote attackers to view the data if
an error occurs when the HTTP server attempts to execute
the file. Status: Entry
Reference: BUGTRAQ:19991130 Ultimate Bulletin
Board v5.3x? Bug
Reference: BUGTRAQ:20000225 FW: Important UBB
News For Licensed Users
Reference:
URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-02-22&msg=NDBBLKOPOLNKELHPDEFKIEPGCAAA.renzo.toma@veronica.nl
Reference:
CONFIRM:http://www.ultimatebb.com/home/versions.shtml
Reference: XF:http-ultimate-bbs
Name: CVE-1999-0856
Description:
login in Slackware 7.0 allows remote attackers to
identify valid users on the system by reporting an
encryption error when an account is locked or does not
exist. Status: Entry
Reference: BUGTRAQ:19991202 Slackware 7.0 - login
bug
Reference: XF:slackware-remote-login
Name: CVE-1999-0858
Description:
Internet Explorer 5 allows a remote attacker to modify
the IE client's proxy configuration via a malicious Web
Proxy Auto-Discovery (WPAD) server. Status: Entry
Reference: MS:MS99-054
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-054.mspx
Reference: MSKB:Q247333
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q247333
Reference: BID:846
Reference:
URL:http://www.securityfocus.com/bid/846
Reference: XF:ie-wpad-proxy-settings
Name: CVE-1999-0859
Description:
Solaris arp allows local users to read files via the -f
parameter, which lists lines in the file that do not
parse properly. Status: Entry
Reference: BUGTRAQ:19991130 Solaris 2.x
chkperm/arp vulnerabilities
Reference: SUNBUG:4296166
Reference: BID:837
Reference:
URL:http://www.securityfocus.com/bid/837
Reference: XF:sol-arp-parse
Reference: OSVDB:6994
Reference: URL:http://www.osvdb.org/6994
Name: CVE-1999-0861
Description:
Race condition in the SSL ISAPI filter in IIS and other
servers may leak information in plaintext. Status:
Entry
Reference: MS:MS99-053
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-053.mspx
Reference: MSKB:Q244613
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q244613
Reference: XF:iis-ssl-isapi-filter
Name: CVE-1999-0864
Description:
UnixWare programs that dump core allow a local user to
modify files via a symlink attack on the ./core.pid
file. Status: Entry
Reference: BUGTRAQ:19991202 UnixWare coredumps
follow symlinks
Reference:
URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=19991203020720.13115.qmail@nwcst289.netaddress.usa.net
Reference: BUGTRAQ:19991215 Recent postings about
SCO UnixWare 7
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94530783815434&w=2
Reference: BUGTRAQ:19991223 FYI, SCO Security
patches available.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94606167110764&w=2
Reference: BUGTRAQ:19991220 SCO OpenServer
Security Status
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94581379905584&w=2
Reference: XF:sco-coredump-symlink
Reference: BID:851
Reference:
URL:http://www.securityfocus.com/bid/851
Name: CVE-1999-0865
Description:
Buffer overflow in CommuniGatePro via a long string to
the HTTP configuration port. Status: Entry
Reference: BUGTRAQ:19991203 CommuniGatePro 3.1
for NT DoS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94426440413027&w=2
Reference: NTBUGTRAQ:19991203 CommuniGatePro 3.1
for NT Buffer Overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=94454565726775&w=2
Reference: BID:860
Reference:
URL:http://www.securityfocus.com/bid/860
Reference: XF:communigate-pro-bo
Name: CVE-1999-0866
Description:
Buffer overflow in UnixWare xauto program allows local
users to gain root privilege. Status: Entry
Reference: BUGTRAQ:19991203 UnixWare gain root
with non-su/gid binaries
Reference: BUGTRAQ:19991215 Recent postings about
SCO UnixWare 7
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94530783815434&w=2
Reference: BUGTRAQ:19991223 FYI, SCO Security
patches available.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94606167110764&w=2
Reference: BUGTRAQ:19991220 SCO OpenServer
Security Status
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94581379905584&w=2
Reference: SCO:SB-99.24a
Reference:
URL:ftp://ftp.sco.com/SSE/security_bulletins/SB-99.24a
Reference: XF:sco-xauto-bo
Reference: BID:848
Reference:
URL:http://www.securityfocus.com/bid/848
Name: CVE-1999-0867
Description:
Denial of service in IIS 4.0 via a flood of HTTP
requests with malformed headers. Status: Entry
Reference: MS:MS99-029
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-029.mspx
Reference: MSKB:Q238349
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238349
Reference: CIAC:J-058
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-058.shtml
Reference: XF:http-iis-malformed-header
Reference: BID:579
Reference:
URL:http://www.securityfocus.com/bid/579
Name: CVE-1999-0868
Description:
ucbmail allows remote attackers to execute commands via
shell metacharacters that are passed to it from INN.
Status: Entry
Reference: CERT:CA-97.08
Reference: XF:inn-ucbmail-shell-meta
Name: CVE-1999-0869
Description:
Internet Explorer 3.x to 4.01 allows a remote attacker
to insert malicious content into a frame of another web
site, aka frame spoofing. Status: Entry
Reference: MS:MS98-020
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms98-020.mspx
Reference: MSKB:167614
Reference: XF:http-frame-spoof
Name: CVE-1999-0870
Description:
Internet Explorer 4.01 allows remote attackers to read
arbitrary files by pasting a file name into the file
upload control, aka untrusted scripted paste. Status:
Entry
Reference: MS:MS98-015
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms98-015.mspx
Reference: MSKB:169245
Reference: XF:ie-usp-cuartango
Name: CVE-1999-0871
Description:
Internet Explorer 4.0 and 4.01 allow a remote attacker
to read files via IE's cross frame security, aka the
"Cross Frame Navigate" vulnerability. Status:
Entry
Reference: MS:MS98-013
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms98-013.mspx
Reference: OSVDB:7837
Reference: URL:http://www.osvdb.org/7837
Reference: XF:ie-crossframe-file-read(3668)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/3668
Name: CVE-1999-0873
Description:
Buffer overflow in Skyfull mail server via MAIL FROM
command. Status: Entry
Reference: BID:759
Reference:
URL:http://www.securityfocus.com/bid/759
Reference: XF:skyfull-mail-from-bo
Name: CVE-1999-0874
Description:
Buffer overflow in IIS 4.0 allows remote attackers to
cause a denial of service via a malformed request for
files with .HTR, .IDC, or .STM extensions. Status:
Entry
Reference: MS:MS99-019
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-019.asp
Reference: MSKB:Q234905
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q234905
Reference: EEYE:AD06081999
Reference:
URL:http://www.eeye.com/html/Research/Advisories/AD06081999.html
Reference: CERT:CA-99-07
Reference: CIAC:J-048
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-048.shtml
Reference: XF:iis-htr-overflow
Reference: OVAL:oval:org.mitre.oval:def:915
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:915
Name: CVE-1999-0875
Description:
DHCP clients with ICMP Router Discovery Protocol (IRDP)
enabled allow remote attackers to modify their default
routes. Status: Entry
Reference: L0PHT:19990811
Reference: MSKB:Q216141
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q216141
Reference: BID:578
Reference:
URL:http://www.securityfocus.com/bid/578
Reference: XF:irdp-gateway-spoof
Name: CVE-1999-0876
Description:
Buffer overflow in Internet Explorer 4.0 via EMBED tag.
Status: Entry
Reference: MSKB:Q185959
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q185959
Reference: MSKB:Q176697
Reference:
URL:http://support.microsoft.com/support/kb/articles/q176/6/97.asp
Name: CVE-1999-0877
Description:
Internet Explorer 5 allows remote attackers to read
files via an ExecCommand method called on an IFRAME.
Status: Entry
Reference: MSKB:Q243638
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243638
Reference: MS:MS99-042
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-042.mspx
Reference: XF:ie-iframe-exec
Name: CVE-1999-0878
Description:
Buffer overflow in WU-FTPD and related FTP servers
allows remote attackers to gain root privileges via
MAPPING_CHDIR. Status: Entry
Reference: COMPAQ:SSRT0622
Reference: REDHAT:RHSA1999031_01
Reference: AUSCERT:AA-1999.01
Reference: CERT:CA-99-13
Reference: BID:599
Reference:
URL:http://www.securityfocus.com/bid/599
Reference: XF:wu-ftpd-dir-name
Name: CVE-1999-0879
Description:
Buffer overflow in WU-FTPD and related FTP servers
allows remote attackers to gain root privileges via
macro variables in a message file. Status: Entry
Reference: CERT:CA-99-13
Reference: XF:wuftp-message-file-root
Name: CVE-1999-0880
Description:
Denial of service in WU-FTPD via the SITE NEWER command,
which does not free memory properly. Status:
Entry
Reference: CERT:CA-99-13
Reference: XF:wuftp-site-newer-dos
Name: CVE-1999-0881
Description:
Falcon web server allows remote attackers to read
arbitrary files via a .. (dot dot) attack. Status:
Entry
Reference: BUGTRAQ:19991025 Falcon Web Server
Reference: BINDVIEW:Falcon Web Server
Reference: BID:743
Reference:
URL:http://www.securityfocus.com/bid/743
Reference: XF:falcon-path-parsing
Reference: OSVDB:1127
Reference: URL:http://www.osvdb.org/1127
Name: CVE-1999-0883
Description:
Zeus web server allows remote attackers to read
arbitrary files by specifying the file name in an option
to the search engine. Status: Entry
Reference: BUGTRAQ:19991024 RFP9905: Zeus
webserver remote root compromise
Reference: BID:742
Reference:
URL:http://www.securityfocus.com/bid/742
Reference: OSVDB:1126
Reference: URL:http://www.osvdb.org/1126
Reference: XF:zeus-remote-root(3380)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/3380
Name: CVE-1999-0884
Description:
The Zeus web server administrative interface uses weak
encryption for its passwords. Status: Entry
Reference: BUGTRAQ:19991024 RFP9905: Zeus
webserver remote root compromise
Reference: BID:742
Reference:
URL:http://www.securityfocus.com/bid/742
Reference: OSVDB:8186
Reference: URL:http://www.osvdb.org/8186
Reference: XF:zeus-weak-password(3833)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/3833
Name: CVE-1999-0886
Description:
The security descriptor for RASMAN allows users to point
to an alternate location via the Windows NT Service
Control Manager. Status: Entry
Reference: MSKB:Q242294
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242294
Reference: MS:MS99-041
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-041.mspx
Reference: BID:645
Reference:
URL:http://www.securityfocus.com/bid/645
Reference: XF:nt-rasman-pathname
Name: CVE-1999-0887
Description:
FTGate web interface server allows remote attackers to
read files via a .. (dot dot) attack. Status:
Entry
Reference: BUGTRAQ:19991104 FTGate Version 2.1
Web interface Server Directory Traversal Vulnerability
Reference: EEYE:AD05261999
Reference:
URL:http://www.eeye.com/html/Research/Advisories/AD05261999.html
Reference: OSVDB:1137
Reference: URL:http://www.osvdb.org/1137
Name: CVE-1999-0888
Description:
dbsnmp in Oracle Intelligent Agent allows local users to
gain privileges by setting the ORACLE_HOME environmental
variable, which dbsnmp uses to find the nmiconf.tcl
script. Status: Entry
Reference: BUGTRAQ:19990817 Security Bug in
Oracle
Reference: XF:oracle-dbsnmp
Reference: BID:585
Reference:
URL:http://www.securityfocus.com/bid/585
Name: CVE-1999-0889
Description:
Cisco 675 routers running CBOS allow remote attackers to
establish telnet sessions if an exec or superuser
password has not been set. Status: Entry
Reference: BUGTRAQ:19990810 Cisco 675 password
nonsense
Reference: XF:cisco-cbos-telnet
Reference: OSVDB:39
Reference: URL:http://www.osvdb.org/39
Name: CVE-1999-0890
Description:
iHTML Merchant allows remote attackers to obtain
sensitive information or execute commands via a code
parsing error. Status: Entry
Reference: BUGTRAQ:19990928 Team Asylum: iHTML
Merchant Vulnerabilities
Reference:
CONFIRM:http://www.ihtmlmerchant.com/support_patches_feedback.htm
Reference: BID:694
Reference:
URL:http://www.securityfocus.com/bid/694
Reference: XF:ihtml-merchant-file-access
Name: CVE-1999-0891
Description:
The "download behavior" in Internet Explorer 5 allows
remote attackers to read arbitrary files via a
server-side redirect. Status: Entry
Reference: MS:MS99-040
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-040.mspx
Reference: MSKB:Q242542
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242542
Reference: CERT-VN:VU#37828
Reference:
URL:http://www.kb.cert.org/vuls/id/37828
Reference: CIAC:K-002
Reference:
URL:http://www.ciac.org/ciac/bulletins/k-002.shtml
Reference: BID:674
Reference:
URL:http://www.securityfocus.com/bid/674
Reference: OSVDB:11274
Reference: URL:http://www.osvdb.org/11274
Reference: XF:ie-download-behavior
Name: CVE-1999-0892
Description:
Buffer overflow in Netscape Communicator before 4.7 via
a dynamic font whose length field is less than the size
of the font. Status: Entry
Reference: BUGTRAQ:19991018 Netscape 4.x buffer
overflow
Name: CVE-1999-0893
Description:
userOsa in SCO OpenServer allows local users to corrupt
files via a symlink attack. Status: Entry
Reference: BUGTRAQ:19991011 SCO OpenServer 5.0.5
overwrite /etc/shadow
Reference: XF:sco-openserver-userosa-script
Name: CVE-1999-0894
Description:
Red Hat Linux screen program does not use Unix98 ptys,
allowing local users to write to other terminals.
Status: Entry
Reference: REDHAT:RHSA1999042-01
Name: CVE-1999-0895
Description:
Firewall-1 does not properly restrict access to LDAP
attributes. Status: Entry
Reference: BUGTRAQ:19991020 Checkpoint FireWall-1
V4.0: possible bug in LDAP authentication
Reference:
URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=19991020150002.21047.qmail@tarjan.mediaways.net
Reference: BID:725
Reference:
URL:http://www.securityfocus.com/bid/725
Reference: XF:checkpoint-ldap-auth
Reference: OSVDB:1117
Reference: URL:http://www.osvdb.org/1117
Name: CVE-1999-0896
Description:
Buffer overflow in RealNetworks RealServer
administration utility allows remote attackers to
execute arbitrary commands via a long username and
password. Status: Entry
Reference: BUGTRAQ:19991109 RealNetworks
RealServer G2 buffer overflow.
Reference:
MISC:http://service.real.com/help/faq/servg260.html
Reference: XF:realserver-g2-pw-bo
Reference: BID:767
Reference:
URL:http://www.securityfocus.com/bid/767
Name: CVE-1999-0897
Description:
iChat ROOMS Webserver allows remote attackers to read
arbitrary files via a .. (dot dot) attack. Status:
Entry
Reference: BUGTRAQ:19980908 bug in iChat 3.0
(maybe others)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90538488231977&w=2
Reference: XF:ichat-file-read-vuln
Name: CVE-1999-0898
Description:
Buffer overflows in Windows NT 4.0 print spooler allow
remote attackers to gain privileges or cause a denial of
service via a malformed spooler request. Status:
Entry
Reference: MS:MS99-047
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-047.mspx
Reference: MSKB:Q243649
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243649
Reference: XF:nt-printer-spooler-bo
Reference: BID:768
Reference:
URL:http://www.securityfocus.com/bid/768
Name: CVE-1999-0899
Description:
The Windows NT 4.0 print spooler allows a local user to
execute arbitrary commands due to inappropriate
permissions that allow the user to specify an alternate
print provider. Status: Entry
Reference: MS:MS99-047
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-047.mspx
Reference: MSKB:Q243649
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243649
Reference: BID:769
Reference:
URL:http://www.securityfocus.com/bid/769
Reference: XF:nt-printer-spooler-bo
Name: CVE-1999-0900
Description:
Buffer overflow in rpc.yppasswdd allows a local user to
gain privileges via MD5 hash generation. Status:
Entry
Reference: REDHAT:RHSA1999046-01
Reference: SUSE:19991023 Security hole in ypserv
< 1.3.9
Reference: DEBIAN:19991027 nis
Name: CVE-1999-0901
Description:
ypserv allows a local user to modify the GECOS and login
shells of other users. Status: Entry
Reference: REDHAT:RHSA1999046-01
Reference: SUSE:19991023 Security hole in ypserv
< 1.3.9
Reference: DEBIAN:19991027 nis
Name: CVE-1999-0902
Description:
ypserv allows local administrators to modify password
tables. Status: Entry
Reference: REDHAT:RHSA1999046-01
Reference: SUSE:19991023 Security hole in ypserv
< 1.3.9
Reference: DEBIAN:19991027 nis
Name: CVE-1999-0903
Description:
genfilt in the AIX Packet Filtering Module does not
properly filter traffic to destination ports greater
than 32767. Status: Entry
Reference: BUGTRAQ:19991025 IBM AIX Packet Filter
module
Reference: BUGTRAQ:19991027 Re: IBM AIX Packet
Filter module (followup)
Reference: XF:aix-genfilt-filtering
Name: CVE-1999-0904
Description:
Buffer overflow in BFTelnet allows remote attackers to
cause a denial of service via a long username.
Status: Entry
Reference: BUGTRAQ:19991103 Remote DoS Attack in
BFTelnet Server v1.1 for Windows NT
Reference: XF:bftelnet-username-dos
Reference: BID:771
Reference:
URL:http://www.securityfocus.com/bid/771
Name: CVE-1999-0905
Description:
Denial of service in Axent Raptor firewall via malformed
zero-length IP options. Status: Entry
Reference: BUGTRAQ:19991020 Remote DoS in Axent's
Raptor 6.0
Reference: BID:736
Reference:
URL:http://www.securityfocus.com/bid/736
Reference: XF:raptor-ipoptions-dos
Reference: OSVDB:1121
Reference: URL:http://www.osvdb.org/1121
Name: CVE-1999-0906
Description:
Buffer overflow in sccw allows local users to gain root
access via the HOME environmental variable. Status:
Entry
Reference: BUGTRAQ:19990923 SuSE 6.2 sccw
overflow exploit
Reference: SUSE:19990926 Security hole in sccw
(Part II)
Reference: BID:656
Reference:
URL:http://www.securityfocus.com/bid/656
Reference: XF:linux-sccw-bo
Name: CVE-1999-0907
Description:
sccw allows local users to read arbitrary files.
