| OSVDB ID | Disclosure Date | Title |
|
8733
Description:
The FTP client included with Solaris contains a flaw that allows a malicious FTP server to execute arbitrary commands on the client computer. No further details have been provided.
|
1998-09-30
|
Solaris FTP Client Arbitrary Command Execution
|
|
11158
Description:
(Description Provided by CVE) : Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.
|
1998-09-30
|
Microsoft Windows NT Malformed Token Ring DoS
|
|
11496
Description:
(Description Provided by CVE) : A malicious Palace server can force a client to execute arbitrary programs.
|
1998-09-30
|
Palace Client Server Trust Arbitrary Program Execution
|
|
13690
Description:
(Description Provided by CVE) : Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (carbon copy) parameter.
|
1998-09-28
|
Multiple Unix mailx mail -c Parameter Local Overflow
|
|
11265
Description:
(Description Provided by CVE) : The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.
|
1998-09-28
|
Microsoft Windows NT Malformed RPC Packet Error Message Loop DoS (snork)
|
|
84985
Description:
Check Point Firewall-1 contains a flaw that is triggered when information sent to the session agent module is not encrypted. This may allow an attacker to spoof a valid session agent and gain access to user credentials.
|
1998-09-24
|
Check Point Firewall-1 Session Agent Cleartext Authentication Credentials Spoofing Weakness
|
|
6023
Description:
SLMail contains a flaw that may allow a remote denial of service. The issue is triggered when sending commands containing open parentheses ('('), and will result in loss of availability for the smtp service.
|
1998-09-22
|
SLMail Malformed Command DoS
|
|
83787
Description:
PHP is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted imap_header or header_info header line that is larger than 1024 characters, an attacker can potentially cause a loss of availability.
|
1998-09-22
|
PHP imap_header / header_info Header Line Parsing Overflow DoS
|
|
83786
Description:
PHP contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an error message displays user credential information. In some cases, it may be the full username and password, and in other cases it may be obscured but reveal the length of each making enumeration a bit easier.
|
1998-09-22
|
PHP Error Message User Credential Disclosure
|
|
11977
Description:
(Description Provided by CVE) : SMTP server in SLmail 3.1 and earlier allows remote attackers to cause a denial of service via malformed commands whose arguments begin with a "(" (parenthesis) character, such as (1) SEND, (2) VRFY, (3) EXPN, (4) MAIL FROM, (5) RCPT TO.
|
1998-09-22
|
SLmail SMTP Server Multiple Command Unmatched Parentheses DoS
|
|
612
Description:
(Description Provided by CVE) : The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE.
|
1998-09-18
|
Novell NetWare NDS Tree Remote Information Disclosure
|
|
7942
Description:
Unknown / Incomplete
|
1998-09-17
|
Apache HTTP Server mod_ssl Default Pass Phrase
|
|
9770
Description:
(Description Provided by CVE) : ROUTERmate has a default SNMP community name which allows remote attackers to modify its configuration.
|
1998-09-14
|
ROUTERmate Default SNMP Community Name
|
|
1441
Description:
Unknown / Incomplete
|
1998-09-12
|
IRCnet IRCD res.c Unspecified Overflow
|
|
1097
Description:
Cisco PIX and IOS Firewall extensions contain a flaw that may allow a REMOTE denial of service. The issue is triggered when a large number of fragmented packets are sent to a protected host, and will result in loss of availability for the targeted host.
|
1998-09-10
|
Cisco PIX / IOS Fragmentation Attack Remote DoS
|
|
92
Description:
(Description Provided by CVE) : iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.
|
1998-09-09
|
iChat Server Traversal Arbitrary File Read
|
|
8041
Description:
(Description Provided by CVE) : SSH 1.2.25 on HP-UX allows access to new user accounts.
|
1998-09-07
|
HP-UX SSH New User Account Access
|
|
7837
Description:
Microsoft Internet Explorer contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a user visits a malicious web site, which could read files on the local file system.
|
1998-09-04
|
Microsoft IE Cross Frame Security Arbitrary File Access
|
|
8345
Description:
A local overflow exists in bash. The rl_redisplay() function fails to perform proper bounds checking resulting in a buffer overflow. The issue is triggered when creating a overly long directory name containing more than 1024 bytes, which is inserted into the password prompt via the '\w' option in the PS1 environmental variable when another user changes into that directory. It is possible for a malicious user to gain elevated privileges resulting in a loss of integrity.
|
1998-09-04
|
bash \w option PS1 Environment Variable Overflow
|
|
250
Description:
(Description Provided by CVE) : wwwboard allows a remote attacker to delete message board articles via a malformed argument.
|
1998-09-03
|
WWWBoard wwwboard.pl Arbitrary Forum Post Deletion
|
|
4505
Description:
(Description Provided by CVE) : Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
|
1998-09-01
|
CDE ToolTalk RPC Service Remote Overflow
|
|
8785
Description:
(Description Provided by CVE) : Buffer overflow in web administration feature of Kolban Webcam32 4.8.3 and earlier allows remote attackers to execute arbitrary commands via a long URL.
|
1998-09-01
|
Kolban Webcam32 Long URL Overflow
|