| OSVDB ID | Disclosure Date | Title |
|
1184
Description:
AnalogX SimpleServer:WWW contains a flaw that allows a remote attacker to execute arbitrary code on the server. The issue is due to the web server not properly sanitizing GET requests. If an attacker sends a sepcially crafted GET request longer than 1000 bytes, they can overflow a buffer to execute arbitrary code.
|
1999-12-31
|
AnalogX SimpleServer:WWW GET Request Remote Overflow
|
|
1186
Description:
IRIX contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a malicious user appends a semicolon and arbitrary command to the end of a filename when saving a file in soundplayer. This flaw may lead to a loss of integrity.
|
1999-12-31
|
IRIX soundplayer midikeys Malformed .wav Arbitrary Command Execution
|
|
1183
Description:
(Description Provided by CVE) : Buffer overflow in CamShot WebCam HTTP server allows remote attackers to execute commands via a long GET request.
|
1999-12-30
|
CamShot GET Request Remote Overflow
|
|
1185
Description:
(Description Provided by CVE) : The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which allows local users to execute arbitrary commands.
|
1999-12-30
|
Optivity NETarchitect bna_pass Path Variable Local Privilege Escalation
|
|
1187
Description:
(Description Provided by CVE) : CascadeView TFTP server allows local users to gain privileges via a symlink attack.
|
1999-12-30
|
Ascend CascadeView tftpd /tmp/tftpd_xfer_status.log Symlink Arbitrary File Overwrite Privilege Escalation
|
|
1447
Description:
(Description Provided by CVE) : nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.
|
1999-12-30
|
Multiple Vendor nviboot Arbitrary File Delete
|
|
7577
Description:
(Description Provided by CVE) : Buffer overflow in UnixWare rtpm program allows local users to gain privileges via a long environmental variable.
|
1999-12-30
|
SCO UnixWare rtpm Environment Variable Overflow
|
|
15
Description:
AltaVista Intranet Search CGI contains a flaw that allows a remote attacker to read arbitrary files outside of the web path. The issue is due to the "query" not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the "mss" variable.
|
1999-12-29
|
AltaVista Intranet Search CGI query Traversal Arbitrary File Access
|
|
43
Description:
(Description Provided by CVE) : Buffer overflow in CSM mail server allows remote attackers to cause a denial of service or execute commands via a long HELO command.
|
1999-12-29
|
CSM Mail Server HELO Command Remote Overflow
|
|
1173
Description:
Open Transport in Mac OS 9 contains a flaw that may allow a remote denial of service. The issue is triggered when sending a malformed 29 byte long UDP packet, which will cause the machine to respond with an 1,500 byte long ICMP packet. It is possible for a remote attacker to use this behavior as an amplifier against other targets.
|
1999-12-29
|
Mac OS 9 Open Transport Malformed ICMP Datagram Response DoS
|
|
1585
Description:
(Description Provided by CVE) : Trend Micro PC-Cillin does not restrict access to its internal proxy port, allowing remote attackers to conduct a denial of service.
|
1999-12-29
|
Trend Micro PC-Cillin Internal Proxy Port DoS
|
|
1177
Description:
(Description Provided by CVE) : Denial of service in Savant web server via a null character in the requested URL.
|
1999-12-28
|
Savant Web Server GET Request NULL Character Handling Remote DoS
|
|
1181
Description:
(Description Provided by CVE) : Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.
|
1999-12-28
|
Majordomo -C Parameter Local Privilege Escalation
|
|
13626
Description:
(Description Provided by CVE) : resend command in Majordomo allows local users to gain privileges via shell metacharacters.
|
1999-12-28
|
Majordomo resend Command Local Privilege Escalation
|
|
1170
Description:
(Description Provided by CVE) : IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.
|
1999-12-28
|
Microsoft IIS Escape Character URL Access Bypass
|
|
84754
Description:
Fortech Proxy+ contains a flaw that is triggered when the program fails to properly enforce authentication on /admin. This may allow a remote unauthenticated attacker to gain administrator access.
|
1999-12-27
|
Fortech Proxy+ /admin Unauthenticated Remote Admin Access
|
|
232
Description:
(Description Provided by CVE) : Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.
|
1999-12-27
|
Mini SQL CGI content-length Field Remote Overflow
|
|
1179
Description:
(Description Provided by CVE) : IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.
|
1999-12-27
|
IBM Network Station Manager Race Condition Privilege Escalation
|
|
7581
Description:
(Description Provided by CVE) : The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.
|
1999-12-27
|
Red Hat Linux initscripts Symlink Privilege Escalation
|
|
1176
Description:
(Description Provided by CVE) : Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name.