Status: Entry
Reference: BUGTRAQ:19990916 SuSE 6.2
/usr/bin/sccw read any file
Reference: SUSE:19990921 Security Hole in
sccw-1.1 and earlier
Name: CVE-1999-0908
Description:
Denial of service in Solaris TCP streams driver via a
malicious connection that causes the server to panic as
a result of recursive calls to mutex_enter. Status:
Entry
Reference: BUGTRAQ:19990921 solaris DoS
Reference: BID:655
Reference:
URL:http://www.securityfocus.com/bid/655
Reference: XF:sun-tcp-mutex-enter-dos
Name: CVE-1999-0909
Description:
Multihomed Windows systems allow a remote attacker to
bypass IP source routing restrictions via a malformed
packet with IP options, aka the "Spoofed Route Pointer"
vulnerability. Status: Entry
Reference: NAI:Windows IP Source Routing
Vulnerability
Reference: MS:MS99-038
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-038.mspx
Reference: MSKB:Q238453
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238453
Reference: BID:646
Reference:
URL:http://www.securityfocus.com/bid/646
Reference: XF:nt-ip-source-route
Name: CVE-1999-0912
Description:
FreeBSD VFS cache (vfs_cache) allows local users to
cause a denial of service by opening a large number of
files. Status: Entry
Reference: BUGTRAQ:19990921 FreeBSD-specific
denial of service
Reference: BID:653
Reference:
URL:http://www.securityfocus.com/bid/653
Reference: XF:freebsd-vfscache-dos
Reference: OSVDB:1079
Reference: URL:http://www.osvdb.org/1079
Name: CVE-1999-0914
Description:
Buffer overflow in the FTP client in the Debian
GNU/Linux netstd package. Status: Entry
Reference: DEBIAN:19990104
Reference: BUGTRAQ:19990103 [SECURITY] New
versions of netstd fixes buffer overflows
Reference: BID:324
Reference:
URL:http://www.securityfocus.com/bid/324
Name: CVE-1999-0915
Description:
URL Live! web server allows remote attackers to read
arbitrary files via a .. (dot dot) attack. Status:
Entry
Reference: BUGTRAQ:19991028 URL Live! 1.0
WebServer
Reference: BID:746
Reference:
URL:http://www.securityfocus.com/bid/746
Reference: OSVDB:1129
Reference: URL:http://www.osvdb.org/1129
Name: CVE-1999-0916
Description:
WebTrends software stores account names and passwords in
a file which does not have restricted access
permissions. Status: Entry
Reference: ISS:19990629 Bad Permissions on
Passwords Stored by WebTrends Software
Name: CVE-1999-0917
Description:
The Preloader ActiveX control used by Internet Explorer
allows remote attackers to read arbitrary files.
Status: Entry
Reference: MS:MS99-018
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-018.mspx
Reference: MSKB:Q231452
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231452
Reference: XF:legacy-activex-local-drive
Name: CVE-1999-0918
Description:
Denial of service in various Windows systems via
malformed, fragmented IGMP packets. Status: Entry
Reference: BUGTRAQ:19990703 IGMP fragmentation
bug in Windows 98/2000
Reference: MSKB:Q238329
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238329
Reference: MS:MS99-034
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-034.mspx
Reference: XF:igmp-dos
Reference: BID:514
Reference:
URL:http://www.securityfocus.com/bid/514
Name: CVE-1999-0920
Description:
Buffer overflow in the pop-2d POP daemon in the IMAP
package allows remote attackers to gain privileges via
the FOLD command. Status: Entry
Reference: BUGTRAQ:19990526 Remote vulnerability
in pop2d
Reference: DEBIAN:19990607a
Reference: BID:283
Reference:
URL:http://www.securityfocus.com/bid/283
Reference: XF:pop2-fold-bo
Name: CVE-1999-0921
Description:
BMC Patrol allows any remote attacker to flood its UDP
port, causing a denial of service. Status: Entry
Reference: BUGTRAQ:19990409 Patrol security bugs
Reference:
URL:http://www.securityfocus.com/archive/1/13204
Reference: XF:bmc-patrol-udp-dos(4291)
Reference:
URL:http://www.iss.net/security_center/static/4291.php
Reference: BID:1879
Reference:
URL:http://www.securityfocus.com/bid/1879
Name: CVE-1999-0922
Description:
An example application in ColdFusion Server 4.0 allows
remote attackers to view source code via the
sourcewindow.cfm file. Status: Entry
Reference: ALLAIRE:ASB99-02
Reference:
URL:http://www.allaire.com/handlers/index.cfm?ID=8739&Method=Full
Reference: XF:coldfusion-sourcewindow
Name: CVE-1999-0924
Description:
The Syntax Checker in ColdFusion Server 4.0 allows
remote attackers to conduct a denial of service.
Status: Entry
Reference: ALLAIRE:ASB99-02
Reference:
URL:http://www.allaire.com/handlers/index.cfm?ID=8739&Method=Full
Reference: XF:coldfusion-syntax-checker(1742)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/1742
Reference: OSVDB:3236
Reference: URL:http://www.osvdb.org/3236
Name: CVE-1999-0927
Description:
NTMail allows remote attackers to read arbitrary files
via a .. (dot dot) attack. Status: Entry
Reference: EEYE:AD05261999
Reference:
URL:http://www.eeye.com/html/Research/Advisories/AD05261999.html
Reference: BID:279
Reference:
URL:http://www.securityfocus.com/bid/279
Reference: XF:ntmail-fileread
Name: CVE-1999-0928
Description:
Buffer overflow in SmartDesk WebSuite allows remote
attackers to cause a denial of service via a long URL.
Status: Entry
Reference: BUGTRAQ:19990525 Buffer overflow in
SmartDesk WebSuite v2.1
Reference: XF:websuite-dos
Reference: BID:278
Reference:
URL:http://www.securityfocus.com/bid/278
Name: CVE-1999-0930
Description:
wwwboard allows a remote attacker to delete message
board articles via a malformed argument. Status:
Entry
Reference: BUGTRAQ:19980903 wwwboard.pl
vulnerability
Reference:
CONFIRM:http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml
Reference: XF:http-cgi-wwwboard(2344)
Reference:
URL:http://xforce.iss.net/static/2344.php
Reference: BID:1795
Reference:
URL:http://www.securityfocus.com/bid/1795
Name: CVE-1999-0931
Description:
Buffer overflow in Mediahouse Statistics Server allows
remote attackers to execute commands. Status:
Entry
Reference: BUGTRAQ:19990930 Security flaw in
Mediahouse Statistics Server v4.28 & 5.01
Reference: BID:734
Reference:
URL:http://www.securityfocus.com/bid/734
Reference: XF:mediahouse-stats-login-bo
Name: CVE-1999-0932
Description:
Mediahouse Statistics Server allows remote attackers to
read the administrator password, which is stored in
cleartext in the ss.cfg file. Status: Entry
Reference: BUGTRAQ:19990930 Security flaw in
Mediahouse Statistics Server v4.28 & 5.01
Reference: BID:735
Reference:
URL:http://www.securityfocus.com/bid/735
Reference: XF:mediahouse-stats-adminpw-cleartext
Name: CVE-1999-0933
Description:
TeamTrack web server allows remote attackers to read
arbitrary files via a .. (dot dot) attack. Status:
Entry
Reference: BUGTRAQ:19991001 RFP9904: TeamTrack
webserver vulnerability
Reference: BID:689
Reference:
URL:http://www.securityfocus.com/bid/689
Reference: OSVDB:1096
Reference: URL:http://www.osvdb.org/1096
Name: CVE-1999-0934
Description:
classifieds.cgi allows remote attackers to read
arbitrary files via shell metacharacters. Status:
Entry
Reference: EL8:19991215 Classifieds
(classifieds.cgi)
Reference: BID:2020
Reference:
URL:http://www.securityfocus.com/bid/2020
Reference: XF:http-cgi-classifieds-read(3102)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/3102
Name: CVE-1999-0935
Description:
classifieds.cgi allows remote attackers to execute
arbitrary commands by specifying them in a hidden
variable in a CGI form. Status: Entry
Reference: EL8:19991215 Classifieds
(classifieds.cgi)
Name: CVE-1999-0936
Description:
BNBSurvey survey.cgi program allows remote attackers to
execute commands via shell metacharacters. Status:
Entry
Reference: EL8:19981203 BNBSurvey (survey.cgi)
Name: CVE-1999-0937
Description:
BNBForm allows remote attackers to read arbitrary files
via the automessage hidden form variable. Status:
Entry
Reference: EL8:19981203 BNBForm (bnbform.cgi)
Name: CVE-1999-0938
Description:
MBone SDR Package allows remote attackers to execute
commands via shell metacharacters in Sesion Initiation
Protocol (SIP) messages. Status: Entry
Reference: CERT:VN-99-03
Reference: XF:sdr-execute
Name: CVE-1999-0939
Description:
Denial of service in Debian IRC Epic/epic4 client via a
long string. Status: Entry
Reference: BUGTRAQ:19990826 [SECURITY] New
versions of epic4 fixes possible DoS vulnerability
Reference: DEBIAN:19990826
Reference: BID:605
Reference:
URL:http://www.securityfocus.com/bid/605
Name: CVE-1999-0940
Description:
Buffer overflow in mutt mail client allows remote
attackers to execute commands via malformed MIME
messages. Status: Entry
Reference: CALDERA:CSSA-1999-031
Reference: SUSE:19990927 Security hole in mutt
Name: CVE-1999-0942
Description:
UnixWare dos7utils allows a local user to gain root
privileges by using the STATICMERGE environmental
variable to find a script which it executes. Status:
Entry
Reference: BUGTRAQ:19991005 SCO UnixWare 7.1
local root exploit
Reference: XF:sco-unixware-dos7utils-root-privs
Name: CVE-1999-0943
Description:
Buffer overflow in OpenLink 3.2 allows remote attackers
to gain privileges via a long GET request to the web
configurator. Status: Entry
Reference: BUGTRAQ:19991015 OpenLink 3.2 Advisory
Reference: BID:720
Reference:
URL:http://www.securityfocus.com/bid/720
Name: CVE-1999-0945
Description:
Buffer overflow in Internet Mail Service (IMS) for
Microsoft Exchange 5.5 and 5.0 allows remote attackers
to conduct a denial of service via AUTH or AUTHINFO
commands. Status: Entry
Reference: ISS:19980724 Denial of Service attacks
against Microsoft Exchange 5.0 to 5.5
Reference:
URL:http://xforce.iss.net/alerts/advise4.php
Reference: CIAC:I-080
Reference:
URL:http://www.ciac.org/ciac/bulletins/i-080.shtml
Reference: MSKB:Q169174
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q169174
Reference: XF:exchange-dos(1223)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/1223
Name: CVE-1999-0946
Description:
Buffer overflow in Yamaha MidiPlug via a Text variable
in an EMBED tag. Status: Entry
Reference: BUGTRAQ:19991102 Some holes for
Win/UNIX softwares
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94157187815629&w=2
Reference: XF:yamaha-midiplug-embed
Reference: BID:760
Reference:
URL:http://www.securityfocus.com/bid/760
Name: CVE-1999-0947
Description:
AN-HTTPd provides example CGI scripts test.bat,
input.bat, input2.bat, and envout.bat, which allow
remote attackers to execute commands via shell
metacharacters. Status: Entry
Reference: BUGTRAQ:19991102 Some holes for
Win/UNIX softwares
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94157187815629&w=2
Reference: BID:762
Reference:
URL:http://www.securityfocus.com/bid/762
Name: CVE-1999-0950
Description:
Buffer overflow in WFTPD FTP server allows remote
attackers to gain root access via a series of MKD and
CWD commands that create nested directories. Status:
Entry
Reference: BUGTRAQ:19991027 WFTPD v2.40 FTPServer
remotely exploitable buffer overflow vulnerability
Reference: BID:747
Reference:
URL:http://www.securityfocus.com/bid/747
Reference: XF:wftpd-mkd-bo
Name: CVE-1999-0951
Description:
Buffer overflow in OmniHTTPd CGI program imagemap.exe
allows remote attackers to execute commands. Status:
Entry
Reference: BUGTRAQ:19991022 Imagemap CGI overflow
exploit
Reference: BID:739
Reference:
URL:http://www.securityfocus.com/bid/739
Reference: XF:http-cgi-imagemap-bo
Reference: OSVDB:3380
Reference: URL:http://www.osvdb.org/3380
Name: CVE-1999-0953
Description:
WWWBoard stores encrypted passwords in a password file
that is under the web root and thus accessible by remote
attackers. Status: Entry
Reference: BUGTRAQ:19980903 wwwboard.pl
vulnerability
Reference: BUGTRAQ:19990916 More fun with
WWWBoard
Name: CVE-1999-0954
Description:
WWWBoard has a default username and default password.
Status: Entry
Reference: BUGTRAQ:19990916 More fun with
WWWBoard
Reference: BID:649
Reference:
URL:http://www.securityfocus.com/bid/649
Name: CVE-1999-0955
Description:
Race condition in wu-ftpd and BSDI ftpd allows remote
attackers gain root access via the SITE EXEC command.
Status: Entry
Reference: CERT:CA-94.08
Reference: CIAC:E-17
Reference: XF:ftp-exec
Name: CVE-1999-0956
Description:
The NeXT NetInfo _writers property allows local users to
gain root privileges or conduct a denial of service.
Status: Entry
Reference: CERT:CA-93.02a
Reference: XF:next-netinfo
Name: CVE-1999-0957
Description:
MajorCool mj_key_cache program allows local users to
modify files via a symlink attack. Status: Entry
Reference: BUGTRAQ:19970618 Security hole in
MajorCool 1.0.3
Reference: XF:majorcool-file-overwrite-vuln
Name: CVE-1999-0958
Description:
sudo 1.5.x allows local users to execute arbitrary
commands via a .. (dot dot) attack. Status: Entry
Reference: BUGTRAQ:19980112 Re: hole in sudo for
MP-RAS.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88465708614896&w=2
Reference: XF:sudo-dot-dot-attack
Name: CVE-1999-0959
Description:
IRIX startmidi program allows local users to modify
arbitrary files via a symlink attack. Status:
Entry
Reference: BUGTRAQ:19970209 IRIX: Bug in
startmidi
Reference: AUSCERT:AA-97-05
Reference: SGI:19980301-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX
Reference: BID:469
Reference:
URL:http://www.securityfocus.com/bid/469
Reference: OSVDB:8447
Reference: URL:http://www.osvdb.org/8447
Reference: XF:irix-startmidi-file-creation((1634)
Name: CVE-1999-0960
Description:
IRIX cdplayer allows local users to create directories
in arbitrary locations via a command line option.
Status: Entry
Reference: AUSCERT:AA-96.11
Reference: SGI:19980301-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX
Reference: XF:irix-cdplayer-directory-create
Name: CVE-1999-0961
Description:
HPUX sysdiag allows local users to gain root privileges
via a symlink attack during log file creation.
Status: Entry
Reference: BUGTRAQ:19960921 Vunerability in HP
sysdiag ?
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419906&w=2
Reference: CIAC:H-03
Reference: XF:hp-sysdiag-symlink
Name: CVE-1999-0962
Description:
Buffer overflow in HPUX passwd command allows local
users to gain root privileges via a command line option.
Status: Entry
Reference: AUSCERT:AA-96.13
Reference: HP:HPSBUX9701-045
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9701-045
Reference: XF:hp-password-cmd-bo
Reference: OSVDB:6415
Reference: URL:http://www.osvdb.org/6415
Name: CVE-1999-0963
Description:
FreeBSD mount_union command allows local users to gain
root privileges via a symlink attack. Status:
Entry
Reference: BUGTRAQ:19960517 BoS: SECURITY BUG in
FreeBSD
Reference: CERT:VB-96.06
Reference: XF:freebsd-mount-union-root
Reference: OSVDB:6088
Reference: URL:http://www.osvdb.org/6088
Name: CVE-1999-0964
Description:
Buffer overflow in FreeBSD setlocale in the libc module
allows attackers to execute arbitrary code via a long
PATH_LOCALE environment variable. Status: Entry
Reference: FREEBSD:FreeBSD-SA-97:01
Reference: XF:freebsd-setlocale-bo
Reference: OSVDB:6086
Reference: URL:http://www.osvdb.org/6086
Name: CVE-1999-0965
Description:
Race condition in xterm allows local users to modify
arbitrary files via the logging option. Status:
Entry
Reference: CERT:CA-93.17
Reference: XF:xterm
Name: CVE-1999-0966
Description:
Buffer overflow in Solaris getopt in libc allows local
users to gain root privileges via a long argv[0].
Status: Entry
Reference: L0PHT:19970127 Solaris libc -
getopt(3)
Name: CVE-1999-0967
Description:
Buffer overflow in the HTML library used by Internet
Explorer, Outlook Express, and Windows Explorer via the
res: local resource protocol. Status: Entry
Reference: L0PHT:19971101 Microsoft Internet
Explorer 4.0 Suite
Name: CVE-1999-0968
Description:
Buffer overflow in BNC IRC proxy allows remote attackers
to gain privileges. Status: Entry
Reference: BUGTRAQ:19981226 bnc exploit
Reference:
URL:http://www.securityfocus.com/archive/1/11711
Reference: XF:bnc-proxy-bo(1546)
Reference:
URL:http://xforce.iss.net/static/1546.php
Reference: BID:1927
Reference:
URL:http://www.securityfocus.com/bid/1927
Name: CVE-1999-0969
Description:
The Windows NT RPC service allows remote attackers to
conduct a denial of service using spoofed malformed RPC
packets which generate an error message that is sent to
the spoofed host, potentially setting up a loop, aka
Snork. Status: Entry
Reference: ISS:19980929 "Snork" Denial of Service
Attack Against Windows NT RPC Service
Reference: NTBUGTRAQ:19980929 ISS Security
Advisory: Snork
Reference: MS:MS98-014
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms98-014.mspx
Reference: MSKB:Q193233
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q193233
Reference: XF:snork-dos
Name: CVE-1999-0971
Description:
Buffer overflow in Exim allows local users to gain root
privileges via a long :include: option in a .forward
file. Status: Entry
Reference: BUGTRAQ:19970722 Security hole in exim
1.62: local root exploit
Reference:
URL:http://www.securityfocus.com/archive/1/7301
Reference: XF:exim-include-overflow
Name: CVE-1999-0972
Description:
Buffer overflow in Xshipwars xsw program. Status:
Entry
Reference: BUGTRAQ:19991209 xsw 1.24 remote
buffer overflow
Reference: BID:863
Reference:
URL:http://www.securityfocus.com/bid/863
Name: CVE-1999-0973
Description:
Buffer overflow in Solaris snoop program allows remote
attackers to gain root privileges via a long domain name
when snoop is running in verbose mode. Status:
Entry
Reference: BUGTRAQ:19991206 [w00giving #8]
Solaris 2.7's snoop
Reference: BUGTRAQ:19991209 Clarification needed
on the snoop vuln(s) (fwd)
Reference: BID:858
Reference:
URL:http://www.securityfocus.com/bid/858
Name: CVE-1999-0974
Description:
Buffer overflow in Solaris snoop allows remote attackers
to gain root privileges via GETQUOTA requests to the
rpc.rquotad service. Status: Entry
Reference: ISS:19991209 Buffer Overflow in
Solaris Snoop
Reference: SUN:00190
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/190
Reference: BUGTRAQ:19991209 Clarification needed
on the snoop vuln(s) (fwd)
Reference: BID:864
Reference:
URL:http://www.securityfocus.com/bid/864
Name: CVE-1999-0975
Description:
The Windows help system can allow a local user to
execute commands as another user by editing a table of
contents metafile with a .CNT extension and modifying
the topic action to include the commands to be executed
when the .hlp file is accessed. Status: Entry
Reference: BUGTRAQ:19991207 Local user can fool
another to run executable. .CNT/.GID/.HLP M$WINNT
Reference: BID:868
Reference:
URL:http://www.securityfocus.com/bid/868
Name: CVE-1999-0976
Description:
Sendmail allows local users to reinitialize the aliases
database via the newaliases command, then cause a denial
of service by interrupting Sendmail. Status:
Entry
Reference: OPENBSD:19991204
Reference: BUGTRAQ:19991207 [Debian] New version
of sendmail released
Reference: XF:sendmail-bi-alias
Reference: BID:857
Reference:
URL:http://www.securityfocus.com/bid/857
Name: CVE-1999-0977
Description:
Buffer overflow in Solaris sadmind allows remote
attackers to gain root privileges using a
NETMGT_PROC_SERVICE request. Status: Entry
Reference: SF-INCIDENTS:19991209 sadmind
Reference: BUGTRAQ:19991210 Solaris sadmind
Buffer Overflow Vulnerability
Reference: BUGTRAQ:19991210 Re: Solaris sadmind
Buffer Overflow Vulnerability
Reference: CERT:CA-99-16
Reference: SUN:00191
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/191
Reference: BID:866
Reference:
URL:http://www.securityfocus.com/bid/866
Reference: BID:2354
Reference:
URL:http://www.securityfocus.com/bid/2354
Reference: XF:sol-sadmind-amslverify-bo
Reference: OSVDB:2558
Reference: URL:http://www.osvdb.org/2558
Name: CVE-1999-0978
Description:
htdig allows remote attackers to execute commands via
filenames with shell metacharacters. Status:
Entry
Reference: DEBIAN:19991209
Reference: BID:867
Reference:
URL:http://www.securityfocus.com/bid/867
Name: CVE-1999-0979
Description:
The SCO UnixWare privileged process system allows local
users to gain root privileges by using a debugger such
as gdb to insert traps into _init before the privileged
process is executed. Status: Entry
Reference: BUGTRAQ:19991209 Fundamental flaw in
UnixWare 7 security
Reference: BUGTRAQ:19991215 Recent postings about
SCO UnixWare 7
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94530783815434&w=2
Reference: BID:869
Reference:
URL:http://www.securityfocus.com/bid/869
Name: CVE-1999-0980
Description:
Windows NT Service Control Manager (SCM) allows remote
attackers to cause a denial of service via a malformed
argument in a resource enumeration request. Status:
Entry
Reference: MS:MS99-055
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-055.mspx
Reference: MSKB:Q246045
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246045
Name: CVE-1999-0981
Description:
Internet Explorer 5.01 and earlier allows a remote
attacker to create a reference to a client window and
use a server-side redirect to access local files via
that window, aka "Server-side Page Reference Redirect."
