| OSVDB ID | Disclosure Date | Title |
|
56525
Description:
(Description Provided by CVE) : Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.
|
1999-08-31
|
Microsoft Eyedog ActiveX Unspecified Overflow
|
|
159
Description:
(Description Provided by CVE) : Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.
|
1999-08-30
|
amd AMQPROC_MOUNT Procedure Remote Overflow
|
|
6543
Description:
(Description Provided by CVE) : Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.
|
1999-08-30
|
Mars NetWare Emulation Long Directory Name Overflow
|
|
6056
Description:
Management information base(MIB) for 3Com SuperStack II hub contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an object identifier accessible by a read-only community string leads to lists the entire table of community strings, allowing attackers to conduct unauthorized activities resulting in a loss of confidentiality.
|
1999-08-30
|
3Com SuperStack II Hub MIB Community String Disclosure
|
|
6862
Description:
(Description Provided by CVE) : E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled.
|
1999-08-30
|
FirstClass Internet Server home.fc Password Disclosure
|
|
6863
Description:
(Description Provided by CVE) : E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled.
|
1999-08-30
|
FirstClass Internet Server network.fc Password Disclosure
|
|
6864
Description:
(Description Provided by CVE) : E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled.
|
1999-08-30
|
FirstClass Internet Server FCCLIENT.LOG Password Disclosure
|
|
7550
Description:
cron contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an attacker manipulates the MAILTO environment variable, which is executed by the root user. This flaw may lead to a loss of integrity.
|
1999-08-30
|
cron MAILTO Overflow Privilege Escalation
|
|
144
Description:
(Description Provided by CVE) : Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.
|
1999-08-27
|
ProFTPD src/log.c log_xfer() Function Remote Overflow
|
|
1066
Description:
(Description Provided by CVE) : FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers.
|
1999-08-27
|
Multiple BSD setsockopt() Saturation Local DoS
|
|
8210
Description:
(Description Provided by CVE) : Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.
|
1999-08-27
|
Microsoft HTML Control Large Form Field DoS
|
|
8717
Description:
wu-ftpd contains a flaw that may allow a malicious user to overwrite arbitrary files. The issue is triggered when an attacker sends a specially formed rnfr command. It is possible that the flaw may allow the attacker to overwrite any file on the system as root resulting in a loss of integrity.
|
1999-08-27
|
WU-FTPD rnfr File Overwrite
|
|
79358
Description:
Unknown / Incomplete
|
1999-08-26
|
GSM A5/2 Algorithm Known Plaintext Attack Cryptanalysis Weakness
|
|
1055
Description:
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.
|
1999-08-26
|
WU-FTPD MAPPING_CHDIR Feature Overflow
|
|
1058
Description:
(Description Provided by CVE) : Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.
|
1999-08-25
|
Vixie Cron MAILTO Environement Variable Overflow
|
|
1061
Description:
(Description Provided by CVE) : Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.
|
1999-08-25
|
Vixie Cron MAILTO Sendmail Variable Manipulation
|
|
1059
Description:
(Description Provided by CVE) : Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.
|
1999-08-24
|
NT Predictable TCP Sequence Number
|
|
1060
Description:
(Description Provided by CVE) : Denial of service in Debian IRC Epic/epic4 client via a long string.
|
1999-08-24
|
EPIC4 ircII Long String DoS
|
|
1053
Description:
(Description Provided by CVE) : The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.
|
1999-08-23
|
Linux pt_chown Arbitrary TTY Modification
|
|
9664
Description:
(Description Provided by CVE) : IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.
|
1999-08-23
|
IBM GINA for OS/2 GroupMapping Registry Key Privilege Escalation
|
|
1057
Description:
Lotus Notes Domino Server LDAP Service contains a flaw that may allow a remote denial of service. The issue is triggered when a very long string is submitted to ldap_search occurs, and will result in loss of availability for the Notes Server.
|
1999-08-23
|
IBM Lotus Domino Server NLDAP DoS
|
|
1453
Description:
(Description Provided by CVE) : The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions.
