| OSVDB ID | Disclosure Date | Title |
|
7393
Description:
(Description Provided by CVE) : xosview 1.5.1 in Red Hat 5.1 allows local users to gain root access via a long HOME environmental variable.
|
1998-05-28
|
Red Hat Linux xosview HOME Variable Overflow
|
|
8565
Description:
(Description Provided by CVE) : Vulnerability in (1) diskperf and (2) diskalign in IRIX 6.4 allows local attacker to create arbitrary root owned files, leading to root privileges.
|
1998-05-27
|
IRIX diskperf Arbitrary File Create Privilege Escalation
|
|
8566
Description:
(Description Provided by CVE) : Vulnerability in (1) diskperf and (2) diskalign in IRIX 6.4 allows local attacker to create arbitrary root owned files, leading to root privileges.
|
1998-05-27
|
IRIX diskalign Arbitrary File Create Privilege Escalation
|
|
8757
Description:
Unknown / Incomplete
|
1998-05-27
|
OSF Ladebug Debugger Local Privilege Escalation
|
|
1000
Description:
(Description Provided by CVE) : Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.
|
1998-05-26
|
Solaris libauth Local Overflow
|
|
83791
Description:
PHP contains a flaw that may allow a remote denial of service. The issue is triggered during the handling of a specially crafted ftp:// URL. This will result in loss of availability for the program.
|
1998-05-23
|
PHP Malformed ftp:// URL Handling DoS
|
|
83790
Description:
PHP is prone to an overflow condition. The Sybase-DB module fails to properly sanitize user-supplied input resulting in an overflow. With a specially crafted numeric data string, a remote attacker can potentially cause a loss of availability or execute arbitrary code.
|
1998-05-23
|
PHP Sybase-DB Module Numeric Data String Handling Overflow
|
|
11504
Description:
(Description Provided by CVE) : Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.
|
1998-05-21
|
BNU UUCP Long Hostname Local Overflow
|
|
9769
Description:
(Description Provided by CVE) : Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.
|
1998-05-18
|
ISC DHCP Distribution Server (dhcpd) Multiple Overflows
|
|
9984
Description:
(Description Provided by CVE) : Buffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental variable.
|
1998-05-16
|
KDE klock HOME Variable Local Overflow
|
|
12961
Description:
The 'man.sh' CGI script contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is triggered due to the script not properly sanitizing user-supplied input. It is possible that the flaw may allow a remote attacker to execute arbitrary commands with the privileges of the Web server resulting in a loss of integrity.
|
1998-05-16
|
SysAdmin Magazine man.sh CGI Script Arbitrary Command Execution
|
|
2930
Description:
Many old Award BIOS chips contained default passwords installed by the manufacturer to aid in tech support issues. Mid to late 1990's Award BIOS were often found to have one of the following default/backdoor passwords: "Condo", "AWARD_SW", "j332", and "589589".
|
1998-05-15
|
Award BIOS Default/Backdoor Passwords
|
|
5840
Description:
(Description Provided by CVE) : libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
|
1998-05-14
|
Solaris libnsl Library Multiple Overflows
|
|
6089
Description:
FreeBSD contains a flaw that may allow a malicious user to spoof a connection. The issue is triggered when a TCP CC larger than the one currently in per-host cache is sent to the victim platform. It is possible that the flaw may allow spoofing attacks resulting in a loss of integrity.
|
1998-05-14
|
FreeBSD T/TCP Extensions Transactions Spoofing
|
|
6610
Description:
(Description Provided by CVE) : Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.
|
1998-05-13
|
Cisco Cache Engine WCCP HTTP Traffic Redirection
|
|
6060
Description:
3Com Total Control NETServer Card contains a flaw that may allow a remote attacker to bypass filtering mechanisms. The issue is triggered when a port is set to "set host prompt", which allows an remote attacker to bypass restrictions by providing the hostname twice at the "host:" prompt, and gain unauthorized access to the system.
|
1998-05-11
|
3Com Total Control Chassis Double Hostname Filter Bypass
|
|
4416
Description:
Check Point FireWall-1 contains a flaw that may allow attackers access to resources that were intended to be restricted. The issue is due to a flaw in the firewall keyword mechanism and certain keywords being reserved. When a reserved keyword is used, the firewall rule will default to "ANY" which may allow traffic to a resource that was intended to be blocked.
|
1998-05-11
|
Check Point FireWall-1 Restricted Keyword Bypass
|
|
44249
Description:
By default, 3Com SuperStack II Switches install with multiple default accounts. The monitor, manager and security accounts each have a password the same as the account name, which is publicly known and documented. This allows attackers to trivially access the program or system.
|
1998-05-10
|
3Com SuperStack II Switch Multiple Default Accounts
|
|
44251
Description:
Unknown / Incomplete
|
1998-05-10
|
3Com SNMP Cleartext Router Password Disclosure
|
|
6427
Description:
CVSNT for Debian contains a non-descript flaw related to cvsconfig and the use of tempfile. No further details have been provided.
|
1998-05-10
|
CVSNT (Debian) cvsconfig Tempfile Unspecified
|
|
7297
Description:
(Description Provided by CVE) : A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections.
|
1998-05-10
|
Motorola CableRouter Memory Leak DoS
|
|
44264
Description:
Unknown / Incomplete
|
1998-05-10
|
Proteon Switch Unspecified Default Password
|
|
10609
Description:
(Description Provided by CVE) : Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages.
|
1998-05-09
|
Microsoft Windows WINS Malformed Packet Consumption DoS
|
|
965
Description:
(Description Provided by CVE) : Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.
|
1998-05-07
|
Solaris Admintool World Writeable Permissions Local Privilege Escalation
|
|
44248
Description:
By default, multiple 3Com switches install with a default password. The 'debug' account has a password of 'synnet' which is publicly known and documented. This allows attackers to trivially access the program or system.
|
1998-05-06
|
3Com LanPlex 2500 / Corebuilder Routers Default Backdoor (Undocumented) Account
|
|
44250
Description:
By default, multiple 3Com routers install with a default password. The 'tech' account has a password of 'tech' which is publicly known and documented. This allows attackers to trivially access the program or system.
|
1998-05-05
|
3Com Multiple Router Default tech Account
|
|
36
Description:
(Description Provided by CVE) : Netmanager Chameleon SMTPd has several buffer overflows that cause a crash.
|
1998-05-04
|
NetManage Chameleon SMTPd Remote Overflow DoS
|
|
83127
Description:
By default, multiple Quake products install with a default password that can be used as a backdoor. The issue is triggered by the program allowing an attacker to remotely send commands to the quake console. A remote attacker may be able to bypass authentication via a specially crafted UDP packet with a header containing the rcon command and the "tms" password with a source IP coming from ID software's subnet. When this is exploited, no logs are reported of the rcon command being used and the attacker may compromise an administrators access on any Quake server.
|
1998-05-02
|
Quake Multiple Products rcon Command Default Password Vendor Backdoor
|
|
2951
Description:
Hayes Century MR200 Channelized T-1 and PRI modem racks contain a default password allowing any remote user to successfully log in.
|
1998-05-02
|
Hayes Century MR200 Default Password
|
|
902
Description:
(Description Provided by CVE) : Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.
|
1998-05-01
|
Webmin Password Brute Force Weakness
|