Status: Entry
Reference: MS:MS99-050
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-050.mspx
Reference: MSKB:Q246094
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246094
Name: CVE-1999-0982
Description:
The Sun Web-Based Enterprise Management (WBEM)
installation script stores a password in plaintext in a
world readable file. Status: Entry
Reference: BUGTRAQ:19991206 Solaris WBEM 1.0:
plaintext password stored in world readable file
Name: CVE-1999-0986
Description:
The ping command in Linux 2.0.3x allows local users to
cause a denial of service by sending large packets with
the -R (record route) option. Status: Entry
Reference: BUGTRAQ:19991209 Big problem on 2.0.x?
Reference: BID:870
Reference:
URL:http://www.securityfocus.com/bid/870
Name: CVE-1999-0987
Description:
Windows NT does not properly download a system policy if
the domain user logs into the domain with a space at the
end of the domain name. Status: Entry
Reference: NTBUGTRAQ:19991118 NT System Policy
for Win95 Not downloaded when adding a space after
domain name
Reference: MSKB:Q237923
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237923
Name: CVE-1999-0989
Description:
Buffer overflow in Internet Explorer 5 directshow filter
(MSDXM.OCX) allows remote attackers to execute commands
via the vnd.ms.radio protocol. Status: Entry
Reference: NTBUGTRAQ:19991205 new IE5 remote
exploit
Reference: BUGTRAQ:19991205 new IE5 remote
exploit
Reference: BID:861
Reference:
URL:http://www.securityfocus.com/bid/861
Name: CVE-1999-0991
Description:
Buffer overflow in GoodTech Telnet Server NT allows
remote users to cause a denial of service via a long
login name. Status: Entry
Reference: NTBUGTRAQ:19991206 Remote DoS Attack
in GoodTech Telnet Server NT v2.2.1 Vulnerability
Reference: BUGTRAQ:19991206 Remote DoS Attack in
GoodTech Telnet Server NT v2.2.1 Vulnerability
Reference: BID:862
Reference:
URL:http://www.securityfocus.com/bid/862
Name: CVE-1999-0992
Description:
HP VirtualVault with the PHSS_17692 patch allows
unprivileged processes to bypass access restrictions via
the Trusted Gateway Proxy (TGP). Status: Entry
Reference: HP:HPSBUX9912-107
Reference:
URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9912-107
Name: CVE-1999-0994
Description:
Windows NT with SYSKEY reuses the keystream that is used
for encrypting SAM password hashes, allowing an attacker
to crack passwords. Status: Entry
Reference: BINDVIEW:19991216 Windows NT's SYSKEY
feature
Reference: MS:MS99-056
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-056.mspx
Reference: MSKB:Q248183
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248183
Reference: BID:873
Reference:
URL:http://www.securityfocus.com/bid/873
Name: CVE-1999-0995
Description:
Windows NT Local Security Authority (LSA) allows remote
attackers to cause a denial of service via malformed
arguments to the LsaLookupSids function which looks up
the SID, aka "Malformed Security Identifier Request."
Status: Entry
Reference: NAI:19991216 Windows NT LSA Remote
Denial of Service
Reference: MS:MS99-057
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-057.mspx
Reference: MSKB:Q248185
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248185
Reference: BID:875
Reference:
URL:http://www.securityfocus.com/bid/875
Name: CVE-1999-0996
Description:
Buffer overflow in Infoseek Ultraseek search engine
allows remote attackers to execute commands via a long
GET request. Status: Entry
Reference: EEYE:AD19991215
Reference:
URL:http://www.eeye.com/html/Research/Advisories/AD19991215.html
Reference: BUGTRAQ:19991216 Infoseek Ultraseek
Remote Buffer Overflow
Reference: NTBUGTRAQ:19991216 Infoseek Ultraseek
Remote Buffer Overflow
Reference: XF:infoseek-ultraseek-bo
Reference: OSVDB:6490
Reference: URL:http://www.osvdb.org/6490
Name: CVE-1999-0997
Description:
wu-ftp with FTP conversion enabled allows an attacker to
execute commands via a malformed file name that is
interpreted as an argument to the program that does the
conversion, e.g. tar or uncompress. Status: Entry
Reference: BUGTRAQ:19991220 Security
vulnerability in certain wu-ftpd (and derivitives)
configurations (fwd)
Reference: DEBIAN:DSA-377
Reference:
URL:http://www.debian.org/security/2003/dsa-377
Reference: XF:wuftp-ftp-conversion
Name: CVE-1999-0998
Description:
Cisco Cache Engine allows an attacker to replace content
in the cache. Status: Entry
Reference: CISCO:19991216 Cisco Cache Engine
Authentication Vulnerabilities
Reference: BUGTRAQ:19991216 Cisco Security
Advisory: Cisco Cache Engine Authentication
Vulnerabilities
Reference: XF:cisco-cache-engine-replace
Name: CVE-1999-0999
Description:
Microsoft SQL 7.0 server allows a remote attacker to
cause a denial of service via a malformed TDS packet.
Status: Entry
Reference: MS:MS99-059
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-059.mspx
Reference: MSKB:Q248749
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248749
Reference: BID:817
Reference:
URL:http://www.securityfocus.com/bid/817
Name: CVE-1999-1000
Description:
The web administration interface for Cisco Cache Engine
allows remote attackers to view performance statistics.
Status: Entry
Reference: CISCO:19991216 Cisco Cache Engine
Authentication Vulnerabilities
Reference: BUGTRAQ:19991216 Cisco Security
Advisory: Cisco Cache Engine Authentication
Vulnerabilities
Reference: XF:cisco-cache-engine-performance
Name: CVE-1999-1001
Description:
Cisco Cache Engine allows a remote attacker to gain
access via a null username and password. Status:
Entry
Reference: CISCO:19991216 Cisco Cache Engine
Authentication Vulnerabilities
Reference: BUGTRAQ:19991216 Cisco Security
Advisory: Cisco Cache Engine Authentication
Vulnerabilities
Name: CVE-1999-1004
Description:
Buffer overflow in the POP server POProxy for the Norton
Anti-Virus protection NAV2000 program via a large USER
command. Status: Entry
Reference: BUGTRAQ:19991217 NAV2000 Email
Protection DoS
Reference:
URL:http://www.securityfocus.com/archive/1/38970
Reference: BUGTRAQ:19991220 Norton Email
Protection Remote Overflow (Addendum)
Reference:
URL:http://www.securityfocus.com/archive/1/39194
Reference:
CONFIRM:http://service1.symantec.com/SUPPORT/nav.nsf/df0a595864594c86852567ac0063608c/6206f660a1f2516a882568660082c930?OpenDocument&Highlight=0,poproxy
Reference: OSVDB:6267
Reference: URL:http://www.osvdb.org/6267
Name: CVE-1999-1005
Description:
Groupwise web server GWWEB.EXE allows remote attackers
to read arbitrary files with .htm extensions via a ..
(dot dot) attack using the HELP parameter. Status:
Entry
Reference: BUGTRAQ:19991219 Groupewise Web
Interface
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94571433731824&w=2
Reference: XF:groupwise-web-read-files
Reference: BID:879
Reference:
URL:http://www.securityfocus.com/bid/879
Reference: OSVDB:3413
Reference: URL:http://www.osvdb.org/3413
Name: CVE-1999-1007
Description:
Buffer overflow in VDO Live Player allows remote
attackers to execute commands on the VDO client via a
malformed .vdo file. Status: Entry
Reference: BUGTRAQ:19991213 VDO Live Player 3.02
Buffer Overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94512259331599&w=2
Reference: XF:vdolive-bo-execute
Reference: BID:872
Reference:
URL:http://www.securityfocus.com/bid/872
Name: CVE-1999-1008
Description:
xsoldier program allows local users to gain root access
via a long argument. Status: Entry
Reference: BUGTRAQ:19991215 FreeBSD 3.3 xsoldier
root exploit
Reference:
MISC:http://marc.theaimsgroup.com/?l=freebsd-security&m=94531826621620&w=2
Reference: BID:871
Reference:
URL:http://www.securityfocus.com/bid/871
Reference: XF:unix-xsoldier-overflow
Name: CVE-1999-1010
Description:
An SSH 1.2.27 server allows a client to use the "none"
cipher, even if it is not allowed by the server policy.
Status: Entry
Reference: BUGTRAQ:19991214 sshd1 allows
unencrypted sessions regardless of server policy
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94519142415338&w=2
Reference: XF:ssh-policy-bypass
Name: CVE-1999-1011
Description:
The Remote Data Service (RDS) DataFactory component of
Microsoft Data Access Components (MDAC) in IIS 3.x and
4.x exposes unsafe methods, which allows remote
attackers to execute arbitrary commands. Status:
Entry
Reference: MS:MS98-004
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms98-004.asp
Reference: MS:MS99-025
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-025.asp
Reference: CIAC:J-054
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-054.shtml
Reference: ISS:19990809 Vulnerabilities in
Microsoft Remote Data Service
Reference: BID:529
Reference:
URL:http://www.ciac.org/ciac/bulletins/j-054.shtml
Reference: XF:nt-iis-rds
Reference: OSVDB:272
Reference: URL:http://www.osvdb.org/272
Name: CVE-1999-1014
Description:
Buffer overflow in mail command in Solaris 2.7 and 2.7
allows local users to gain privileges via a long -m
argument. Status: Entry
Reference: BUGTRAQ:19990913 Solaris 2.7
/usr/bin/mail
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93727925026476&w=2
Reference: BUGTRAQ:19990927 Working Solaris x86
/usr/bin/mail exploit
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93846422810162&w=2
Reference: SUNBUG:4276509
Reference: XF:sun-usrbinmail-local-bo(3297)
Reference:
URL:http://xforce.iss.net/static/3297.php
Reference: BID:672
Reference:
URL:http://www.securityfocus.com/bid/672
Name: CVE-1999-1019
Description:
SpectroSERVER in Cabletron Spectrum Enterprise Manager
5.0 installs a directory tree with insecure permissions,
which allows local users to replace a privileged
executable (processd) with a Trojan horse, facilitating
a root or Administrator compromise. Status: Entry
Reference: BUGTRAQ:19990623 Cabletron Spectrum
security vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93024398713491&w=2
Reference: BUGTRAQ:19990624 Re: Cabletron
Spectrum security vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93024398513475&w=2
Reference: BID:495
Reference:
URL:http://www.securityfocus.com/bid/495
Name: CVE-1999-1021
Description:
NFS on SunOS 4.1 through 4.1.2 ignores the high order 16
bits in a 32 bit UID, which allows a local user to gain
root access if the lower 16 bits are set to 0, as fixed
by the NFS jumbo patch upgrade. Status: Entry
Reference: CERT:CA-1992-15
Reference:
URL:http://www.cert.org/advisories/CA-1992-15.html
Reference: SUN:00117
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/117&type=0&nav=sec.sba
Reference: BID:47
Reference:
URL:http://www.securityfocus.com/bid/47
Reference: XF:nfs-uid(82)
Reference:
URL:http://xforce.iss.net/static/82.php
Name: CVE-1999-1027
Description:
Solaris 2.6 HW3/98 installs admintool with
world-writable permissions, which allows local users to
gain privileges by replacing it with a Trojan horse
program. Status: Entry
Reference: BUGTRAQ:19980507 admintool mode 0777
in Solaris 2.6 HW3/98
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925880&w=2
Reference: SUNBUG:4178998
Reference:
XF:solaris-admintool-world-writable(7296)
Reference:
URL:http://xforce.iss.net/static/7296.php
Reference: BID:290
Reference:
URL:http://www.securityfocus.com/bid/290
Name: CVE-1999-1028
Description:
Symantec pcAnywhere 8.0 allows remote attackers to cause
a denial of service (CPU utilization) via a large amount
of data to port 5631. Status: Entry
Reference: NTBUGTRAQ:19990528 DoS against PC
Anywhere
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92807524225090&w=2
Reference: BID:288
Reference:
URL:http://www.securityfocus.com/bid/288
Reference: XF:pcanywhere-dos(2256)
Reference:
URL:http://www.iss.net/security_center/static/2256.php
Name: CVE-1999-1032
Description:
Vulnerability in LAT/Telnet Gateway (lattelnet) on
Ultrix 4.1 and 4.2 allows attackers to gain root
privileges. Status: Entry
Reference: CERT:CA-1991-11
Reference:
URL:http://www.cert.org/advisories/CA-1991-11.html
Reference: CIAC:B-36
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/b-36.shtml
Reference: BID:26
Reference:
URL:http://www.securityfocus.com/bid/26
Reference: XF:ultrix-telnet(584)
Reference:
URL:http://xforce.iss.net/static/584.php
Name: CVE-1999-1034
Description:
Vulnerability in login in AT&T System V Release 4 allows
local users to gain privileges. Status: Entry
Reference: CERT:CA-1991-08
Reference:
URL:http://www.cert.org/advisories/CA-1991-08.html
Reference: CIAC:B-28
Reference:
URL:http://www.ciac.org/ciac/bulletins/b-28.shtml
Reference: BID:23
Reference:
URL:http://www.securityfocus.com/bid/23
Reference: XF:sysv-login(583)
Reference:
URL:http://xforce.iss.net/static/583.php
Name: CVE-1999-1035
Description:
IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers
to cause a denial of service (hang) via a malformed GET
request, aka the IIS "GET" vulnerability. Status:
Entry
Reference: MS:MS98-019
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms98-019.asp
Reference: MSKB:Q192296
Reference:
URL:http://support.microsoft.com/support/kb/articles/q192/2/96.asp
Reference: XF:iis-get-dos(1823)
Reference:
URL:http://xforce.iss.net/static/1823.php
Name: CVE-1999-1037
Description:
rex.satan in SATAN 1.1.1 allows local users to overwrite
arbitrary files via a symlink attack on the /tmp/rex.$$
file. Status: Entry
Reference: BUGTRAQ:19980626 vulnerability in
satan, cops & tiger
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221103125976&w=2
Reference: BUGTRAQ:19980627 Re: vulnerability in
satan, cops & tiger
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221103125986&w=2
Reference: XF:satan-rexsatan-symlink(7167)
Reference:
URL:http://www.iss.net/security_center/static/7167.php
Reference: OSVDB:3147
Reference: URL:http://www.osvdb.org/3147
Name: CVE-1999-1044
Description:
Vulnerability in Advanced File System Utility (advfs) in
Digital UNIX 4.0 through 4.0d allows local users to gain
privileges. Status: Entry
Reference: COMPAQ:SSRT0495U
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/i-050.shtml
Reference: CIAC:I-050
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/i-050.shtml
Reference: XF:dgux-advfs-softlinks(7431)
Reference:
URL:http://www.iss.net/security_center/static/7431.php
Name: CVE-1999-1045
Description:
pnserver in RealServer 5.0 and earlier allows remote
attackers to cause a denial of service by sending a
short, malformed request. Status: Entry
Reference: BUGTRAQ:19980115 pnserver exploit..
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88492978527261&w=2
Reference: BUGTRAQ:19980115 [rootshell] Security
Bulletin #7
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88490880523890&w=2
Reference: BUGTRAQ:19980817 Re: Real Audio Server
Version 5 bug?
