| OSVDB ID | Disclosure Date | Title |
|
17182
Description:
Unknown / Incomplete
|
1995-01-04
|
Solaris /etc Directory Permission Weakness
|
|
17179
Description:
Unknown / Incomplete
|
1995-01-03
|
Solaris Multiple Config/Log File Permission Weakness
|
|
17180
Description:
Unknown / Incomplete
|
1995-01-03
|
Solaris hostname.le0 Permission Weakness Unauthorized Hostname Modification
|
|
17181
Description:
Unknown / Incomplete
|
1995-01-03
|
Solaris SUNWdxlib Permission Weakness Privilege Escalation
|
|
12964
Description:
(Description Provided by CVE) : rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.
|
1995-01-02
|
Linux rxvt -print-pipe Local Privilege Escalation
|
|
60
Description:
(Description Provided by CVE) : finger 0@host on some systems may print information on some user accounts.
|
1995-01-02
|
Multiple Vendor fingerd 0@host User List Remote Information Disclosure
|
|
63
Description:
(Description Provided by CVE) : finger .@host on some systems may print information on some user accounts.
|
1995-01-02
|
Multiple Vendor fingerd .@host User List Remote Information Disclosure
|
|
199
Description:
(Description Provided by CVE) : FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.
|
1995-01-01
|
Multiple Vendor TCP/IP ISN Sequence Prediction Weakness
|
|
334
Description:
It is possible to modify the registry paths to commonly used applications. The path to a Trojan program could be substituted, and the next time the application is executed the Trojan could be used to gain unauthorized access.
|
1995-01-01
|
Microsoft Windows Registry: Permission to Modify Common Paths
|
|
2048
Description:
By default, PCexpress BBS installs with a default password. The connect password has a password of "QU ME CYKEL PUMPE MED SKOR" which is publicly known and documented. This allows attackers to trivially access the program or system.
|
1995-01-01
|
PCexpress BBS Backdoor Password
|
|
5958
Description:
FastCGI mod_fastcgi package contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker executes the "echo.exe" program, which will disclose extensive details about the machine's operating environment resulting in a loss of confidentiality.
|
1995-01-01
|
FastCGI echo Information Disclosure
|
|
62
Description:
Unknown / Incomplete
|
1995-01-01
|
Multiple Web Server finger CGI Information Disclosure
|
|
75
Description:
(Description Provided by CVE) : A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user.
|
1995-01-01
|
Multiple FTP Server QUOTE CWD Command Home Path Disclosure
|
|
94
Description:
(Description Provided by CVE) : ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.
|
1995-01-01
|
Multiple Vendor ICMP timestamp Request Information Disclosure
|
|
95
Description:
(Description Provided by CVE) : ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.
|
1995-01-01
|
Multiple Vendor ICMP netmask Request Information Disclosure
|
|
129
Description:
This host is running a FTP server. The user account 'GUEST' is allowed to login. An attacker could use this to download or upload files, and possibly take control of this host.
|
1995-01-01
|
Microsoft Windows NT FTP 'guest' Account
|
|
200
Description:
(Description Provided by CVE) : Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.
|
1995-01-01
|
Multiple Web Server CGI Directory Command Interpretor
|
|
304
Description:
It is possible to determine the Windows Service Pack level of this system by reading the registry via NetBIOS. An attacker could use this information to determine potential vulnerabilities on the system. Depending on the Windows configuration and version, a valid username and password may be required before this information can be obtained.
|
1995-01-01
|
Microsoft Windows NT service pack level via remote registry access
|
|
331
Description:
It is possible for authenticated, non- administrative domain users on a Windows NT network to access several hives in the registry remotely. An attacker could cause denials of service conditions or elevate access by modifying various keys.
|
1995-01-01
|
Microsoft Windows Remote Registry Access
|
|
7757
Description:
Iniquity BBS contains a flaw that may allow a remote attacker to access arbitrary files. The issue is due to the E-mail system not filtering or limiting what files can be attached. If an attacker sends e-mail to himself and specifies a sensitive file, the file will be attached to the e-mail and disclosed.
|
1995-01-01
|
Iniquity BBS E-mail Arbitrary File Access
|
|
9352
Description:
(Description Provided by CVE) : A Sendmail alias allows input to be piped to a program.
|
1995-01-01
|
Sendmail Alias Piped Input Issue
|
|
9645
Description:
(Description Provided by CVE) : vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.
|
1995-01-01
|
HP-UX vhe_u_mnt Symlink Arbitrary Root Owned File Creation
|
|
9726
Description:
Multiple Unix vendors install the rpc.rquotad service by default. This service may allow remote attackers to gain information about NFS services including user/system quotas.
|
1995-01-01
|
rpc.rquotad Service NFS Information Disclosure
|
|
11094
Description:
(Description Provided by CVE) : Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.
|
1995-01-01
|
Microsoft Windows NT User Mode Application Handle Closing DoS
|
|
11095
Description:
(Description Provided by CVE) : When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies.
|
1995-01-01
|
Microsoft Windows NT Ntconfig.pol Long Server Name Access Restriction Bypass
|
|
92995
Description:
By default, Advanced Integration BIOS installs with default user credentials (username/password combination). Any account name supplied has a password of 'Advance', which is publicly known and documented. This allows physically present attackers to trivially access the program or system and gain privileged access.
|
1995-01-01
|
Advanced Integration BIOS Default Password
|