|
1999-12-27
|
Avirt Rover POP3 Server Username Remote Overflow DoS
|
|
1178
Description:
(Description Provided by CVE) : InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments.
|
1999-12-27
|
Trend Micro InterScan VirusWall Scan Evasion
|
|
1180
Description:
(Description Provided by CVE) : UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack.
|
1999-12-27
|
SCO UnixWare pis/mkpis Symbolic Link
|
|
1174
Description:
(Description Provided by CVE) : WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.
|
1999-12-26
|
WebWho+ whois.pl type Parameter Arbitrary Command Execution
|
|
13585
Description:
(Description Provided by CVE) : FTPPro allows local users to read sensitive information, which is stored in plain text.
|
1999-12-26
|
FTPPro Local Information Disclosure
|
|
7579
Description:
(Description Provided by CVE) : strace allows local users to read arbitrary files via memory mapped file names.
|
1999-12-25
|
strace Memory Mapped File Name Arbitrary File Access
|
|
1172
Description:
(Description Provided by CVE) : Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.
|
1999-12-23
|
ZBSoft ZBServer GET Request Remote Overflow
|
|
7385
Description:
By default, glFTPd installs with a default password. The 'gltftpd' account has a password of 'gltftpd' which is publicly known and documented. This allows attackers to trivially access the program or system and gain privileged access.
|
1999-12-23
|
glFTPd Default Root Account
|
|
7386
Description:
(Description Provided by CVE) : glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.
|
1999-12-23
|
glFTPd SITE ZIPCHK Arbitrary Command Execution
|
|
7389
Description:
Unknown / Incomplete
|
1999-12-23
|
glFTPd /site Directory Permission Arbitrary File Overwrite
|
|
7578
Description:
(Description Provided by CVE) : ZBServer Pro allows remote attackers to read source code for executable files by inserting a . (dot) into the URL.
|
1999-12-23
|
ZBServer Pro Single Dot Source Disclosure
|
|
6269
Description:
One "feature" of Virus scanning software permits attackers to hide malicious code in the "RECYCLED" directory. On vulnerable platforms, this means that users will not be notified of the presence of malware which is placed in this directory, in the event that their machine is compromised. However, this could allow infected machines to continue to be used for malicious purposes that should otherwise be noticed and stopped.
|
1999-12-22
|
Multiple Virus Scanner Recycle Bin Scan Bypass
|
|
6310
Description:
The i2odialog daemon in UnixWare contains a flaw that may allow a remote attacker to gain access to unauthorized privileges. The issue is triggered due to improper bounds checking of the i2odialog daemon, resulting in an buffer overflow. When sending a long username/password authorization string with 88 or more characters, a remote attacker could gain root access, resulting in a loss of integrity.
|
1999-12-22
|
SCO UnixWare i2odialogd Daemon Username Authorization String Remote Overflow
|
|
1171
Description:
(Description Provided by CVE) : RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.
|
1999-12-22
|
RealServer Long ramgen Request Remote DoS
|
|
1182
Description:
(Description Provided by CVE) : Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.
|
1999-12-22
|
Sendmail Crafted ETRN Commands Remote DoS
|
|
7582
Description:
Sun Microsystems Solaris dmispd contains a flaw that may allow a local denial of service. The issue is triggered when dmi_cmd is used to add a file which has more than 1024 characters in the first line to the DMI database, and will result in loss of availability for the DMI service.
|
1999-12-22
|
Solaris dmi_cmd Malformed DB Entry dmispd DoS
|
|
7903
Description:
(Description Provided by CVE) : Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.
|
1999-12-22
|
Microsoft IE external.NavigateAndFind Arbitrary File Access
|
|
13644
Description:
(Description Provided by CVE) : Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of service via a long Location URL.
|
1999-12-22
|
RealPlayer Long Location URL DoS
|
|
11101
Description:
A remote overflow exists in Microsoft IIS. The server fails to handle overly long URLs which contain hundreds of forward slashes, resulting in an access violation. With a specially crafted request, an attacker can cause the server to crash, resulting in a loss of availability.
|
1999-12-22
|
Microsoft IIS Multiple Slash ASP Page Request DoS
|
|
11169
Description:
(Description Provided by CVE) : The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.
|
1999-12-22
|
ARP Reply Cache Poisoning
|
|
107
Description:
A remote overflow may exists in Linuxconf. The issue is due to the handling of HTTP headers resulting in a buffer overflow. When the Web administration mode is enabled, a remote attacker could send an overly long parameter to the USER_AGENT field, which may allow arbitrary code execution reulting in a loss of integrity.
|
1999-12-21
|
Linuxconf Long Parameter Remote Overflow
|