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90338245305236&w=2
Reference:
MISC:http://service.real.com/help/faq/serv501.html
Reference:
XF:realserver-pnserver-remote-dos(7297)
Reference:
URL:http://www.iss.net/security_center/static/7297.php
Reference: OSVDB:6979
Reference: URL:http://www.osvdb.org/6979
Name: CVE-1999-1047
Description:
When BSDI patches for Gauntlet 5.0 BSDI are installed in
a particular order, Gauntlet allows remote attackers to
bypass firewall access restrictions, and does not log
the activities. Status: Entry
Reference: BUGTRAQ:19991018 Gauntlet 5.0 BSDI
warning
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94026690521279&w=2
Reference: BUGTRAQ:19991019 Re: Gauntlet 5.0 BSDI
warning
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94036662326185&w=2
Reference: XF:gauntlet-bsdi-bypass(3397)
Reference:
URL:http://www.iss.net/security_center/static/3397.php
Name: CVE-1999-1048
Description:
Buffer overflow in bash 2.0.0, 1.4.17, and other
versions allows local attackers to gain privileges by
creating an extremely large directory name, which is
inserted into the password prompt via the \w option in
the PS1 environmental variable when another user changes
into that directory. Status: Entry
Reference: BUGTRAQ:19980905 BASH buffer overflow,
LiNUX x86 exploit
Reference:
URL:http://www.securityfocus.com/archive/1/10542
Reference: BUGTRAQ:19970821 Buffer overflow in
/bin/bash
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602746719555&w=2
Reference: DEBIAN:19980909 problem with very long
pathnames
Reference:
URL:http://www.debian.org/security/1998/19980909
Reference: XF:linux-bash-bo(3414)
Reference:
URL:http://xforce.iss.net/static/3414.php
Reference: OSVDB:8345
Reference: URL:http://www.osvdb.org/8345
Name: CVE-1999-1055
Description:
Microsoft Excel 97 does not warn the user before
executing worksheet functions, which could allow
attackers to execute arbitrary commands by using the
CALL function to execute a malicious DLL, aka the Excel
"CALL Vulnerability." Status: Entry
Reference: MS:MS98-018
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms98-018.asp
Reference: BID:179
Reference:
URL:http://www.securityfocus.com/bid/179
Reference: XF:excel-call(1737)
Reference:
URL:http://xforce.iss.net/static/1737.php
Name: CVE-1999-1057
Description:
VMS 4.0 through 5.3 allows local users to gain
privileges via the ANALYZE/PROCESS_DUMP dcl command.
Status: Entry
Reference: CERT:CA-1990-07
Reference:
URL:http://www.cert.org/advisories/CA-1990-07.html
Reference: CIAC:B-04
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/b-04.shtml
Reference: BID:12
Reference:
URL:http://www.securityfocus.com/bid/12
Reference:
XF:vms-analyze-processdump-privileges(7137)
Reference:
URL:http://www.iss.net/security_center/static/7137.php
Name: CVE-1999-1059
Description:
Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP
4.0 for various SVR4 systems allows remote attackers to
execute arbitrary commands. Status: Entry
Reference: CERT:CA-1992-04
Reference:
URL:http://www.cert.org/advisories/CA-1992-04.html
Reference: BID:36
Reference:
URL:http://www.securityfocus.com/bid/36
Reference: XF:att-rexecd(3159)
Reference:
URL:http://www.iss.net/security_center/static/3159.php
Name: CVE-1999-1074
Description:
Webmin before 0.5 does not restrict the number of
invalid passwords that are entered for a valid username,
which could allow remote attackers to gain privileges
via brute force password cracking. Status: Entry
Reference: BUGTRAQ:19980501 Warning! Webmin
Security Advisory
Reference:
URL:http://www.securityfocus.com/archive/1/9138
Reference:
CONFIRM:http://www.webmin.com/webmin/changes.html
Reference: BID:98
Reference:
URL:http://www.securityfocus.com/bid/98
Name: CVE-1999-1080
Description:
rmmount in SunOS 5.7 may mount file systems without the
nosuid flag set, contrary to the documentation and its
use in previous versions of SunOS, which could allow
local users with physical access to gain root privileges
by mounting a floppy or CD-ROM that contains a setuid
program and running volcheck, when the file systems do
not have the nosuid option specified in rmmount.conf.
Status: Entry
Reference: BUGTRAQ:19990510 SunOS 5.7 rmmount, no
nosuid.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92633694100270&w=2
Reference: BUGTRAQ:19991011
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93971288323395&w=2
Reference: BID:250
Reference:
URL:http://www.securityfocus.com/bid/250
Reference: SUNBUG:4205437
Reference: XF:solaris-rmmount-gain-root(8350)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/8350
Name: CVE-1999-1085
Description:
SSH 1.2.25, 1.2.23, and other versions, when used in in
CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64
bits) modes, allows remote attackers to insert arbitrary
data into an existing stream between an SSH client and
server by using a known plaintext attack and computing a
valid CRC-32 checksum for the packet, aka the "SSH
insertion attack." Status: Entry
Reference: BUGTRAQ:19980612 CORE-SDI-04: SSH
insertion attack
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221103125884&w=2
Reference: BUGTRAQ:19980703 UPDATE: SSH insertion
attack
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104525878&w=2
Reference: CISCO:20010627 Multiple SSH
Vulnerabilities
Reference: CERT-VN:VU#13877
Reference:
URL:http://www.kb.cert.org/vuls/id/13877
Reference: XF:ssh-insert(1126)
Reference:
URL:http://www.iss.net/security_center/static/1126.php
Name: CVE-1999-1087
Description:
Internet Explorer 4 treats a 32-bit number ("dotless IP
address") in the a URL as the hostname instead of an IP
address, which causes IE to apply Local Intranet Zone
settings to the resulting web page, allowing remote
malicious web servers to conduct unauthorized activities
by using URLs that contain the dotless IP address for
their server. Status: Entry
Reference: MS:MS98-016
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS98-016.asp
Reference: MSKB:Q168617
Reference:
URL:http://support.microsoft.com/support/kb/articles/q168/6/17.asp
Reference:
CONFIRM:http://www.microsoft.com/Windows/Ie/security/dotless.asp
Reference: OSVDB:7828
Reference: URL:http://www.osvdb.org/7828
Reference: XF:ie-dotless(2209)
Reference:
URL:http://xforce.iss.net/static/2209.php
Name: CVE-1999-1090
Description:
The default configuration of NCSA Telnet package for
Macintosh and PC enables FTP, even though it does not
include an "ftp=yes" line, which allows remote attackers
to read and modify arbitrary files. Status: Entry
Reference: CERT:CA-1991-15
Reference:
URL:http://www.cert.org/advisories/CA-1991-15.html
Reference: XF:ftp-ncsa(1844)
Reference:
URL:http://xforce.iss.net/static/1844.php
Name: CVE-1999-1093
Description:
Buffer overflow in the Window.External function in the
JScript Scripting Engine in Internet Explorer 4.01 SP1
and earlier allows remote attackers to execute arbitrary
commands via a malicious web page. Status: Entry
Reference: MS:MS98-011
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS98-011.asp
Reference: MSKB:Q191200
Reference:
URL:http://support.microsoft.com/support/kb/articles/q191/2/00.asp
Reference: XF:java-script-patch(1276)
Reference:
URL:http://www.iss.net/security_center/static/1276.php
Name: CVE-1999-1094
Description:
Buffer overflow in Internet Explorer 4.01 and earlier
allows remote attackers to execute arbitrary commands
via a long URL with the "mk:" protocol, aka the "MK
Overrun security issue." Status: Entry
Reference: MSKB:Q176697
Reference:
URL:http://support.microsoft.com/support/kb/articles/q176/6/97.asp
Reference: BUGTRAQ:19980114 L0pht Advisory
MSIE4.0(1)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88480839506155&w=2
Reference: XF:iemk-bug(917)
Reference:
URL:http://xforce.iss.net/static/917.php
Name: CVE-1999-1098
Description:
Vulnerability in BSD Telnet client with encryption and
Kerberos 4 authentication allows remote attackers to
decrypt the session via sniffing. Status: Entry
Reference: CERT:CA-1995-03
Reference:
URL:http://www.cert.org/advisories/CA-1995-03.html
Reference: CIAC:F-12
Reference:
URL:http://www.ciac.org/ciac/bulletins/f-12.shtml
Reference: XF:bsd-telnet(516)
Reference:
URL:http://www.iss.net/security_center/static/516.php
Reference: OSVDB:4881
Reference: URL:http://www.osvdb.org/4881
Name: CVE-1999-1099
Description:
Kerberos 4 allows remote attackers to obtain sensitive
information via a malformed UDP packet that generates an
error string that inadvertently includes the realm name
and the last user. Status: Entry
Reference: BUGTRAQ:19961122 L0pht Kerberos
Advisory
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420184&w=2
Reference: XF:kerberos-user-grab(65)
Reference:
URL:http://xforce.iss.net/static/65.php
Name: CVE-1999-1100
Description:
Cisco PIX Private Link 4.1.6 and earlier does not
properly process certain commands in the configuration
file, which reduces the effective key length of the DES
key to 48 bits instead of 56 bits, which makes it easier
for an attacker to find the proper key via a brute force
attack. Status: Entry
Reference: CISCO:19980616 PIX Private Link Key
Processing and Cryptography Issues
Reference:
URL:http://www.cisco.com/warp/public/770/pixkey-pub.shtml
Reference: CIAC:I-056
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/i-056.shtml
Reference: XF:cisco-pix-parse-error(1579)
Reference:
URL:http://xforce.iss.net/static/1579.php
Name: CVE-1999-1102
Description:
lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other
BSD-based operating systems allows local users to create
or overwrite arbitrary files via a symlink attack that
is triggered after invoking lpr 1000 times. Status:
Entry
Reference:
MISC:http://www.phreak.org/archives/security/8lgm/8lgm.lpr
Reference: BUGTRAQ:19940307 8lgm Advisory
Releases
Reference:
URL:http://www.aenigma.net/resources/maillist/bugtraq/1994/0091.htm
Reference: CIAC:E-25a
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/e-25.shtml
Name: CVE-1999-1103
Description:
dxconsole in DEC OSF/1 3.2C and earlier allows local
users to read arbitrary files by specifying the file
with the -file parameter. Status: Entry
Reference: CERT:VB-96.05
Reference:
URL:http://www.cert.org/vendor_bulletins/VB-96.05.dec
Reference: CIAC:G-18
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/g-18.shtml
Reference:
MISC:http://www.tao.ca/fire/bos/0209.html
Reference: XF:osf-dxconsole-gain-privileges(7138)
Reference:
URL:http://www.iss.net/security_center/static/7138.php
Name: CVE-1999-1104
Description:
Windows 95 uses weak encryption for the password list
(.pwl) file used when password caching is enabled, which
allows local users to gain privileges by decrypting the
passwords. Status: Entry
Reference: BUGTRAQ:19951205 Cracked: WINDOWS.PWL
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418931&w=2
Reference: NTBUGTRAQ:19980121 How to recover
private keys for various Microsoft products
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=88540877601866&w=2
Reference: BUGTRAQ:19980120 How to recover
private keys for various Microsoft products
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88536273725787&w=2
Reference: MSKB:Q140557
Reference:
URL:http://support.microsoft.com/support/kb/articles/q140/5/57.asp
Reference: XF:win95-nbsmbpwl(71)
Reference:
URL:http://www.iss.net/security_center/static/71.php
Name: CVE-1999-1105
Description:
Windows 95, when Remote Administration and File Sharing
for NetWare Networks is enabled, creates a share (C$)
when an administrator logs in remotely, which allows
remote attackers to read arbitrary files by mapping the
network drive. Status: Entry
Reference:
CONFIRM:http://www.zdnet.com/eweek/reviews/1016/tr42bug.html
Reference:
MISC:http://www.net-security.sk/bugs/NT/netware1.html
Reference: XF:win95-netware-hidden-share(7231)
Reference:
URL:http://www.iss.net/security_center/static/7231.php
Name: CVE-1999-1109
Description:
Sendmail before 8.10.0 allows remote attackers to cause
a denial of service by sending a series of ETRN commands
then disconnecting from the server, while Sendmail
continues to process the commands after the connection
has been terminated. Status: Entry
Reference: BUGTRAQ:19991222 Re: procmail /
Sendmail - five bugs
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94632241202626&w=2
Reference: BUGTRAQ:20000113 Re: procmail /
Sendmail - five bugs
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94780566911948&w=2
Reference: BID:904
Reference:
URL:http://www.securityfocus.com/bid/904
Reference: XF:sendmail-etrn-dos(7760)
Reference:
URL:http://www.iss.net/security_center/static/7760.php
Name: CVE-1999-1111
Description:
Vulnerability in StackGuard before 1.21 allows remote
attackers to bypass the Random and Terminator Canary
security mechanisms by using a non-linear attack which
directly modifies a pointer to a return address instead
of using a buffer overflow to reach the return address
entry itself. Status: Entry
Reference: BUGTRAQ:19911109 ImmuniX OS Security
Alert: StackGuard 1.21 Released
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94218618329838&w=2
Reference: BID:786
Reference:
URL:http://www.securityfocus.com/bid/786
Reference: XF:immunix-stackguard-bo(3524)
Reference:
URL:http://xforce.iss.net/static/3524.php
Name: CVE-1999-1114
Description:
Buffer overflow in Korn Shell (ksh) suid_exec program on
IRIX 6.x and earlier, and possibly other operating
systems, allows local users to gain root privileges.
Status: Entry
Reference: CIAC:H-15A
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/h-15a.shtml
Reference: AUSCERT:AA-96.17
Reference:
URL:ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.17.suid_exec.vul
Reference: SGI:19980405-01-I
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980405-01-I
Reference: XF:ksh-suid_exec(2100)
Reference:
URL:http://xforce.iss.net/static/2100.php
Reference: BID:467
Reference:
URL:http://www.securityfocus.com/bid/467
Name: CVE-1999-1115
Description:
Vulnerability in the /etc/suid_exec program in HP Apollo
Domain/OS sr10.2 and sr10.3 beta, related to the Korn
Shell (ksh). Status: Entry
Reference: CERT:CA-1990-04
Reference:
URL:http://www.cert.org/advisories/CA-1990-04.html
Reference: CIAC:A-30
Reference:
URL:http://www.ciac.org/ciac/bulletins/a-30.shtml
Reference: BID:7
Reference: URL:http://www.securityfocus.com/bid/7
Reference:
XF:apollo-suidexec-unauthorized-access(6721)
Reference:
URL:http://www.iss.net/security_center/static/6721.php
Name: CVE-1999-1116
Description:
Vulnerability in runpriv in Indigo Magic System
Administration subsystem of SGI IRIX 6.3 and 6.4 allows
local users to gain root privileges. Status:
Entry
Reference: SGI:19970503-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19970503-01-PX
Reference: BID:462
Reference:
URL:http://www.securityfocus.com/bid/462
Reference: OSVDB:1009
Reference: URL:http://www.osvdb.org/1009
Reference: XF:sgi-runpriv(2108)
Reference:
URL:http://xforce.iss.net/static/2108.php
Name: CVE-1999-1117
Description:
lquerypv in AIX 4.1 and 4.2 allows local users to read
arbitrary files by specifying the file in the -h command
line parameter. Status: Entry
Reference: BUGTRAQ:19961124
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&w=2&r=1&s=lquerypv&q=b
Reference: BUGTRAQ:19961125 lquerypv fix
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420195&w=2
Reference: BUGTRAQ:19961125 AIX lquerypv
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420196&w=2
Reference: CIAC:H-13
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/h-13.shtml
Reference: BID:455
Reference:
URL:http://www.securityfocus.com/bid/455
Reference: XF:ibm-lquerypv(1752)
Reference:
URL:http://xforce.iss.net/static/1752.php
Name: CVE-1999-1118
Description:
ndd in Solaris 2.6 allows local users to cause a denial
of service by modifying certain TCP/IP parameters.
Status: Entry
Reference: SUN:00165
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/165&type=0&nav=sec.sba
Reference: BID:433
Reference:
URL:http://www.securityfocus.com/bid/433
Reference: XF:sun-ndd(817)
Reference:
URL:http://xforce.iss.net/static/817.php
Name: CVE-1999-1119
Description:
FTP installation script anon.ftp in AIX insecurely
configures anonymous FTP, which allows remote attackers
to execute arbitrary commands. Status: Entry
Reference: CERT:CA-1992-09
Reference:
URL:http://www.cert.org/advisories/CA-1992-09.html
Reference: BID:41
Reference:
URL:http://www.securityfocus.com/bid/41
Reference: XF:aix-anon-ftp(3154)
Reference:
URL:http://xforce.iss.net/static/3154.php
Name: CVE-1999-1120
Description:
netprint in SGI IRIX 6.4 and earlier trusts the PATH
environmental variable for finding and executing the
disable program, which allows local users to gain
privileges. Status: Entry
Reference: BUGTRAQ:19970104 Irix: netprint story
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420403&w=2
Reference: SGI:19961203-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19961203-01-PX
Reference: SGI:19961203-02-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX
Reference: BID:395
Reference:
URL:http://www.securityfocus.com/bid/395
Reference: OSVDB:993
Reference: URL:http://www.osvdb.org/993
Reference: XF:sgi-netprint(2107)
Reference:
URL:http://xforce.iss.net/static/2107.php
Name: CVE-1999-1121
Description:
The default configuration for UUCP in AIX before 3.2
allows local users to gain root privileges. Status:
Entry
Reference: CERT:CA-1992-06
Reference:
URL:http://www.cert.org/advisories/CA-1992-06.html
Reference: BID:38
Reference:
URL:http://www.securityfocus.com/bid/38
Reference: XF:ibm-uucp(554)
Reference:
URL:http://xforce.iss.net/static/554.php
Reference: OSVDB:891
Reference: URL:http://www.osvdb.org/891
Name: CVE-1999-1122
Description:
Vulnerability in restore in SunOS 4.0.3 and earlier
allows local users to gain privileges. Status:
Entry
Reference: CERT:CA-1989-02
Reference:
URL:http://www.cert.org/advisories/CA-1989-02.html
Reference: CIAC:CIAC-08
Reference:
URL:http://www.ciac.org/ciac/bulletins/ciac-08.shtml
Reference: SUNBUG:1019265
Reference: BID:3
Reference: URL:http://www.securityfocus.com/bid/3
Reference: XF:sun-restore-gain-privileges(6695)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/6695
Name: CVE-1999-1127
Description:
Windows NT 4.0 does not properly shut down invalid named
pipe RPC connections, which allows remote attackers to
cause a denial of service (resource exhaustion) via a
series of connections containing malformed data, aka the
"Named Pipes Over RPC" vulnerability. Status:
Entry
Reference: MS:MS98-017
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms98-017.asp
Reference: MSKB:Q195733
Reference:
URL:http://support.microsoft.com/support/kb/articles/Q195/7/33.asp
Reference: XF:nt-spoolss(523)
Reference:
URL:http://www.iss.net/security_center/static/523.php
Name: CVE-1999-1131
Description:
Buffer overflow in OSF Distributed Computing Environment
(DCE) security demon (secd) in IRIX 6.4 and earlier
allows attackers to cause a denial of service via a long
principal, group, or organization. Status: Entry
Reference: CERT:VB-97.12
Reference:
URL:http://www.cert.org/vendor_bulletins/VB-97.12.opengroup
Reference: CIAC:I-060
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/i-060.shtml
Reference: SGI:19980601-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980601-01-PX
Reference: XF:sgi-osf-dce-dos(1123)
Reference:
URL:http://xforce.iss.net/static/1123.php
Name: CVE-1999-1132
Description:
Windows NT 4.0 allows remote attackers to cause a denial
of service (crash) via extra source routing data such as
(1) a Routing Information Field (RIF) field with a hop
count greater than 7, or (2) a list containing duplicate
Token Ring IDs. Status: Entry
Reference: BUGTRAQ:19981005 NMRC Advisory - Lame
NT Token Ring DoS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90763508011966&w=2
Reference: NTBUGTRAQ:19981002 NMRC Advisory -
Lame NT Token Ring DoS
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=90760603030452&w=2
Reference: MSKB:Q179157
Reference:
URL:http://support.microsoft.com/support/kb/articles/Q179/1/57.asp
Reference: XF:token-ring-dos(1399)
Reference:
URL:http://www.iss.net/security_center/static/1399.php
Name: CVE-1999-1136
Description:
Vulnerability in Predictive on HP-UX 11.0 and earlier,
and MPE/iX 5.5 and earlier, allows attackers to
compromise data transfer for Predictive messages (using
e-mail or modem) between customer and Response Center
Predictive systems. Status: Entry
Reference: HP:HPSBUX9807-081
Reference:
URL:http://www.codetalker.com/advisories/vendor/hp/hpsbux9807-081.html
Reference: HP:HPSBMP9807-005
Reference:
URL:http://cert.ip-plus.net/bulletin-archive/msg00040.html
Reference: BUGTRAQ:19980729 HP-UX Predictive &
Netscape SSL Vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526177&w=2
Reference: CIAC:I-081
Reference:
URL:http://www.ciac.org/ciac/bulletins/i-081.shtml
Reference: XF:mpeix-predictive(1413)
Reference:
URL:http://xforce.iss.net/static/1413.php
Name: CVE-1999-1137
Description:
The permissions for the /dev/audio device on Solaris 2.2
and earlier, and SunOS 4.1.x, allow any local user to
read from the device, which could be used by an attacker
to monitor conversations happening near a machine that
has a microphone. Status: Entry
Reference: CIAC:E-01
Reference:
URL:http://www.ciac.org/ciac/bulletins/e-01.shtml
Reference: SUN:00122
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/122&type=0&nav=sec.sba
Reference: XF:sun-audio(549)
Reference:
URL:http://xforce.iss.net/static/549.php
Reference: OSVDB:6436
Reference: URL:http://www.osvdb.org/6436
Name: CVE-1999-1138
Description:
SCO UNIX System V/386 Release 3.2, and other SCO
products, installs the home directories (1) /tmp for the
dos user, and (2) /usr/tmp for the asg user, which
allows other users to gain access to those accounts
since /tmp and /usr/tmp are world-writable. Status:
Entry
Reference: CERT:CA-1993-13
Reference:
URL:http://www.cert.org/advisories/CA-1993-13.html
Reference: XF:sco-homedir(546)
Reference:
URL:http://xforce.iss.net/static/546.php
Name: CVE-1999-1139
Description:
Character-Terminal User Environment (CUE) in HP-UX 11.0
and earlier allows local users to overwrite arbitrary
files and gain root privileges via a symlink attack on
the IOERROR.mytty file. Status: Entry
Reference: BUGTRAQ:19980121 HP-UX CUE, CUD and
LAND vulnerabilities
Reference:
URL:http://security-archive.merton.ox.ac.uk/bugtraq-199801/0122.html
Reference: BUGTRAQ:19970901 HP UX Bug :)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602880019745&w=2
Reference: HP:HPSBUX9801-074
Reference:
URL:http://www.codetalker.com/advisories/vendor/hp/hpsbux9801-074.html
Reference: CIAC:I-027B
Reference:
URL:http://www.ciac.org/ciac/bulletins/i-027b.shtml
Reference: XF:hp-cue(2007)
Reference:
URL:http://www.iss.net/security_center/static/2007.php
Name: CVE-1999-1140
Description:
Buffer overflow in CrackLib 2.5 may allow local users to
gain root privileges via a long GECOS field. Status:
Entry
Reference: BUGTRAQ:19971214 buffer overflows in
cracklib?!
