| OSVDB ID | Disclosure Date | Title |
|
4748
Description:
Hermes Bulletin Board Software allows a remote attacker to gain administrative privileges. The flaw is due to a backdoor coded into the software. By logging in with a specific name, phone number and password, any person can gain full administrative control over the BBS.
|
1992-12-14
|
Hermes BBS Backdoor
|
|
45578
Description:
Unknown / Incomplete
|
1992-12-14
|
LOKI91 Chosen-plaintext Attack Weakness
|
|
796
Description:
Cisco IOS contains a flaw that may allow a malicious user to bypass Access Control Lists. The issue is triggered by a combination of configuration options which combine to affect the way certain ACLs are evaluated. It is possible that the flaw may allow unauthorized network traffic resulting in a loss of confidentiality, integrity, and/or availability.
|
1992-12-10
|
Cisco IOS Established Keyword ACL Bypass
|
|
64
Description:
(Description Provided by CVE) : Finger redirection allows finger bombs.
|
1992-10-28
|
GNU fingerd Recursive Host Request Remote DoS
|
|
7623
Description:
(Description Provided by CVE) : Vulnerability in Novell NetWare 3.x and earlier allows local users to gain privileges via packet spoofing.
|
1992-10-14
|
Novell NetWare Packet Spoofing Local Privilege Escalation
|
|
8615
Description:
UnZip contains a flaw related to the 'sco_dos' cross-compilation target that may allow an attacker to cause a stack overflow. No further details have been provided.
|
1992-08-23
|
UnZip sco_dos Overflow
|
|
893
Description:
(Description Provided by CVE) : NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.
|
1992-07-22
|
Multiple Unix Vendor NFS UID Mismatch Remote Privilege Escalation
|
|
14739
Description:
ViSiON-X contains a flaw that may allow a regular user to gain elevated privileges or execute arbitrary programs. The issue is due to the upload Matrix not properly sanitizing file names and storing files in the main BBS directory. An attacker could upload a file named VISION-X.EXE, COMMAND.COM, or COMMAND.EXE which would be executed the next time the BBS was run.
|
1992-07-10
|
ViSiON-X Matrix Upload Privilege Escalation
|
|
84726
Description:
Ultrix contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when /bin/mail is ran from shell-escape. This will allow a local attacker to gain access to any password submitted to su.
|
1992-07-08
|
Ultrix /bin/mail Privileged Program Local Password Disclosure
|
|
894
Description:
(Description Provided by CVE) : Denial of service by sending forged ICMP unreachable packets.
|
1992-07-02
|
Multiple Vendor ICMP Spoofed Packet Unreachable Connection DoS
|
|
3276
Description:
Unicos contains a flaw that allows an unprivileged local user to read arbitrary files and modify system configurations. The issue is due to a non-descript flaw in the "accton" command.
|
1992-06-25
|
UNICOS accton Read Arbitrary File
|
|
8111
Description:
NIS contains a flaw that may allow a malicious user to get password files. The issue is due to the insufficient access control for NIS Query. By guessing and requesting a domain name, a remote attacker can collect a password file from the NIS map replied by a NIS server, resulting in a loss of confidentiality, integrity, and/or availability.
|
1992-06-04
|
NIS Domain Name Password Disclosure
|
|
8028
Description:
(Description Provided by CVE) : SunOS 4.1.2 and earlier allows local users to gain privileges via "LD_*" environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.
|
1992-05-27
|
SunOS Dynamically Linked SETUID Program Privilege Escalation
|
|
30926
Description:
(Description Provided by CVE) : Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors.
|
1992-05-26
|
IBM AIX crontab -e Escaped Shell Local Privilege Escalation
|
|
25089
Description:
Unknown / Incomplete
|
1992-05-20
|
Empire Server telegram Remote DoS
|
|
892
Description:
(Description Provided by CVE) : FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.
|
1992-04-27
|
IBM AIX anon.ftp Script Arbitrary Command Execution
|
|
891
Description:
IBM AIX contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered by an insecure default configuration of UUCP where users can aquire root privileges. This flaw may lead to a loss of confidentiality and/or integrity.
|
1992-03-19
|
IBM AIX uucp Local Privilege Escalation
|
|
7988
Description:
(Description Provided by CVE) : AIX passwd allows local users to gain root access.
|
1992-03-01
|
IBM AIX passwd Local Privilege Escalation
|
|
8318
Description:
(Description Provided by CVE) : SAS System 5.18 on VAX/VMS is installed with insecure permissions for its directories and startup file, which allows local users to gain privileges.
|
1992-02-28
|
VAX/VMS SAS System Insecure Permission Privilege Escalation
|
|
890
Description:
(Description Provided by CVE) : Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.
|
1992-02-25
|
AT&T rexecd Remote Arbitrary Command Execution
|
|
17069
Description:
Unknown / Incomplete
|
1992-02-10
|
SCO UNIX at Arbitrary Privileged Command Execution
|
|
15267
Description:
Unknown / Incomplete
|
1992-01-24
|
SunOS binmail mailbox Race Condition Arbitrary File Creation
|
|
84725
Description:
UNIX and SysV R4 contain a flaw that is triggered by sadc having root privileges. This may allow an attacker to create arbitrary files that contain escalated privileges.
|
1992-01-08
|
UNIX SysV R4 sadc Arbitrary Privileged File Creation
|
|
84724
Description:
A/UX contains a flaw that is triggered by sadc having root privileges. This may allow an attacker to create arbitrary files that contain escalated privileges.
|
1992-01-08
|
A/UX sadc Arbitrary Privileged File Creation
|
|
17063
Description:
Unknown / Incomplete
|
1992-01-08
|
SCO Unix sadc Arbitrary Privileged File Creation
|
|
11449
Description:
(Description Provided by CVE) : The rwho/rwhod service is running, which exposes machine status and user information.
|
1992-01-01
|
rwho/rwhod Service Remote Information Disclosure
|
|
11451
Description:
The finger service provides information about local users in response to queries from remote systems. This information can include login ids (account names), home directory, the type of local shell, the last time the user logged in, and the remote system the user logged in from. This information can be used for further more focused attacks.
|
1992-01-01
|
finger Service Remote Information Disclosure
|
|
14727
Description:
KBBS contains a flaw that may allow a regular user to spoof the system operator (SYSOP) email. The issue is due to the bulletin board accepting white space in user names. This may allow a user to create a name that appears to be the same as the system operator (ie: "John Doe " instead of "John Doe"). Email from such a user may appear to be from the legitimate SYSOP and convince other users to execute commands or perform actions they would not otherwise do.
|
1992-01-01
|
KBBS Padded Name SYSOP Spoofing
|
|
14728
Description:
By default, Oblivion/2 installs with a default password. The SYSOP account has a password of "SYSOP" which is publicly known and documented. This allows attackers to trivially access the program or system.
|
1992-01-01
|
Oblivion/2 BBS Default SYSOP Password
|
|
14729
Description:
PCBoard contains a flaw that may allow a user to gain elevated privileges. The issue is due to the system not properly sanitizing input to the OP (Open door) command. If the system allows parameters such as /SYSOP, /DEBUG, or /SEC:255, these parameters can be invoked via the OPEN command to gain privileges.
|
1992-01-01
|
PCBoard BBS OP Command Privilege Escalation
|