|
1999-08-23
|
Multiple Vendor XDMCP Access Restriction Bypass
|
|
3501
Description:
Microsoft FrontPage contains a flaw that may lead to an unauthorized information disclosure. The issue is due to "form_results.[txt|htm|html]" being accessable to anyone via the web. This file contains user supplied input and may contain logins, passwords or other sensitive information.
|
1999-08-23
|
Microsoft FrontPage form_results Information Disclosure
|
|
9832
Description:
(Description Provided by CVE) : Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]).
|
1999-08-22
|
WindowMaker Remote Overflow
|
|
1054
Description:
(Description Provided by CVE) : The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.
|
1999-08-21
|
Microsoft IE scriptlet.typelib ActiveX Arbitrary Command Execution
|
|
10977
Description:
(Description Provided by CVE) : The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.
|
1999-08-21
|
Microsoft Eyedog ActiveX Server Side Redirect Arbitrary Command Execution
|
|
59322
Description:
Jet Database contains a flaw that may allow an attacker to execute arbitrary commands. The issue is triggered when a malicious user submits a specially crafted database query.
|
1999-08-20
|
Microsoft Jet Database Crafted Query Arbitrary Command Execution
|
|
7428
Description:
MHonArc contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the .mhonarc.db file is publically accessible, which will disclose address information resulting in a loss of confidentiality.
|
1999-08-20
|
MHonArc .mhonarc.db Address Information Disclosure
|
|
13563
Description:
SHOUTcast contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when viewing the sc_serv.conf or viewing the log file occurs, which will disclose the administrator password information resulting in a loss of confidentiality.
|
1999-08-20
|
SHOUTcast Server sc_serv.conf Admin Password Cleartext Disclosure
|
|
1048
Description:
(Description Provided by CVE) : Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.
|
1999-08-19
|
IBM AIX Source Code Browser Overflow
|
|
6205
Description:
(Description Provided by CVE) : Trn allows local users to overwrite other users' files via symlinks.
|
1999-08-19
|
trn Symlink Overwrite Arbitrary File
|
|
6541
Description:
(Description Provided by CVE) : The logging facilitity of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.
|
1999-08-19
|
Debian smtp-refuser Package Symlink Arbitrary File Deletion
|
|
7675
Description:
CiscoSecure Access Control Server (CiscoSecure ACS) for UNIX contains a flaw that may allow a remote attacker to modify the database. The issue is due to the database access protocol not properly authenticating clients. Without authenticating, an attacker can read and write to the server database, including modification of access policies.
|
1999-08-19
|
CiscoSecure Access Control Server (CiscoSecure ACS) for UNIX Unauthenticated Database Modification
|
|
9766
Description:
(Description Provided by CVE) : QMS CrownNet Unix Utilities for 2060 allows root to log on without a password.
|
1999-08-19
|
QMS CrownNet Unix Utilities for 2060 Default Root Passwordless Account
|
|
59826
Description:
(Description Provided by CVE) : Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
|
1999-08-19
|
vqSoft vqServer for Windows DOS Filename Request Access Bypass
|
|
59827
Description:
(Description Provided by CVE) : Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
|
1999-08-19
|
Xitami Web Server DOS Filename Request Access Bypass
|
|
59828
Description:
Unknown / Incomplete
|
1999-08-19
|
Cat Soft Serv-U DOS Filename Request Access Bypass
|
|
1051
Description:
(Description Provided by CVE) : Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.
|
1999-08-18
|
NetKit (netkit-telnet) telnetd Malformed TERM Environment Variable DoS
|
|
1049
Description:
(Description Provided by CVE) : The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.
|
1999-08-18
|
Mini SQL w3-msql Arbitrary Directory Access
|
|
61158
Description:
Unknown / Incomplete
|
1999-08-18
|
web2ldap ldap-client-cgi FORM Tag METHOD-parameter Unspecified Issue
|