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88209041500913&w=2
Reference: CERT:VB-97.16
Reference:
URL:http://www.cert.org/vendor_bulletins/VB-97.16.CrackLib
Reference: XF:cracklib-bo(1539)
Reference:
URL:http://xforce.iss.net/static/1539.php
Name: CVE-1999-1142
Description:
SunOS 4.1.2 and earlier allows local users to gain
privileges via "LD_*" environmental variables to certain
dynamically linked setuid or setgid programs such as (1)
login, (2) su, or (3) sendmail, that change the real and
effective user ids to the same user. Status:
Entry
Reference: CERT:CA-1992-11
Reference:
URL:http://www.cert.org/advisories/CA-1992-11.html
Reference: SUN:00116
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/116
Reference: XF:sun-env(3152)
Reference:
URL:http://xforce.iss.net/static/3152.php
Name: CVE-1999-1143
Description:
Vulnerability in runtime linker program rld in SGI IRIX
6.x and earlier allows local users to gain privileges
via setuid and setgid programs. Status: Entry
Reference: CIAC:H-065
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/h-65.shtml
Reference: SGI:19970504-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19970504-01-PX
Reference: XF:sgi-rld(2109)
Reference:
URL:http://xforce.iss.net/static/2109.php
Name: CVE-1999-1144
Description:
Certain files in MPower in HP-UX 10.x are installed with
insecure permissions, which allows local users to gain
privileges. Status: Entry
Reference: HP:HPSBUX9701-051
Reference:
URL:http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-051.html
Reference: XF:hp-mpower(2056)
Reference:
URL:http://xforce.iss.net/static/2056.php
Name: CVE-1999-1145
Description:
Vulnerability in Glance programs in GlancePlus for HP-UX
10.20 and earlier allows local users to access arbitrary
files and gain privileges. Status: Entry
Reference: HP:HPSBUX9701-044
Reference:
URL:http://www.securityfocus.com/templates/advisory.html?id=1514
Reference: CIAC:H-21
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/h-21.shtml
Reference: XF:hp-glanceplus(2059)
Reference:
URL:http://xforce.iss.net/static/2059.php
Name: CVE-1999-1146
Description:
Vulnerability in Glance and gpm programs in GlancePlus
for HP-UX 9.x and earlier allows local users to access
arbitrary files and gain privileges. Status:
Entry
Reference: HP:HPSBUX9405-011
Reference:
URL:http://www.securityfocus.com/advisories/1555
Reference: XF:hp-glanceplus-gpm(2060)
Reference:
URL:http://xforce.iss.net/static/2060.php
Name: CVE-1999-1147
Description:
Buffer overflow in Platinum Policy Compliance Manager
(PCM) 7.0 allows remote attackers to execute arbitrary
commands via a long string to the Agent port (1827),
which is handled by smaxagent.exe. Status: Entry
Reference: BUGTRAQ:19981204
[SAFER-981204.DOS.1.3] Buffer Overflow in Platinum PCM
7.0
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91273739726314&w=2
Reference: BUGTRAQ:19981207 Re:
[SAFER-981204.DOS.1.3] Buffer Overflow in Platinum PCM
7.0
Reference: XF:pcm-dos-execute(1430)
Reference:
URL:http://xforce.iss.net/static/1430.php
Reference: OSVDB:3164
Reference: URL:http://www.osvdb.org/3164
Name: CVE-1999-1148
Description:
FTP service in IIS 4.0 and earlier allows remote
attackers to cause a denial of service (resource
exhaustion) via many passive (PASV) connections at the
same time. Status: Entry
Reference: MS:MS98-006
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms98-006.asp
Reference: MSKB:Q189262
Reference:
URL:http://support.microsoft.com/support/kb/articles/Q189/2/62.ASP
Reference: XF:iis-passive-ftp(1215)
Reference:
URL:http://xforce.iss.net/static/1215.php
Name: CVE-1999-1156
Description:
BisonWare FTP Server 4.1 and earlier allows remote
attackers to cause a denial of service via a malformed
PORT command that contains a non-numeric character and a
large number of carriage returns. Status: Entry
Reference: NTBUGTRAQ:19990517 Vulnerabilities in
BisonWare FTP Server 3.5
Reference: XF:bisonware-port-crash(2254)
Reference:
URL:http://xforce.iss.net/static/2254.php
Name: CVE-1999-1157
Description:
Tcpip.sys in Windows NT 4.0 before SP4 allows remote
attackers to cause a denial of service via an ICMP
Subnet Mask Address Request packet, when certain
multiple IP addresses are bound to the same network
interface. Status: Entry
Reference: MSKB:Q192774
Reference:
URL:http://support.microsoft.com/support/kb/articles/Q192/7/74.ASP
Reference: XF:tcpipsys-icmp-dos(3894)
Reference:
URL:http://xforce.iss.net/static/3894.php
Name: CVE-1999-1159
Description:
SSH 2.0.11 and earlier allows local users to request
remote forwarding from privileged ports without being
root. Status: Entry
Reference: BUGTRAQ:19981229 ssh2 security problem
(and patch) (fwd)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91495920911490&w=2
Reference: XF:ssh-privileged-port-forward(1471)
Reference:
URL:http://xforce.iss.net/static/1471.php
Name: CVE-1999-1160
Description:
Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows
local and possibly remote users to gain root privileges.
Status: Entry
Reference: HP:HPSBUX9702-055
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420581&w=2
Reference: CIAC:H-33
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/h-33.shtml
Reference: XF:hp-ftpd-kftpd(7437)
Reference:
URL:http://www.iss.net/security_center/static/7437.php
Name: CVE-1999-1161
Description:
Vulnerability in ppl in HP-UX 10.x and earlier allows
local users to gain root privileges by forcing ppl to
core dump. Status: Entry
Reference: BUGTRAQ:19961103 Re: Untitled
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420102&w=2
Reference: BUGTRAQ:19961104 ppl bugs
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420103&w=2
Reference: HP:HPSBUX9704-057
Reference:
URL:http://www.codetalker.com/advisories/vendor/hp/hpsbux9704-057.html
Reference: CIAC:H-32
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/h-32.shtml
Reference: AUSCERT:AA-97.07
Reference: XF:hp-ppl(7438)
Reference:
URL:http://www.iss.net/security_center/static/7438.php
Name: CVE-1999-1162
Description:
Vulnerability in passwd in SCO UNIX 4.0 and earlier
allows attackers to cause a denial of service by
preventing users from being able to log into the system.
Status: Entry
Reference: CERT:CA-1993-08
Reference:
URL:http://www.cert.org/advisories/CA-1993-08.html
Reference: XF:sco-passwd-deny(542)
Reference:
URL:http://www.iss.net/security_center/static/542.php
Name: CVE-1999-1163
Description:
Vulnerability in HP Series 800 S/X/V Class servers
allows remote attackers to gain access to the S/X/V
Class console via the Service Support Processor (SSP)
Teststation. Status: Entry
Reference: HP:HPSBUX9911-105
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94347039929958&w=2
Reference: XF:hp-ssp(7439)
Reference:
URL:http://www.iss.net/security_center/static/7439.php
Name: CVE-1999-1167
Description:
Cross-site scripting vulnerability in Third Voice Web
annotation utility allows remote users to read sensitive
data and generate fake web pages for other Third Voice
users by injecting malicious Javascript into an
annotation. Status: Entry
Reference:
CONFIRM:http://www.wired.com/news/technology/0,1282,20677,00.html
Reference:
MISC:http://www.wired.com/news/technology/0,1282,20636,00.html
Reference:
XF:thirdvoice-cross-site-scripting(7252)
Reference:
URL:http://www.iss.net/security_center/static/7252.php
Name: CVE-1999-1175
Description:
Web Cache Control Protocol (WCCP) in Cisco Cache Engine
for Cisco IOS 11.2 and earlier does not use
authentication, which allows remote attackers to
redirect HTTP traffic to arbitrary hosts via WCCP
packets to UDP port 2048. Status: Entry
Reference: CISCO:19980513 Cisco Web Cache Control
Protocol Router Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/770/wccpauth-pub.shtml
Reference: CIAC:I-054
Reference:
URL:http://www.ciac.org/ciac/bulletins/i-054.shtml
Reference: XF:cisco-wccp-vuln(1577)
Reference:
URL:http://xforce.iss.net/static/1577.php
Name: CVE-1999-1177
Description:
Directory traversal vulnerability in nph-publish before
1.2 allows remote attackers to overwrite arbitrary files
via a .. (dot dot) in the pathname for an upload
operation. Status: Entry
Reference:
MISC:http://www.w3.org/Security/Faq/wwwsf4.html
Reference:
CONFIRM:http://www-genome.wi.mit.edu/WWW/tools/CGI_scripts/server_publish/nph-publish
Reference: XF:http-cgi-nphpublish(2055)
Reference:
URL:http://xforce.iss.net/static/2055.php
Name: CVE-1999-1181
Description:
Vulnerability in On-Line Customer Registration software
for IRIX 6.2 through 6.4 allows local users to gain root
privileges. Status: Entry
Reference: SGI:19980901-01-PX
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19980901-01-PX
Reference: CIAC:J-003
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/j-003.shtml
Reference: XF:irix-register(7441)
Reference:
URL:http://www.iss.net/security_center/static/7441.php
Name: CVE-1999-1188
Description:
mysqld in MySQL 3.21 creates log files with
world-readable permissions, which allows local users to
obtain passwords for users who are added to the user
database. Status: Entry
Reference: BUGTRAQ:19981227 mysql: mysqld creates
world readable logs..
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91479159617803&w=2
Reference: XF:mysql-readable-log-files(1568)
Reference:
URL:http://xforce.iss.net/static/1568.php
Name: CVE-1999-1189
Description:
Buffer overflow in Netscape Navigator/Communicator 4.7
for Windows 95 and Windows 98 allows remote attackers to
cause a denial of service, and possibly execute
arbitrary commands, via a long argument after the ?
character in a URL that references an .asp, .cgi, .html,
or .pl file. Status: Entry
Reference: BUGTRAQ:19991124 Netscape Communicator
4.7 - Navigator Overflows
Reference:
URL:http://www.securityfocus.com/archive/1/36306
Reference: BUGTRAQ:19991127 Netscape Communicator
4.7 - Navigator Overflows
Reference:
URL:http://www.securityfocus.com/archive/1/36608
Reference: BID:822
Reference:
URL:http://www.securityfocus.com/bid/822
Reference: XF:netscape-long-argument-bo(7884)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7884
Name: CVE-1999-1191
Description:
Buffer overflow in chkey in Solaris 2.5.1 and earlier
allows local users to gain root privileges via a long
command line argument. Status: Entry
Reference: BUGTRAQ:19970519 Re: Finally, most of
an exploit for Solaris 2.5.1's ps.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418335&w=2
Reference: AUSCERT:AA-97.18
Reference:
URL:ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.18.solaris.chkey.buffer.overflow.vul
Reference: SUN:00144
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/144
Reference: BID:207
Reference:
URL:http://www.securityfocus.com/bid/207
Reference: XF:solaris-chkey-bo(7442)
Reference:
URL:http://www.iss.net/security_center/static/7442.php
Name: CVE-1999-1192
Description:
Buffer overflow in eeprom in Solaris 2.5.1 and earlier
allows local users to gain root privileges via a long
command line argument. Status: Entry
Reference: SUN:00143
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/143
Reference: BID:206
Reference:
URL:http://www.securityfocus.com/bid/206
Reference: XF:solaris-eeprom-bo(7444)
Reference:
URL:http://www.iss.net/security_center/static/7444.php
Name: CVE-1999-1193
Description:
The "me" user in NeXT NeXTstep 2.1 and earlier has wheel
group privileges, which could allow the me user to use
the su command to become root. Status: Entry
Reference: CERT:CA-1991-06
Reference:
URL:http://www.cert.org/advisories/CA-1991-06.html
Reference: XF:next-me(581)
Reference:
URL:http://xforce.iss.net/static/581.php
Reference: BID:20
Reference:
URL:http://www.securityfocus.com/bid/20
Name: CVE-1999-1194
Description:
chroot in Digital Ultrix 4.1 and 4.0 is insecurely
installed, which allows local users to gain privileges.
Status: Entry
Reference: CERT:CA-1991-05
Reference:
URL:http://www.cert.org/advisories/CA-1991-05.html
Reference: BID:17
Reference:
URL:http://www.securityfocus.com/bid/17
Reference: XF:dec-chroot(577)
Reference:
URL:http://xforce.iss.net/static/577.php
Name: CVE-1999-1197
Description:
TIOCCONS in SunOS 4.1.1 does not properly check the
permissions of a user who tries to redirect console
output and input, which could allow a local user to gain
privileges. Status: Entry
Reference: CERT:CA-1990-12
Reference:
URL:http://www.cert.org/advisories/CA-1990-12.html
Reference: BID:14
Reference:
URL:http://www.securityfocus.com/bid/14
Reference:
XF:sunos-tioccons-console-redirection(7140)
Reference:
URL:http://www.iss.net/security_center/static/7140.php
Name: CVE-1999-1198
Description:
BuildDisk program on NeXT systems before 2.0 does not
prompt users for the root password, which allows local
users to gain root privileges. Status: Entry
Reference: CERT:CA-1990-06
Reference:
URL:http://www.cert.org/advisories/CA-1990-06.html
Reference: CIAC:B-01
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/b-01.shtml
Reference: BID:11
Reference:
URL:http://www.securityfocus.com/bid/11
Reference:
XF:nextstep-builddisk-root-access(7141)
Reference:
URL:http://www.iss.net/security_center/static/7141.php
Name: CVE-1999-1199
Description:
Apache WWW server 1.3.1 and earlier allows remote
attackers to cause a denial of service (resource
exhaustion) via a large number of MIME headers with the
same name, aka the "sioux" vulnerability. Status:
Entry
Reference: BUGTRAQ:19980807 YA Apache DoS attack
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90252779826784&w=2
Reference: BUGTRAQ:19980808 Debian Apache
Security Update
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90276683825862&w=2
Reference: BUGTRAQ:19980810 Apache DoS Attack
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90286768232093&w=2
Reference: BUGTRAQ:19980811 Apache 'sioux' DOS
fix for TurboLinux
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90280517007869&w=2
Reference:
CONFIRM:http://www.redhat.com/support/errata/rh51-errata-general.html#apache
Name: CVE-1999-1201
Description:
Windows 95 and Windows 98 systems, when configured with
multiple TCP/IP stacks bound to the same MAC address,
allow remote attackers to cause a denial of service
(traffic amplification) via a certain ICMP echo (ping)
packet, which causes all stacks to send a ping response,
aka TCP Chorusing. Status: Entry
Reference: NTBUGTRAQ:19990206 New Windows 9x Bug:
TCP Chorusing
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91849617221319&w=2
Reference: BID:225
Reference:
URL:http://www.securityfocus.com/bid/225
Reference: XF:win-multiple-ip-dos(7542)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7542
Name: CVE-1999-1203
Description:
Multilink PPP for ISDN dialup users in Ascend before 4.6
allows remote attackers to cause a denial of service via
a spoofed endpoint identifier. Status: Entry
Reference: BUGTRAQ:19990210 Security problems in
ISDN equipment authentication
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91868964203769&w=2
Reference: BUGTRAQ:19990212 PPP/ISDN multilink
security issue - summary
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91888117502765&w=2
Reference: XF:ascend-ppp-isdn-dos(7498)
Reference:
URL:http://www.iss.net/security_center/static/7498.php
Name: CVE-1999-1204
Description:
Check Point Firewall-1 does not properly handle certain
restricted keywords (e.g., Mail, auth, time) in
user-defined objects, which could produce a rule with a
default "ANY" address and result in access to more
systems than intended by the administrator. Status:
Entry
Reference: BUGTRAQ:19980511 Firewall-1 Reserved
Keywords Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925912&w=2
Reference:
CONFIRM:http://www.checkpoint.com/techsupport/config/keywords.html
Reference:
XF:fw1-user-defined-keywords-access(7293)
Reference:
URL:http://xforce.iss.net/static/7293.php
Reference: OSVDB:4416
Reference: URL:http://www.osvdb.org/4416
Name: CVE-1999-1205
Description:
nettune in HP-UX 10.01 and 10.00 is installed setuid
root, which allows local users to cause a denial of
service by modifying critical networking configuration
information. Status: Entry
Reference: BUGTRAQ:19960607 HP-UX B.10.01
vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419195&w=2
Reference: HP:HPSBUX9607-035
Reference:
URL:http://packetstormsecurity.org/advisories/ibm-ers/96-08
Reference: CIAC:G-34
Reference: XF:hp-nettune(414)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/414
Name: CVE-1999-1208
Description:
Buffer overflow in ping in AIX 4.2 and earlier allows
local users to gain root privileges via a long command
line argument. Status: Entry
Reference: BUGTRAQ:19970721 AIX ping, lchangelv,
xlock fixes
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602661419337&w=2
Reference: BUGTRAQ:19970721 AIX ping (Exploit)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602661419330&w=2
Reference: XF:ping-bo(803)
Reference:
URL:http://xforce.iss.net/static/803.php
Name: CVE-1999-1209
Description:
Vulnerability in scoterm in SCO OpenServer 5.0 and SCO
Open Desktop/Open Server 3.0 allows local users to gain
root privileges. Status: Entry
Reference: BUGTRAQ:19971204 scoterm exploit
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88131151000069&w=2
Reference: CERT:VB-97.14
Reference:
URL:http://www.cert.org/vendor_bulletins/VB-97.14.scoterm
Reference: XF:sco-scoterm(690)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/690
Name: CVE-1999-1214
Description:
The asynchronous I/O facility in 4.4 BSD kernel does not
check user credentials when setting the recipient of I/O
notification, which allows local users to cause a denial
of service by using certain ioctl and fcntl calls to
cause the signal to be sent to an arbitrary process ID.
