| OSVDB ID | Disclosure Date | Title |
|
85829
Description:
Allaire JRun contains a flaw that may allow a remote denial of service. The issue is triggered when multiple malformed requests are made to the Java /servlet/. This will result in a loss of availability for the program.
|
2000-10-31
|
Allaire JRun /servlet/ Malformed Request Remote DoS
|
|
457
Description:
Exchange contains a flaw that may allow a remote denial of service. The issue is triggered when a specially crafted email is sent, which contains specific malformed MIME headers, and will result in loss of availability for the service.
|
2000-10-31
|
Microsoft Exchange Malformed MIME Header DoS
|
|
469
Description:
ServletExec contains a flaw that may allow a remote attacker to arbitrarily upload files. The problem is that the application does not restrict access to the 'com.unify.ewave.servletexec.UploadServlet' servlet. It is possible that the flaw may allow a remote attacker to create a HTML form and upload JSP files to the server and execute arbitrary commands resulting in a loss of integrity.
|
2000-10-31
|
Unify eWave ServletExec UploadServlet Unprivileged File Upload
|
|
3250
Description:
ezbounce contains a flaw that may allow a local user to cause a denial of service. The issue is due to the ezbounce.pid file being written with randomg permissions. If the file becomes world writeable at any point, a local attacker could change the PID inside the file to an arbitrary program, which could then be killed from another process such as CRON, as is often the case.
|
2000-10-31
|
ezbounce PID File Random Permissions Local DoS
|
|
13753
Description:
(Description Provided by CVE) : CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.
|
2000-10-31
|
CS&T CorporateTime Error Message Account Enumeration
|
|
215
Description:
(Description Provided by CVE) : Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.
|
2000-10-30
|
Samba Web Administration Tool (SWAT) cgi.log Symlink Arbitrary File Modification
|
|
1625
Description:
(Description Provided by CVE) : Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks.
|
2000-10-30
|
Samba Web Administration Tool (SWAT) Failed Login Logging Failure Weakness
|
|
1626
Description:
(Description Provided by CVE) : Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords.
|
2000-10-30
|
Samba Web Administration Tool (SWAT) cgi.log Permission Weakness Information Disclosure
|
|
13754
Description:
(Description Provided by CVE) : Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords of other users.
|
2000-10-30
|
Serv-U FTP Server Brute Force Protection Bypass
|
|
17769
Description:
ServletExec contains a flaw that may allow a remote denial of service. The issue is triggered when issuing a specially crafted HTTP GET request containing the '/servlet/' string, which causes the servlet engine to crash resulting in a loss of availability.
|
2000-10-30
|
Unify eWave ServletExec GET /servlet/ Request Remote DoS
|
|
441
Description:
(Description Provided by CVE) : Search engine in Ultraseek 3.1 and 3.1.10 (aka Inktomi Search) allows remote attackers to cause a denial of service via a malformed URL.
|
2000-10-30
|
Verity UltraSeek Malformed URL DoS
|
|
487
Description:
(Description Provided by CVE) : Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server.
|
2000-10-30
|
Samba Web Administration Tool (SWAT) Error Message Username Enumeration
|
|
13747
Description:
(Description Provided by CVE) : dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.
|
2000-10-30
|
Red Hat Linux dump RSH Environment Variable Subversion Privilege Escalation
|
|
13751
Description:
(Description Provided by CVE) : eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which invokes the ServletExec servlet and causes an exception if the servlet is already running.
|
2000-10-30
|
Unify eWave ServletExec JSP/Java Servlet Engine /servlet/ URL DoS
|
|
59350
Description:
(Description Provided by CVE) : Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart.
|
2000-10-30
|
Samba Web Administration Tool (SWAT) Malformed HTTP Request Saturation Remote DoS
|
|
88637
Description:
FreeBSD contains a format string flaw in the vipw functionality in the chpass utility family. The issue is triggered as format string specifiers (e.g. %s and %x) are not properly sanitized. With a specially crafted request, a local attacker can gain escalated privileges.
|
2000-10-30
|
FreeBSD chpass Util Family vipw Format String Local Privilege Escalation
|
|
440
Description:
(Description Provided by CVE) : Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.
|
2000-10-29
|
KW Whois CGI whois Parameter Arbitrary Command Execution
|
|
488
Description:
(Description Provided by CVE) : Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.
|
2000-10-29
|
Metertek pagelog.cgi Traversal Arbitrary File Access
|
|
14158
Description:
(Description Provided by CVE) : