| OSVDB ID | Disclosure Date | Title |
|
39
Description:
By default, the Cisco 675 router installs with no password. This allows attackers to trivially access the system via telnet.
|
1999-07-31
|
Cisco 675 Router Default Unpassworded Account
|
|
1029
Description:
Gauntlet Firewall contains a flaw that may allow a remote attacker to crash the firewall. The issue is due to a flaw in the packet filter when it receives a ICMP Parameter Problem packets. If an attacker sends a specially crafted packet with such an option to a machine behind the firewall, Gauntlet will crash.
|
1999-07-30
|
NAI Gauntlet Firewall Malformed ICMP Packet Handling Remote DoS
|
|
11864
Description:
(Description Provided by CVE) : Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.
|
1999-07-30
|
Netscape Enterprise Server HTML-tocrec-demo1.pat Arbitrary JHTML Source Disclosure
|
|
83461
Description:
ELS Screen to Screen contains a flaw that may lead to an unauthorized information disclosure. This issue is triggered due to password information being stored in the "Authorization" file. The encoded system protecting this file is considered weak and is able to be decoded. This issues may allow a local attacker to gain access to password information.
|
1999-07-30
|
ELS Screen to Screen Authorization File Local Encoded Password Disclosure
|
|
83445
Description:
Autothenticate contains a flaw that may lead to an unauthorized information disclosure. This issue is triggered when encoded site credentials are stored in the "AutothenticatePreferences" file located in the preferences folder. The encoding system used to protect this file is considered weak and is susceptible to being decoded, which may allow a local attacker to gain access to website login credentials.
|
1999-07-30
|
Autothenticate Stored Encoded Site Credentials Local Disclosure
|
|
4485
Description:
(Description Provided by CVE) : Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.
|
1999-07-30
|
Ethereal Packet Capture Symlink Arbitrary File Overwrite
|
|
7406
Description:
(Description Provided by CVE) : OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.
|
1999-07-30
|
BSD User chflags or fchflags on Character or Block Devices
|
|
11066
Description:
(Description Provided by CVE) : DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker.
|
1999-07-30
|
Multiple DNS Server Spoofed Source UDP DNS Query DoS
|
|
11447
Description:
(Description Provided by CVE) : The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.
|
1999-07-30
|
Cobalt RaQ2 Server Arbitrary Remote Software Installation
|
|
13557
Description:
Salesbuilder contains a flaw related to the to the .sbstart script that may allow an attacker to escalate privileges on the affected host. When installed the script is world-writeable and, if installed by root, will allow execution of commands at that privilege level.
|
1999-07-30
|
AcuShop Salesbuilder .sbstart Script Arbitrary Command Execution
|
|
83460
Description:
ELS Screen to Screen contains a flaw that may lead to an unauthorized information disclosure. This issue is triggered due to password information being stored in the "Authorization" file. When the file is deleted the username is reset to "Administrator" and the password is reset to "admin." This issues may allow a local attacker to bypass authentication.
|
1999-07-29
|
ELS Screen to Screen Authorization File Removal Authentication Bypass
|
|
1027
Description:
Check Point VPN-1/FireWall-1 contains a flaw that may allow a remote denial of service. The issue is triggered when a remote attacker sends an abundance of ACK packets to a non-existant machine which fills the connection table, and will result in loss of availability for the firewall.
|
1999-07-29
|
Check Point VPN-1/FireWall-1 Table Saturation DoS
|
|
7405
Description:
(Description Provided by CVE) : Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
|
1999-07-29
|
Microsoft Phone Dialer (dialer.exe) Dialer Entry Overflow
|
|
83459
Description:
On Guard for MacOS contains a flaw in the emergency password feature, which may allow an attacker to generate an emergency code and gain access to password information without placing a call to the vendor (Power on Software). This will allow the attacker to bypass authentication.
|
1999-07-29
|
On Guard for MacOS Emergency Password Challenge Generation Authentication Bypass
|
|
1028
Description:
Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.
|
1999-07-29
|
ColdFusion Undocumented CFML Tags Privilege Escalation
|
|
1052
Description:
(Description Provided by CVE) : The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.
|
1999-07-29
|
Microsoft Jet Database Text I-ISAM Arbitrary File Modification
|
|
10356
Description:
(Description Provided by CVE) : WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.
|
1999-07-29
|
WS_FTP Pro Client Weak Password Encryption
|
|
11369
Description:
(Description Provided by CVE) : SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control.
|
1999-07-29
|
HP Pavilion PC SystemSoft SystemWizard RegObj Control Arbitrary Command Execution
|
|
11370
Description:
(Description Provided by CVE) : SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control.