Status: Entry
Reference: OPENBSD:19970915 Vulnerability in I/O
Signal Handling
Reference:
URL:http://www.openbsd.com/advisories/signals.txt
Reference:
MISC:http://www.openbsd.com/advisories/signals.txt
Reference: OSVDB:11062
Reference: URL:http://www.osvdb.org/11062
Reference: XF:openbsd-iosig(556)
Reference:
URL:http://xforce.iss.net/static/556.php
Name: CVE-1999-1215
Description:
LOGIN.EXE program in Novell Netware 4.0 and 4.01
temporarily writes user name and password information to
disk, which could allow local users to gain privileges.
Status: Entry
Reference: CIAC:D-21
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/d-21.shtml
Reference: CERT:CA-1993-12
Reference:
URL:http://www.cert.org/advisories/CA-1993-12.html
Reference: XF:novell-login(545)
Reference:
URL:http://xforce.iss.net/static/545.php
Name: CVE-1999-1217
Description:
The PATH in Windows NT includes the current working
directory (.), which could allow local users to gain
privileges by placing Trojan horse programs with the
same name as commonly used system programs into certain
directories. Status: Entry
Reference: NTBUGTRAQ:19970725 Re: NT security -
why bother?
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=87602726319435&w=2
Reference: NTBUGTRAQ:19970723 NT security - why
bother?
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=87602726319426&w=2
Reference: XF:nt-path(526)
Reference:
URL:http://xforce.iss.net/static/526.php
Name: CVE-1999-1222
Description:
Netbt.sys in Windows NT 4.0 allows remote malicious DNS
servers to cause a denial of service (crash) by
returning 0.0.0.0 as the IP address for a DNS host name
lookup. Status: Entry
Reference: MSKB:Q188571
Reference:
URL:http://support.microsoft.com/support/kb/articles/Q188/5/71.ASP
Reference: XF:dns-netbtsys-dos(3893)
Reference:
URL:http://xforce.iss.net/static/3893.php
Name: CVE-1999-1223
Description:
IIS 3.0 allows remote attackers to cause a denial of
service via a request to an ASP page in which the URL
contains a large number of / (forward slash) characters.
Status: Entry
Reference: MSKB:Q187503
Reference:
URL:http://support.microsoft.com/support/kb/articles/q187/5/03.asp
Reference: XF:url-asp-av(3892)
Reference:
URL:http://xforce.iss.net/static/3892.php
Name: CVE-1999-1226
Description:
Netscape Communicator 4.7 and earlier allows remote
attackers to cause a denial of service, and possibly
execute arbitrary commands, via a long certificate key.
Status: Entry
Reference:
MISC:http://www.securiteam.com/exploits/Netscape_4_7_and_earlier_vulnerable_to__Huge_Key__DoS.html
Reference: XF:netscape-huge-key-dos(3436)
Reference:
URL:http://xforce.iss.net/static/3436.php
Name: CVE-1999-1233
Description:
IIS 4.0 does not properly restrict access for the
initial session request from a user's IP address if the
address does not resolve to a DNS domain, aka the
"Domain Resolution" vulnerability. Status: Entry
Reference: MS:MS99-039
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms99-039.asp
Reference: MSKB:241562
Reference:
URL:http://support.microsoft.com/support/kb/articles/Q241/5/62.asp
Reference: BID:657
Reference:
URL:http://www.securityfocus.com/bid/657
Reference: XF:iis-unresolved-domain-access(3306)
Reference:
URL:http://xforce.iss.net/static/3306.php
Name: CVE-1999-1243
Description:
SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier
allows local users to modify permissions for arbitrary
files and gain privileges. Status: Entry
Reference: CIAC:F-16
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/f-16.shtml
Reference: SGI:19950301-01-P373
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19950301-01-P373
Reference: XF:sgi-permissions(2113)
Reference:
URL:http://xforce.iss.net/static/2113.php
Name: CVE-1999-1246
Description:
Direct Mailer feature in Microsoft Site Server 3.0 saves
user domain names and passwords in plaintext in the
TMLBQueue network share, which has insecure default
permissions, allowing remote attackers to read the
passwords and gain privileges. Status: Entry
Reference: MSKB:Q229972
Reference:
URL:http://support.microsoft.com/support/kb/articles/Q229/9/72.asp
Reference:
XF:siteserver-directmail-passwords(2068)
Reference:
URL:http://xforce.iss.net/static/2068.php
Name: CVE-1999-1249
Description:
movemail in HP-UX 10.20 has insecure permissions, which
allows local users to gain privileges. Status:
Entry
Reference: HP:HPSBUX9701-047
Reference:
URL:http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-047.html
Reference: XF:hp-movemail(2057)
Reference:
URL:http://xforce.iss.net/static/2057.php
Reference: OSVDB:8099
Reference: URL:http://www.osvdb.org/8099
Name: CVE-1999-1258
Description:
rpc.pwdauthd in SunOS 4.1.1 and earlier does not
properly prevent remote access to the daemon, which
allows remote attackers to obtain sensitive system
information. Status: Entry
Reference: SUN:00102
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/102
Reference: XF:sun-pwdauthd(1782)
Reference:
URL:http://xforce.iss.net/static/1782.php
Name: CVE-1999-1259
Description:
Microsoft Office 98, Macintosh Edition, does not
properly initialize the disk space used by Office 98
files and effectively inserts data from previously
deleted files into the Office file, which could allow
attackers to obtain sensitive information. Status:
Entry
Reference: MSKB:Q189529
Reference:
URL:http://support.microsoft.com/support/kb/articles/q189/5/29.asp
Reference: XF:office-extraneous-data(1780)
Reference:
URL:http://xforce.iss.net/static/1780.php
Name: CVE-1999-1262
Description:
Java in Netscape 4.5 does not properly restrict applets
from connecting to other hosts besides the one from
which the applet was loaded, which violates the Java
security model and could allow remote attackers to
conduct unauthorized activities. Status: Entry
Reference: BUGTRAQ:19990202 Unsecured server in
applets under Netscape
Reference:
URL:http://www.securityfocus.com/archive/1/12231
Reference: XF:java-socket-open(1727)
Reference:
URL:http://xforce.iss.net/static/1727.php
Name: CVE-1999-1263
Description:
Metamail before 2.7-7.2 allows remote attackers to
overwrite arbitrary files via an e-mail message
containing a uuencoded attachment that specifies the
full pathname for the file to be modified, which is
processed by uuencode in Metamail scripts such as
sun-audio-file. Status: Entry
Reference: BUGTRAQ:19971024 Vulnerability in
metamail
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87773365324657&w=2
Reference: XF:metamail-file-creation(1677)
Reference:
URL:http://xforce.iss.net/static/1677.php
Name: CVE-1999-1276
Description:
fte-console in the fte package before 0.46b-4.1 does not
drop root privileges, which allows local users to gain
root access via the virtual console device. Status:
Entry
Reference: DEBIAN:19981207 fte-console: does not
drop its root priviliges
Reference:
URL:http://www.debian.org/security/1998/19981207
Reference: XF:fte-console-privileges(1609)
Reference:
URL:http://xforce.iss.net/static/1609.php
Name: CVE-1999-1279
Description:
An interaction between the AS/400 shared folders feature
and Microsoft SNA Server 3.0 and earlier allows users to
view each other's folders when the users share the same
Local APPC LU. Status: Entry
Reference: MSKB:Q138001
Reference:
URL:http://support.microsoft.com/support/kb/articles/q138/0/01.asp
Reference: XF:snaserver-shared-folders(1548)
Reference:
URL:http://xforce.iss.net/static/1548.php
Name: CVE-1999-1284
Description:
NukeNabber allows remote attackers to cause a denial of
service by connecting to the NukeNabber port (1080)
without sending any data, which causes the CPU usage to
rise to 100% from the report.exe program that is
executed upon the connection. Status: Entry
Reference: BUGTRAQ:19981105 various *lame* DoS
attacks
Reference:
URL:http://www.securityfocus.com/archive/1/11131
Reference: BUGTRAQ:19981107 Re: various *lame*
DoS attacks
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91063407332594&w=2
Reference:
MISC:http://www.dynamsol.com/puppet/text/new.txt
Reference: XF:nukenabber-timeout-dos(1540)
Reference:
URL:http://xforce.iss.net/static/1540.php
Name: CVE-1999-1288
Description:
Samba 1.9.18 inadvertently includes a prototype
application, wsmbconf, which is installed with incorrect
permissions including the setgid bit, which allows local
users to read and write files and possibly gain
privileges via bugs in the program. Status: Entry
Reference: BUGTRAQ:19981119 Vulnerability in
Samba on RedHat, Caldera and PHT TurboLinux
Reference:
URL:http://www.securityfocus.com/archive/1/11397
Reference: CALDERA:SA-1998.35
Reference:
URL:http://www.caldera.com/support/security/advisories/SA-1998.35.txt
Reference: XF:samba-wsmbconf(1406)
Reference:
URL:http://xforce.iss.net/static/1406.php
Name: CVE-1999-1290
Description:
Buffer overflow in nftp FTP client version 1.40 allows
remote malicious FTP servers to cause a denial of
service, and possibly execute arbitrary commands, via a
long response string. Status: Entry
Reference: BUGTRAQ:19981117 nftp vulnerability
(fwd)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91127951426494&w=2
Reference:
CONFIRM:http://www.ayukov.com/nftp/history.html
Reference: XF:nftp-bo(1397)
Reference:
URL:http://xforce.iss.net/static/1397.php
Name: CVE-1999-1294
Description:
Office Shortcut Bar (OSB) in Windows 3.51 enables backup
and restore permissions, which are inherited by programs
such as File Manager that are started from the Shortcut
Bar, which could allow local users to read folders for
which they do not have permission. Status: Entry
Reference: MSKB:Q146604
Reference:
URL:http://support.microsoft.com/support/kb/articles/q146/6/04.asp
Reference: XF:nt-filemgr(562)
Reference:
URL:http://xforce.iss.net/static/562.php
Name: CVE-1999-1297
Description:
cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4
and earlier allows attackers with physical access to the
system to display unechoed characters (such as those
from password prompts) via the L2/AGAIN key. Status:
Entry
Reference: SUNBUG:1077164
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100452&zone_32=10045%2A%20
Reference: XF:sun-cmdtool-echo(7482)
Reference:
URL:http://xforce.iss.net/static/7482.php
Name: CVE-1999-1298
Description:
Sysinstall in FreeBSD 2.2.1 and earlier, when
configuring anonymous FTP, creates the ftp user without
a password and with /bin/date as the shell, which could
allow attackers to gain access to certain system
resources. Status: Entry
Reference: FREEBSD:FreeBSD-SA-97:03
Reference: URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-97:03.sysinstall.asc
Reference:
XF:freebsd-sysinstall-ftp-password(7537)
Reference: URL:http://www.iss.net/security_center/static/7537.php
Reference: OSVDB:6087
Reference: URL:http://www.osvdb.org/6087
Name: CVE-1999-1301
Description:
A design flaw in the Z-Modem protocol allows the remote
sender of a file to execute arbitrary programs on the
client, as implemented in rz in the rzsz module of
FreeBSD before 2.1.5, and possibly other programs.
Status: Entry
Reference: CIAC:G-31
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/g-31.shtml
Reference: FREEBSD:FreeBSD-SA-96:17
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:17.rzsz.asc
Reference: XF:rzsz-command-execution(7540)
Reference:
URL:http://www.iss.net/security_center/static/7540.php
Name: CVE-1999-1309
Description:
Sendmail before 8.6.7 allows local users to gain root
access via a large value in the debug (-d) command line
option. Status: Entry
Reference: BUGTRAQ:19940314 sendmail -d problem
(OLD yet still here)
Reference:
URL:http://www.dataguard.no/bugtraq/1994_1/0040.html
Reference: BUGTRAQ:19940315 so...
Reference:
URL:http://www.dataguard.no/bugtraq/1994_1/0043.html
Reference: BUGTRAQ:19940315 anyone know details?
Reference:
URL:http://www.dataguard.no/bugtraq/1994_1/0042.html
Reference: BUGTRAQ:19940315 Security problem in
sendmail versions 8.x.x
Reference:
URL:http://www.dataguard.no/bugtraq/1994_1/0048.html
Reference: BUGTRAQ:19940327 sendmail exploit
script - resend
Reference:
URL:http://www.dataguard.no/bugtraq/1994_1/0078.html
Reference: CERT:CA-1994-12
Reference:
URL:http://www.cert.org/advisories/CA-94.12.sendmail.vulnerabilities
Reference: XF:sendmail-debug-gain-root(7155)
Reference:
URL:http://xforce.iss.net/static/7155.php
Name: CVE-1999-1316
Description:
Passfilt.dll in Windows NT SP2 allows users to create a
password that contains the user's name, which could make
it easier for an attacker to guess. Status: Entry
Reference: MSKB:Q247975
Reference:
URL:http://support.microsoft.com/support/kb/articles/Q247/9/75.asp
Reference: XF:passfilt-fullname(7391)
Reference:
URL:http://xforce.iss.net/static/7391.php
Name: CVE-1999-1317
Description:
Windows NT 4.0 SP4 and earlier allows local users to
gain privileges by modifying the symbolic link table in
the \?? object folder using a different case letter
(upper or lower) to point to a different device.
Status: Entry
Reference: NTBUGTRAQ:19990312 [ ALERT ] Case
Sensitivity and Symbolic Links
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92127046701349&w=2
Reference: NTBUGTRAQ:19990314 AW: [ ALERT ] Case
Sensitivity and Symbolic Links
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92162979530341&w=2
Reference: MSKB:Q222159
Reference:
URL:http://support.microsoft.com/support/kb/articles/q222/1/59.asp
Reference: XF:nt-symlink-case(7398)
Reference:
URL:http://xforce.iss.net/static/7398.php
Name: CVE-1999-1318
Description:
/usr/5bin/su in SunOS 4.1.3 and earlier uses a search
path that includes the current working directory (.),
which allows local users to gain privileges via Trojan
horse programs. Status: Entry
Reference: SUNBUG:1121935
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100630&zone_32=112193%2A%20
Reference: XF:sun-su-path(7480)
Reference:
URL:http://www.iss.net/security_center/static/7480.php
Name: CVE-1999-1320
Description:
Vulnerability in Novell NetWare 3.x and earlier allows
local users to gain privileges via packet spoofing.
Status: Entry
Reference: CIAC:D-01
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/d-01.shtml
Reference:
XF:netware-packet-spoofing-privileges(7213)
Reference:
URL:http://www.iss.net/security_center/static/7213.php
Name: CVE-1999-1321
Description:
Buffer overflow in ssh 1.2.26 client with Kerberos V
enabled could allow remote attackers to cause a denial
of service or execute arbitrary commands via a long DNS
hostname that is not properly handled during TGT ticket
passing. Status: Entry
Reference: BUGTRAQ:19981105 security patch for
ssh-1.2.26 kerberos code
Reference:
URL:http://lists.netspace.org/cgi-bin/wa?A2=ind9811A&L=bugtraq&P=R4814
Reference: OSVDB:4883
Reference: URL:http://www.osvdb.org/4883
Name: CVE-1999-1324
Description:
VAXstations running Open VMS 5.3 through 5.5-2 with VMS
DECwindows or MOTIF do not properly disable access to
user accounts that exceed the break-in limit threshold
for failed login attempts, which makes it easier for
attackers to conduct brute force password guessing.
Status: Entry
Reference: CIAC:D-06
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/d-06.shtml
Reference: XF:openvms-sysgen-enabled(7225)
Reference:
URL:http://xforce.iss.net/static/7225.php
Name: CVE-1999-1325
Description:
SAS System 5.18 on VAX/VMS is installed with insecure
permissions for its directories and startup file, which
allows local users to gain privileges. Status:
Entry
Reference: CIAC:C-19
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/c-19.shtml
Reference: XF:vaxvms-sas-gain-privileges(7261)
Reference:
URL:http://xforce.iss.net/static/7261.php
Name: CVE-1999-1326
Description:
wu-ftpd 2.4 FTP server does not properly drop privileges
when an ABOR (abort file transfer) command is executed
during a file transfer, which causes a signal to be
handled incorrectly and allows local and possibly remote
attackers to read arbitrary files. Status: Entry
Reference: BUGTRAQ:19970104 serious security bug
in wu-ftpd v2.4
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420401&w=2
Reference: BUGTRAQ:19970105 BoS: serious security
bug in wu-ftpd v2.4 -- PATCH
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420408&w=2
Reference: XF:wuftpd-abor-gain-privileges(7169)
Reference:
URL:http://xforce.iss.net/static/7169.php
Name: CVE-1999-1327
Description:
Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat
Linux 5.1 allows local users to gain root privileges via
a long LANG environmental variable. Status: Entry
Reference: BUGTRAQ:19980601 Re: SECURITY: Red Hat
Linux 5.1 linuxconf bug (fwd)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221103125826&w=2
Reference:
CONFIRM:http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf
Reference: XF:linuxconf-lang-bo(7239)
Reference:
URL:http://www.iss.net/security_center/static/7239.php
Reference: OSVDB:6065
Reference: URL:http://www.osvdb.org/6065
Name: CVE-1999-1328
Description:
linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1
allows local users to overwrite arbitrary files and gain
root access via a symlink attack. Status: Entry
Reference: BUGTRAQ:19980826 [djb@redhat.com:
Unidentified subject!]
Reference: BUGTRAQ:19980823 Security concerns in
linuxconf shipped w/RedHat 5.1
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90383955231511&w=2
Reference:
CONFIRM:http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf
Reference:
XF:linuxconf-symlink-gain-privileges(7232)
Reference:
URL:http://www.iss.net/security_center/static/7232.php
Reference: OSVDB:6068
Reference: URL:http://www.osvdb.org/6068
Name: CVE-1999-1329
Description:
Buffer overflow in SysVInit in Red Hat Linux 5.1 and
earlier allows local users to gain privileges.
Status: Entry
Reference:
CONFIRM:http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit
Reference: XF:sysvinit-root-bo(7250)
Reference:
URL:http://www.iss.net/security_center/static/7250.php
Name: CVE-1999-1330
Description:
The snprintf function in the db library 1.85.4 ignores
the size parameter, which could allow attackers to
exploit buffer overflows that would be prevented by a
properly implemented snprintf. Status: Entry
Reference: BUGTRAQ:19970709 [linux-security]
so-called snprintf() in db-1.85.4 (fwd)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602661419259&w=2
Reference:
CONFIRM:http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html
Reference:
CONFIRM:http://www.redhat.com/support/errata/rh42-errata-general.html#db
Reference: XF:linux-libdb-snprintf-bo(7244)
Reference:
URL:http://www.iss.net/security_center/static/7244.php
Name: CVE-1999-1331
Description:
netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet
interface to be controlled by users on reboot when an
option is set, which allows local users to cause a
denial of service by shutting down the interface.
Status: Entry
Reference:
CONFIRM:http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg
Reference: XF:netcfg-ethernet-dos(7245)
Reference:
URL:http://www.iss.net/security_center/static/7245.php
Name: CVE-1999-1332
Description:
gzexe in the gzip package on Red Hat Linux 5.0 and
earlier allows local users to overwrite files of other
users via a symlink attack on a temporary file.
Status: Entry
Reference: BUGTRAQ:19980128 GZEXE - the big
problem
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88603844115233&w=2
Reference:
CONFIRM:http://www.redhat.com/support/errata/rh50-errata-general.html#gzip
Reference: DEBIAN:DSA-308
Reference:
URL:http://www.debian.org/security/2003/dsa-308
Reference: BID:7845
Reference:
URL:http://www.securityfocus.com/bid/7845
Reference: OSVDB:3812
Reference: URL:http://www.osvdb.org/3812
Reference: XF:gzip-gzexe-tmp-symlink(7241)
Reference:
URL:http://www.iss.net/security_center/static/7241.php
Name: CVE-1999-1333
Description:
automatic download option in ncftp 2.4.2 FTP client in
Red Hat Linux 5.0 and earlier allows remote attackers to
execute arbitrary commands via shell metacharacters in
the names of files that are to be downloaded. Status:
Entry
Reference: BUGTRAQ:19980319 ncftp 2.4.2 MkDirs
bug
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=89042322924057&w=2
Reference:
CONFIRM:http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp
Reference:
XF:ncftp-autodownload-command-execution(7240)
Reference:
URL:http://www.iss.net/security_center/static/7240.php
Reference: OSVDB:6111
Reference: URL:http://www.osvdb.org/6111
Name: CVE-1999-1335
Description:
snmpd server in cmu-snmp SNMP package before 3.3-1 in
Red Hat Linux 4.0 is configured to allow remote
attackers to read and write sensitive information.
Status: Entry
Reference:
CONFIRM:http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp
Reference: XF:cmusnmp-read-write(7251)
Reference:
URL:http://xforce.iss.net/static/7251.php
Name: CVE-1999-1336
Description:
3Com HiPer Access Router Card (HiperARC) 4.0 through
4.2.29 allows remote attackers to cause a denial of
service (reboot) via a flood of IAC packets to the
telnet port. Status: Entry
Reference: BUGTRAQ:19990812 3com hiperarch flaw
[hiperbomb.c]
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93458364903256&w=2
Reference: BUGTRAQ:19990816 Re: 3com hiperarch
flaw [hiperbomb.c]
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93492615408725&w=2
Reference: OSVDB:6057
Reference: URL:http://www.osvdb.org/6057
Name: CVE-1999-1337
Description:
FTP client in Midnight Commander (mc) before 4.5.11
stores usernames and passwords for visited sites in
plaintext in the world-readable history file, which
allows other local users to gain privileges. Status:
Entry
Reference: BUGTRAQ:19990801 midnight commander
vulnerability(?) (fwd)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93370073207984&w=2
Reference:
XF:midnight-commander-data-disclosure(9873)
Reference:
URL:http://www.iss.net/security_center/static/9873.php
Reference: OSVDB:5921
Reference: URL:http://www.osvdb.org/5921
Name: CVE-1999-1339
Description:
Vulnerability when Network Address Translation (NAT) is
enabled in Linux 2.2.10 and earlier with ipchains, or
FreeBSD 3.2 with ipfw, allows remote attackers to cause
a denial of service (kernel panic) via a ping -R (record
route) command. Status: Entry
Reference: BUGTRAQ:19990722 Re: ping -R causes
kernel panic on a forwarding machine ( 2.2.5 a nd 2
.2.10)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93277766505061&w=2
Reference: BUGTRAQ:19990722 Linux +ipchains+ ping
-R
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93277426802802&w=2
Reference:
CONFIRM:http://www.kernel.org/pub/linux/kernel/v2.2/patch-2.2.11.gz
Reference: XF:ipchains-ping-route-dos(7257)
Reference:
URL:http://www.iss.net/security_center/static/7257.php
Reference: OSVDB:6105
Reference: URL:http://www.osvdb.org/6105
Name: CVE-1999-1341
Description:
Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and
PPP options, allows local unprivileged users to forge IP
packets via the TIOCSETD option on tty devices.
Status: Entry
Reference: BUGTRAQ:19991022 Local user can send
forged packets
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94061108411308&w=2
Reference: XF:linux-tiocsetd-forge-packets(7858)
Reference:
URL:http://xforce.iss.net/static/7858.php
Name: CVE-1999-1351
Description:
Directory traversal vulnerability in KVIrc IRC client
0.9.0 with the "Listen to !nick <soundname> requests"
option enabled allows remote attackers to read arbitrary
files via a .. (dot dot) in a DCC GET request.
Status: Entry
Reference: BUGTRAQ:19990924 Kvirc bug
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93845560631314&w=2
Reference: XF:kvirc-dot-directory-traversal(7761)
Reference:
URL:http://www.iss.net/security_center/static/7761.php
Name: CVE-1999-1356
Description:
Compaq Integration Maintenance Utility as used in Compaq
Insight Manager agent before SmartStart 4.50 modifies
the legal notice caption (LegalNoticeCaption) and text
(LegalNoticeText) in Windows NT, which could produce a
legal notice that is in violation of the security
policy. Status: Entry
Reference: BUGTRAQ:19990902 Compaq CIM UG
Overwrites Legal Notice
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93646669500991&w=2
Reference: NTBUGTRAQ:19990902 Compaq CIM UG
Overwrites Legal Notice
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93637792706047&w=2
Reference: NTBUGTRAQ:19990917 Re: Compaq CIM UG
Overwrites Legal Notice
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93759822830815&w=2
Reference:
XF:compaq-smartstart-legal-notice(7763)
Reference:
URL:http://www.iss.net/security_center/static/7763.php
Name: CVE-1999-1358
Description:
When an administrator in Windows NT or Windows 2000
changes a user policy, the policy is not properly
updated if the local ntconfig.pol is not writable by the
user, which could allow local users to bypass
restrictions that would otherwise be enforced by the
policy, possibly by changing the policy file to be
read-only. Status: Entry
Reference: MSKB:Q157673
Reference:
URL:http://support.microsoft.com/support/kb/articles/q157/6/73.asp
Reference: XF:nt-user-policy-update(7400)
Reference:
URL:http://www.iss.net/security_center/static/7400.php
Name: CVE-1999-1359
Description:
When the Ntconfig.pol file is used on a server whose
name is longer than 13 characters, Windows NT does not
properly enforce policies for global groups, which could
allow users to bypass restrictions that were intended by
those policies. Status: Entry
Reference: MSKB:Q163875
Reference:
URL:http://support.microsoft.com/support/kb/articles/q163/8/75.asp
Reference: XF:nt-group-policy-longname(7401)
Reference:
URL:http://www.iss.net/security_center/static/7401.php
Name: CVE-1999-1360
Description:
Windows NT 4.0 allows local users to cause a denial of
service via a user mode application that closes a handle
that was opened in kernel mode, which causes a crash
when the kernel attempts to close the handle. Status:
Entry
Reference: MSKB:Q160650
Reference:
URL:http://support.microsoft.com/support/kb/articles/q160/6/50.asp
Reference: XF:nt-kernel-handle-dos(7402)
Reference:
URL:http://www.iss.net/security_center/static/7402.php
Name: CVE-1999-1362
Description:
Win32k.sys in Windows NT 4.0 before SP2 allows local
users to cause a denial of service (crash) by calling
certain WIN32K functions with incorrect parameters.
Status: Entry
Reference: MSKB:Q160601
Reference:
URL:http://support.microsoft.com/support/kb/articles/q160/6/01.asp
Reference: XF:nt-win32k-dos(7403)
Reference:
URL:http://www.iss.net/security_center/static/7403.php
Name: CVE-1999-1363
Description:
Windows NT 3.51 and 4.0 allow local users to cause a
denial of service (crash) by running a program that
creates a large number of locks on a file, which
exhausts the NonPagedPool. Status: Entry
Reference: MSKB:Q163143
Reference:
URL:http://support.microsoft.com/support/kb/articles/q163/1/43.asp
Reference: XF:nt-nonpagedpool-dos(7405)
Reference:
URL:http://www.iss.net/security_center/static/7405.php
Name: CVE-1999-1365
Description:
Windows NT searches a user's home directory
(%systemroot% by default) before other directories to
find critical programs such as NDDEAGNT.EXE,
EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could
allow local users to bypass access restrictions or gain
privileges by placing a Trojan horse program into the
root directory, which is writable by default. Status:
Entry
Reference: NTBUGTRAQ:19990628 NT runs
Explorer.exe, Taskmgr.exe etc. from wrong location
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93069418400856&w=2
Reference: NTBUGTRAQ:19990630 Update: NT runs
explorer.exe, etc...
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93127894731200&w=2
Reference: XF:nt-login-default-folder(2336)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/2336
Reference: BID:0515
Reference:
URL:http://www.securityfocus.com/bid/0515
Name: CVE-1999-1379
Description:
DNS allows remote attackers to use DNS name servers as
traffic amplifiers via a UDP DNS query with a spoofed
source address, which produces more traffic to the
victim than was sent by the attacker. Status:
Entry
Reference: BUGTRAQ:19990730 Possible Denial Of
Service using DNS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93348057829957&w=2
Reference: BUGTRAQ:19990810 Possible Denial Of
Service using DNS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93433758607623&w=2
Reference: AUSCERT:AL-1999.004
Reference:
URL:ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos
Reference: CIAC:J-063
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/j-063.shtml
Reference: XF:dns-udp-query-dos(7238)
Reference:
URL:http://www.iss.net/security_center/static/7238.php
Name: CVE-1999-1380
Description:
Symantec Norton Utilities 2.0 for Windows 95 marks the
TUNEOCX.OCX ActiveX control as safe for scripting, which
allows remote attackers to execute arbitrary commands
via the run option through malicious web pages that are
accessed by browsers such as Internet Explorer 3.0.
Status: Entry
Reference:
MISC:http://www.net-security.sk/bugs/NT/nu20.html
Reference:
MISC:http://mlarchive.ima.com/win95/1997/May/0342.html
Reference:
MISC:http://news.zdnet.co.uk/story/0,,s2065518,00.html
Reference: XF:nu-tuneocx-activex-control(7188)
Reference:
URL:http://www.iss.net/security_center/static/7188.php
Name: CVE-1999-1382
Description:
NetWare NFS mode 1 and 2 implements the "Read Only" flag
in Unix by changing the ownership of a file to root,
which allows local users to gain root privileges by
creating a setuid program and setting it to "Read Only,"
which NetWare-NFS changes to a setuid root program.
Status: Entry
Reference: BUGTRAQ:19980108 NetWare NFS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88427711321769&w=2
Reference: BUGTRAQ:19980812 Re: Netware NFS (fwd)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90295697702474&w=2
Reference:
CONFIRM:http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551
Reference: XF:netware-nfs-file-ownership(7246)
Reference:
URL:http://www.iss.net/security_center/static/7246.php
Name: CVE-1999-1384
Description:
Indigo Magic System Tour in the SGI system tour package
(systour) for IRIX 5.x through 6.3 allows local users to
gain root privileges via a Trojan horse .exitops
program, which is called by the inst command that is
executed by the RemoveSystemTour program. Status:
Entry
Reference: BUGTRAQ:19961030 (Another)
vulnerability in new SGIs
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420095&w=2
Reference: AUSCERT:AA-96.08
Reference:
URL:ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.08.SGI.systour.vul
Reference: SGI:19961101-01-I
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19961101-01-I
Reference: BID:470
Reference:
URL:http://www.securityfocus.com/bid/470
Reference: XF:irix-systour(7456)
Reference:
URL:http://www.iss.net/security_center/static/7456.php
Name: CVE-1999-1385
Description:
Buffer overflow in ppp program in FreeBSD 2.1 and
earlier allows local users to gain privileges via a long
HOME environment variable. Status: Entry
Reference: BUGTRAQ:19961219 Exploit for ppp bug
(FreeBSD 2.1.0).
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420332&w=2
Reference: FREEBSD:FreeBSD-SA-96:20
Reference:
URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:20.stack-overflow.asc
Reference: XF:ppp-bo(7465)
Reference:
URL:http://www.iss.net/security_center/static/7465.php
Reference: OSVDB:6085
Reference: URL:http://www.osvdb.org/6085
Name: CVE-1999-1386
Description:
Perl 5.004_04 and earlier follows symbolic links when
running with the -e option, which allows local users to
overwrite arbitrary files via a symlink attack on the
/tmp/perl-eaXXXXX file. Status: Entry
Reference: BUGTRAQ:19980308 another /tmp race:
`perl -e' opens temp file not safely
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88932165406213&w=2
Reference:
CONFIRM:http://www.redhat.com/support/errata/rh50-errata-general.html#perl
Reference: XF:perl-e-tmp-symlink(7243)
Reference:
URL:http://www.iss.net/security_center/static/7243.php
Name: CVE-1999-1397
Description:
Index Server 2.0 on IIS 4.0 stores physical path
information in the ContentIndex\Catalogs subkey of the
AllowedPaths registry key, whose permissions allows
local and remote users to obtain the physical paths of
directories that are being indexed. Status: Entry
Reference: BUGTRAQ:19990323 Index Server 2.0 and
the Registry
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92242671024118&w=2
Reference: NTBUGTRAQ:19990323 Index Server 2.0
and the Registry
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92223293409756&w=2
Reference: BID:476
Reference:
URL:http://www.securityfocus.com/bid/476
Reference: XF:iis-indexserver-reveal-path(7559)
Reference:
URL:http://www.iss.net/security_center/static/7559.php
Name: CVE-1999-1402
Description:
The access permissions for a UNIX domain socket are
ignored in Solaris 2.x and SunOS 4.x, and other
BSD-based operating systems before 4.4, which could
allow local users to connect to the socket and possibly
disrupt or control the operations of the program using
that socket. Status: Entry
Reference: BUGTRAQ:19970517 UNIX domain socket
(Solarisx86 2.5)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418317&w=2
Reference: BUGTRAQ:19971003 Solaris 2.6 and
sockets
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602248718482&w=2
Reference: BID:456
Reference:
URL:http://www.securityfocus.com/bid/456
Reference: XF:sun-domain-socket-permissions(7172)
Reference:
URL:http://www.iss.net/security_center/static/7172.php
Name: CVE-1999-1407
Description:
ifdhcpc-done script for configuring DHCP on Red Hat
Linux 5 allows local users to append text to arbitrary
files via a symlink attack on the dhcplog file.
Status: Entry
Reference: BUGTRAQ:19980309 *sigh* another RH5
/tmp problem
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88950856416985&w=2
Reference: BID:368
Reference:
URL:http://www.securityfocus.com/bid/368
Reference:
XF:initscripts-ifdhcpdone-dhcplog-symlink(7294)
Reference:
URL:http://www.iss.net/security_center/static/7294.php
Reference:
CONFIRM:http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts
Name: CVE-1999-1409
Description:
The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier
allows local users to read portions of arbitrary files
by submitting the file to at with the -f argument, which
generates error messages that at sends to the user via
e-mail. Status: Entry
Reference: BUGTRAQ:19980703 more about 'at'
Reference:
URL:http://www.shmoo.com/mail/bugtraq/jul98/msg00064.html
Reference: BUGTRAQ:19980805 irix-6.2 "at -f"
vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90233906612929&w=2
Reference: NETBSD:NetBSD-SA1998-004
Reference:
URL:ftp://ftp.NetBSD.ORG/pub/NetBSD/security/advisories/NetBSD-SA1998-004.txt.asc
Reference: BID:331
Reference:
URL:http://www.securityfocus.com/bid/331
Reference: XF:at-f-read-files(7577)
Reference:
URL:http://www.iss.net/security_center/static/7577.php
Name: CVE-1999-1411
Description:
The installation of the fsp package 2.71-10 in Debian
GNU/Linux 2.0 adds the anonymous FTP user without
notifying the administrator, which could automatically
enable anonymous FTP on some servers such as wu-ftp.