|
1999-07-29
|
HP Pavilion PC SystemSoft SystemWizard Launch Control Arbitrary Command Execution
|
|
83458
Description:
Internet Config for MacOS contains a flaw related to the preferences file in the preferences folder. The issue is triggered by the encryption used to protect the preferences file being weak and easily broken. This may allow an attacker to more easily gain access to password information.
|
1999-07-28
|
Internet Config for MacOS Preferences File Password Encryption Weakness
|
|
83792
Description:
PHP contains a flaw that may allow a remote denial of service. The issue is triggered when the fopen wrappers process a specially crafted URL. This will result in loss of availability for the program.
|
1999-07-28
|
PHP fopen Wrappers Malformed URL Handling DoS
|
|
8659
Description:
(Description Provided by CVE) : rpc.admind in Solaris is not running in a secure mode.
|
1999-07-28
|
Solaris rpc.admind Insecure Mode Remote Privilege Escalation
|
|
9345
Description:
(Description Provided by CVE) : A system does not present an appropriate legal message or warning to a user who is accessing it.
|
1999-07-28
|
System Does Not Present Appropriate Legal Access Message
|
|
9840
Description:
(Description Provided by CVE) : Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.
|
1999-07-28
|
Seattle Labs Emurl ASP File Attachment Execution
|
|
6104
Description:
(Description Provided by CVE) : IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.
|
1999-07-27
|
ipchains Fragmentation Header Port Rewrite Filter Bypass
|
|
83457
Description:
GNU groff contains a flaw that is triggered when a user opens a man page containing macros. These macros will be run under the UID of the user opening the page. This may allow an attacker to compromise a user's account (or the system if root is targeted) by executing arbitrary commands.
|
1999-07-26
|
GNU groff Man Page Macro Handling Arbitrary Command Execution
|
|
10389
Description:
(Description Provided by CVE) : Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.
|
1999-07-26
|
HP-UX Software Distributor SW-DIST.RUPDATE Fileset Overflows
|
|
10390
Description:
(Description Provided by CVE) : Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.
|
1999-07-26
|
HP-UX Software Distributor SW-DIST.SD-AGENT Fileset Overflows
|
|
10391
Description:
(Description Provided by CVE) : Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.
|
1999-07-26
|
HP-UX Software Distributor SW-DIST.SD-CMDS Fileset Overflows
|
|
14465
Description:
(Description Provided by CVE) : A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.
|
1999-07-26
|
Network Intrusion Detection System Packets Out of Order Bypass
|
|
14467
Description:
(Description Provided by CVE) : A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers.
|
1999-07-26
|
Network Intrusion Detection System Improper Sequence Numbers
|
|
14470
Description:
(Description Provided by CVE) : A network intrusion detection system (IDS) does not properly reassemble fragmented packets.
|
1999-07-26
|
Network Intrusion Detection System Fragmented Packet Reassemble Bypass
|
|
14473
Description:
(Description Provided by CVE) : A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets.
|
1999-07-26
|
Network Intrusion Detection Systems TCP Handshake Data Bypass
|
|
14474
Description:
(Description Provided by CVE) : A network intrusion detection system (IDS) does not verify the checksum on a packet.
|
1999-07-26
|
Network Intrusion Detection Systems Checksum Verification
|
|
28
Description:
This host is running the Squid Proxy server 'cachemanager' CGI. The cache manager CGI program, by default, contains no restricts or access permissions. With a malformed request, an intruder can use this script to launch port scans from the server.
|
1999-07-23
|
Squid cachemgr.cgi Proxied Port Scanning Weakness
|
|
8859
Description:
(Description Provided by CVE) : Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations.
|
1999-07-23
|
Samba smbmnt Race Condition Arbitrary Mount Point
|
|
8860
Description:
(Description Provided by CVE) : Denial of service in Samba NETBIOS name service daemon (nmbd).
|
1999-07-23
|
Samba NETBIOS Name Service Daemon DoS
|
|
68
Description:
This server is running Microsoft FrontPage extensions. FrontPage extensions allow anyone to download the .pwd files, which contain the encrypted passwords for FrontPage authors and Administrators. An attacker could easily decrypt these passwords and possible post or overwrite information on the target web server.
|
1999-07-22
|
Microsoft FrontPage Extensions .pwd File Permissions
|
|
11065
Description:
(Description Provided by CVE) : Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command.
|
1999-07-22
|
ipchains/ipfw Network Address Translation ping -R DoS
|
|
1025
Description:
(Description Provided by CVE) : Buffer overflow in Samba smbd program via a malformed message command.
|
1999-07-21
|
Samba smdb Malformed Message Handling Remote Overflow
|