Status: Entry
Reference: DEBIAN:19981126 new version of fsp
fixes security flaw
Reference:
URL:http://lists.debian.org/debian-security-announce/debian-security-announce-1998/msg00033.html
Reference: BUGTRAQ:19981128 Debian: Security flaw
in FSP
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91228908407679&w=2
Reference: BUGTRAQ:19981130 Debian: Security flaw
in FSP
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91244712808780&w=2
Reference: BUGTRAQ:19990217 Debian GNU/Linux
2.0r5 released (fwd)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91936850009861&w=2
Reference: BID:316
Reference:
URL:http://www.securityfocus.com/bid/316
Reference: XF:fsp-anon-ftp-access(7574)
Reference:
URL:http://www.iss.net/security_center/static/7574.php
Name: CVE-1999-1414
Description:
IBM Netfinity Remote Control allows local users to gain
administrator privileges by starting programs from the
process manager, which runs with system level
privileges. Status: Entry
Reference: NTBUGTRAQ:19990525 Security Leak with
IBM Netfinity Remote Control Software
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92765856706547&w=2
Reference: NTBUGTRAQ:19990609 IBM's response to
"Security Leak with IBM Netfinity Remote Control
Software
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92902484317769&w=2
Reference: BID:284
Reference:
URL:http://www.securityfocus.com/bid/284
Name: CVE-1999-1419
Description:
Buffer overflow in nss_nisplus.so.1 library in NIS+ in
Solaris 2.3 and 2.4 allows local users to gain root
privileges. Status: Entry
Reference: SUN:00148
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/148
Reference: BID:219
Reference:
URL:http://www.securityfocus.com/bid/219
Reference: XF:sun-nisplus-bo(7535)
Reference:
URL:http://www.iss.net/security_center/static/7535.php
Name: CVE-1999-1423
Description:
ping in Solaris 2.3 through 2.6 allows local users to
cause a denial of service (crash) via a ping request to
a multicast address through the loopback interface, e.g.
via ping -i. Status: Entry
Reference: BUGTRAQ:19970626 Solaris Ping bug
(DoS)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602558319160&w=2
Reference: BUGTRAQ:19970627 SUMMARY: Solaris Ping
bug (DoS)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602558319171&w=2
Reference: BUGTRAQ:19970627 Solaris Ping
bug(inetsvc)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602558319181&w=2
Reference: BUGTRAQ:19971005 Solaris Ping Bug and
other [bc] oddities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602558319180&w=2
Reference: SUN:00146
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/146
Reference: BID:209
Reference:
URL:http://www.securityfocus.com/bid/209
Reference: XF:ping-multicast-loopback-dos(7492)
Reference:
URL:http://www.iss.net/security_center/static/7492.php
Name: CVE-1999-1432
Description:
Power management (Powermanagement) on Solaris 2.4
through 2.6 does not start the xlock process until after
the sys-suspend has completed, which allows an attacker
with physical access to input characters to the last
active application from the keyboard for a short period
after the system is restoring, which could lead to
increased privileges. Status: Entry
Reference: BUGTRAQ:19980716 Security risk with
powermanagemnet on Solaris 2.6
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104525997&w=2
Reference: BID:160
Reference:
URL:http://www.securityfocus.com/bid/160
Reference: SUNBUG:4024179
Name: CVE-1999-1433
Description:
HP JetAdmin D.01.09 on Solaris allows local users to
change the permissions of arbitrary files via a symlink
attack on the /tmp/jetadmin.log file. Status:
Entry
Reference: BUGTRAQ:19980715 JetAdmin software
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104525988&w=2
Reference: BUGTRAQ:19980722 Re: JetAdmin software
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526067&w=2
Reference: BID:157
Reference:
URL:http://www.securityfocus.com/bid/157
Name: CVE-1999-1437
Description:
ePerl 2.2.12 allows remote attackers to read arbitrary
files and possibly execute certain commands by
specifying a full pathname of the target file as an
argument to bar.phtml. Status: Entry
Reference: BUGTRAQ:19980707 ePerl: bad handling
of ISINDEX queries
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104525890&w=2
Reference: BUGTRAQ:19980710 ePerl Security Update
Available
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104525927&w=2
Reference: BID:151
Reference:
URL:http://www.securityfocus.com/bid/151
Name: CVE-1999-1452
Description:
GINA in Windows NT 4.0 allows attackers with physical
access to display a portion of the clipboard of the user
who has locked the workstation by pasting (CTRL-V) the
contents into the username prompt. Status: Entry
Reference: NTBUGTRAQ:19990129 ole objects in a
"secured" environment?
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91764169410814&w=2
Reference: NTBUGTRAQ:19990205 Alert: MS releases
GINA-fix for SP3, SP4, and TS
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91822011021558&w=2
Reference: BUGTRAQ:19990129 ole objects in a
"secured" environment?
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91788829326419&w=2
Reference: MSKB:Q214802
Reference:
URL:http://support.microsoft.com/support/kb/articles/q214/8/02.asp
Reference: BID:198
Reference:
URL:http://www.securityfocus.com/bid/198
Reference: XF:nt-gina-clipboard(1975)
Reference:
URL:http://xforce.iss.net/static/1975.php
Name: CVE-1999-1455
Description:
RSH service utility RSHSVC in Windows NT 3.5 through 4.0
does not properly restrict access as specified in the
.Rhosts file when a user comes from an authorized host,
which could allow unauthorized users to access the
service by logging in from an authorized host.
Status: Entry
Reference: MSKB:Q158320
Reference:
URL:http://support.microsoft.com/support/kb/articles/q158/3/20.asp
Reference: XF:nt-rshsvc-ale-bypass(7422)
Reference:
URL:http://xforce.iss.net/static/7422.php
Name: CVE-1999-1456
Description:
thttpd HTTP server 2.03 and earlier allows remote
attackers to read arbitrary files via a GET request with
more than one leading / (slash) character in the
filename. Status: Entry
Reference: BUGTRAQ:19980819 thttpd 2.04 released
(fwd)
Reference:
URL:http://www.securityfocus.com/archive/1/10368
Reference:
CONFIRM:http://www.acme.com/software/thttpd/thttpd.html#releasenotes
Reference: XF:thttpd-file-read(1809)
Reference:
URL:http://xforce.iss.net/static/1809.php
Name: CVE-1999-1468
Description:
rdist in various UNIX systems uses popen to execute
sendmail, which allows local users to gain root
privileges by modifying the IFS (Internal Field
Separator) variable. Status: Entry
Reference:
MISC:http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html
Reference: CERT:CA-91.20
Reference:
URL:http://www.cert.org/advisories/CA-91.20.rdist.vulnerability
Reference: BID:31
Reference:
URL:http://www.securityfocus.com/bid/31
Reference: XF:rdist-popen-gain-privileges(7160)
Reference:
URL:http://www.iss.net/security_center/static/7160.php
Reference: OSVDB:8106
Reference: URL:http://www.osvdb.org/8106
Name: CVE-1999-1472
Description:
Internet Explorer 4.0 allows remote attackers to read
arbitrary text and HTML files on the user's machine via
a small IFRAME that uses Dynamic HTML (DHTML) to send
the data to the attacker, aka the Freiburg text-viewing
issue. Status: Entry
Reference: BUGTRAQ:19971017 Security Hole in
Explorer 4.0
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87710897923098&w=2
Reference:
MISC:http://www.insecure.org/sploits/Internet_explorer_4.0.hack.html
Reference:
CONFIRM:http://www.microsoft.com/Windows/ie/security/freiburg.asp
Reference: MSKB:Q176794
Reference:
URL:http://support.microsoft.com/support/kb/articles/q176/7/94.asp
Reference: MSKB:Q176697
Reference:
URL:http://support.microsoft.com/support/kb/articles/q176/6/97.asp
Reference: XF:http-ie-spy(587)
Reference:
URL:http://xforce.iss.net/static/587.php
Reference: OSVDB:7819
Reference: URL:http://www.osvdb.org/7819
Name: CVE-1999-1473
Description:
When a Web site redirects the browser to another site,
Internet Explorer 3.02 and 4.0 automatically resends
authentication information to the second site, aka the
"Page Redirect Issue." Status: Entry
Reference: MSKB:Q176697
Reference:
URL:http://support.microsoft.com/support/kb/articles/q176/6/97.asp
Reference: XF:ie-page-redirect(7426)
Reference:
URL:http://www.iss.net/security_center/static/7426.php
Reference: OSVDB:7818
Reference: URL:http://www.osvdb.org/7818
Name: CVE-1999-1476
Description:
A bug in Intel Pentium processor (MMX and Overdrive)
allows local users to cause a denial of service (hang)
in Intel-based operating systems such as Windows NT and
Windows 95, via an invalid instruction, aka the "Invalid
Operand with Locked CMPXCHG8B Instruction" problem.
Status: Entry
Reference: MSKB:Q163852
Reference:
URL:http://support.microsoft.com/support/kb/articles/q163/8/52.asp
Reference: XF:pentium-crash(704)
Reference:
URL:http://xforce.iss.net/static/704.php
Name: CVE-1999-1478
Description:
The Sun HotSpot Performance Engine VM allows a remote
attacker to cause a denial of service on any server
running HotSpot via a URL that includes the [ character.
Status: Entry
Reference: NTBUGTRAQ:19990706 Bug in SUN's
Hotspot VM
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93138827429589&w=2
Reference: NTBUGTRAQ:19990716 FW: (Review ID:
85125) Hotspot crashes bringing down webserver
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93240220324183&w=2
Reference: BID:522
Reference:
URL:http://www.securityfocus.com/bid/522
Reference: XF:sun-hotspot-vm(2348)
Reference:
URL:http://xforce.iss.net/static/2348.php
Name: CVE-1999-1481
Description:
Squid 2.2.STABLE5 and below, when using external
authentication, allows attackers to bypass access
controls via a newline in the user/password pair.
Status: Entry
Reference: BUGTRAQ:19991025 [squid] exploit for
external authentication problem
Reference:
URL:http://www.securityfocus.com/archive/1/33295
Reference: BUGTRAQ:19991103 [squid]exploit for
external authentication problem
Reference:
URL:http://www.securityfocus.com/archive/1/33295
Reference:
CONFIRM:http://www.squid-cache.org/Versions/v2/2.2/bugs/
Reference: BID:741
Reference:
URL:http://www.securityfocus.com/bid/741
Reference: XF:squid-proxy-auth-access(3433)
Reference:
URL:http://xforce.iss.net/static/3433.php
Name: CVE-1999-1486
Description:
sadc in IBM AIX 4.1 through 4.3, when called from
programs such as timex that are setgid adm, allows local
users to overwrite arbitrary files via a symlink attack.
Status: Entry
Reference:
CONFIRM:http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info
Reference: AIXAPAR:IX75554
Reference:
URL:http://www-1.ibm.com/support/search.wss?rs=0&q=IX75554&apar=only
Reference: AIXAPAR:IX76853
Reference:
URL:http://www-1.ibm.com/support/search.wss?rs=0&q=IX76853&apar=only
Reference: AIXAPAR:IX76330
Reference:
URL:http://www-1.ibm.com/support/search.wss?rs=0&q=IX76330&apar=only
Reference: BID:408
Reference:
URL:http://www.securityfocus.com/bid/408
Reference: XF:aix-sadc-timex(7675)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/7675
Name: CVE-1999-1488
Description:
sdrd daemon in IBM SP2 System Data Repository (SDR)
allows remote attackers to read files without
authentication. Status: Entry
Reference: CIAC:I-079A
Reference:
URL:http://ciac.llnl.gov/ciac/bulletins/i-079a.shtml
Reference: BID:371
Reference:
URL:http://www.securityfocus.com/bid/371
Reference: XF:ibm-sdr-read-files(7217)
Reference:
URL:http://www.iss.net/security_center/static/7217.php
Name: CVE-1999-1490
Description:
xosview 1.5.1 in Red Hat 5.1 allows local users to gain
root access via a long HOME environmental variable.
Status: Entry
Reference: BUGTRAQ:19980528 ALERT: Tiresome
security hole in "xosview", RedHat5.1?
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221101926021&w=2
Reference: BUGTRAQ:19980529 Re: Tiresome security
hole in "xosview" (xosexp.c)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221101926034&w=2
Reference: BID:362
Reference:
URL:http://www.securityfocus.com/bid/362
Reference: XF:linux-xosview-bo(8787)
Reference:
URL:http://www.iss.net/security_center/static/8787.php
Name: CVE-1999-1494
Description:
colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0
allows local attackers to read arbitrary files via the
-text argument. Status: Entry
Reference: BUGTRAQ:19940809 Re: IRIX 5.2 Security
Advisory
Reference:
URL:http://www.securityfocus.com/archive/1/675
Reference: BUGTRAQ:19950307 sigh. another Irix
5.2 hole.
Reference:
URL:http://www.tryc.on.ca/archives/bugtraq/1995_1/0614.html
Reference: SGI:19950209-00-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/19950209-01-P
Reference: XF:sgi-colorview(2112)
Reference:
URL:http://xforce.iss.net/static/2112.php
Reference: BID:336
Reference:
URL:http://www.securityfocus.com/bid/336
Name: CVE-1999-1507
Description:
Sun SunOS 4.1 through 4.1.3 allows local attackers to
gain root access via insecure permissions on files and
directories such as crash. Status: Entry
Reference: CERT:CA-1993-03
Reference:
URL:http://www.cert.org/advisories/CA-1993-03.html
Reference: BID:59
Reference:
URL:http://www.securityfocus.com/bid/59
Reference: XF:sun-dir(521)
Reference:
URL:http://xforce.iss.net/static/521.php
Name: CVE-1999-1512
Description:
The AMaViS virus scanner 0.2.0-pre4 and earlier allows
remote attackers to execute arbitrary commands as root
via an infected mail message with shell metacharacters
in the reply-to field. Status: Entry
Reference: BUGTRAQ:19990716 AMaViS virus scanner
for Linux - root exploit
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93219846414732&w=2
Reference:
CONFIRM:http://www.amavis.org/ChangeLog.txt
Reference: BID:527
Reference:
URL:http://www.securityfocus.com/bid/527
Reference: XF:amavis-command-execute(2349)
Reference:
URL:http://xforce.iss.net/static/2349.php
Name: CVE-1999-1520
Description:
A configuration problem in the Ad Server Sample
directory (AdSamples) in Microsoft Site Server 3.0
allows an attacker to obtain the SITE.CSC file, which
exposes sensitive SQL database information. Status:
Entry
Reference: BUGTRAQ:19990511 [ALERT] Site Server
3.0 May Expose SQL IDs and PSWs
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92647407227303&w=2
Reference: BID:256
Reference:
URL:http://www.securityfocus.com/bid/256
Reference: XF:siteserver-site-csc(2270)
Reference:
URL:http://xforce.iss.net/static/2270.php
Name: CVE-1999-1530
Description:
cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not
properly identify the user for running certain scripts,
which allows a malicious site administrator to view or
modify data located at another virtual site on the same
system. Status: Entry
Reference: BUGTRAQ:19991108 Security flaw in
Cobalt RaQ2 cgiwrap
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94209954200450&w=2
Reference: BUGTRAQ:19991109 [Cobalt] Security
Advisory - cgiwrap
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94225629200045&w=2
Reference: BID:777
Reference:
URL:http://www.securityfocus.com/bid/777
Reference:
XF:cobalt-cgiwrap-incorrect-permissions(7764)
Reference:
URL:http://www.iss.net/security_center/static/7764.php
Reference: OSVDB:35
Reference: URL:http://www.osvdb.org/35
Name: CVE-1999-1531
Description:
Buffer overflow in IBM HomePagePrint 1.0.7 for
Windows98J allows a malicious Web site to execute
arbitrary code on a viewer's system via a long IMG_SRC
HTML tag. Status: Entry
Reference: BUGTRAQ:19991102 Some holes for
Win/UNIX softwares
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94157187815629&w=2
Reference: BID:763
Reference:
URL:http://www.securityfocus.com/bid/763
Reference: XF:ibm-homepageprint-bo(7767)
Reference:
URL:http://www.iss.net/security_center/static/7767.php
Name: CVE-1999-1535
Description:
Buffer overflow in AspUpload.dll in Persits Software
AspUpload before 1.4.0.2 allows remote attackers to
cause a denial of service, and possibly execute
arbitrary commands, via a long argument in the HTTP
request. Status: Entry
Reference: NTBUGTRAQ:19990720 Buffer overflow in
AspUpload 1.4
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93256878011447&w=2
Reference: NTBUGTRAQ:19990818 AspUpload Buffer
Overflow Fixed
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93501427820328&w=2
Reference: BID:592
Reference:
URL:http://www.securityfocus.com/bid/592
Reference: XF:http-aspupload-bo(3291)
Reference:
URL:http://xforce.iss.net/static/3291.php
Name: CVE-1999-1537
Description:
IIS 3.x and 4.x does not distinguish between pages
requiring encryption and those that do not, which allows
remote attackers to cause a denial of service (resource
exhaustion) via SSL requests to the HTTPS port for
normally unencrypted files, which will cause IIS to
perform extra work to send the files over SSL.
Status: Entry
Reference: NTBUGTRAQ:19990707 SSL and IIS.
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93138827329577&w=2
Reference: BID:521
Reference: URL:http://www.securityfocus.com/bid/521
Reference: XF:ssl-iis-dos(2352)
Reference: URL:http://xforce.iss.net/static/2352.php
Name: CVE-1999-1542
Description:
RPMMail before 1.4 allows remote attackers to execute
commands via an e-mail message with shell metacharacters
in the "MAIL FROM" command. Status: Entry
Reference: BUGTRAQ:19991004 RH6.0 local/remote
command execution
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93915641729415&w=2
Reference: BUGTRAQ:19991006 Fwd: [Re: RH6.0
local/remote command execution]
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93923853105687&w=2
Reference: XF:linux-rh-rpmmail(3353)
Reference: URL:http://xforce.iss.net/static/3353.php
Name: CVE-1999-1550
Description:
bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows
remote attackers to read arbitrary files by specifying
the target file in the "file" parameter. Status:
Entry
Reference: BUGTRAQ:19991108 BigIP - bigconf.cgi
holes
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94217006208374&w=2
Reference: BUGTRAQ:19991109 Re: BigIP -
bigconf.cgi holes
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94217879020184&w=2
Reference: BUGTRAQ:19991109
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94225879703021&w=2
Reference: BID:778
Reference: URL:http://www.securityfocus.com/bid/778
Reference: XF:bigip-bigconf-view-files(7771)
Reference: URL:http://www.iss.net/security_center/static/7771.php
Name: CVE-1999-1556
Description:
Microsoft SQL Server 6.5 uses weak encryption for the
password for the SQLExecutiveCmdExec account and stores
it in an accessible portion of the registry, which could
allow local users to gain privileges by reading and
decrypting the CmdExecAccount value. Status:
Entry
Reference: NTBUGTRAQ:19980629 MS SQL Server 6.5
stores password in unprotected registry keys
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=90222453431645&w=2
Reference: BID:109
Reference: URL:http://www.securityfocus.com/bid/109
Reference:
XF:mssql-sqlexecutivecmdexec-password(7354)
Reference: URL:http://xforce.iss.net/xforce/xfdb/7354
Name: CVE-1999-1565
Description:
Man2html 2.1 and earlier allows local users to overwrite
arbitrary files via a symlink attack on a temporary
file. Status: Entry
Reference: BUGTRAQ:19990820 [SECURITY] New
versions of man2html fixes postinst glitch
Reference: URL:http://www.securityfocus.com/archive/1/24784
Reference: OSVDB:6291
Reference: URL:http://www.osvdb.org/6291
Name: CVE-1999-1568
Description:
Off-by-one error in NcFTPd FTP server before 2.4.1
allows a remote attacker to cause a denial of service
(crash) via a long PORT command. Status: Entry
Reference: BUGTRAQ:19990223 NcFTPd remote buffer
overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91981352617720&w=2
Reference: BUGTRAQ:19990223 Comments on NcFTPd
"theoretical root compromise"
Reference: URL:http://www.securityfocus.com/archive/1/12699
Reference: XF:ncftpd-port-bo(1833)
Reference: URL:http://xforce.iss.net/static/1833.php |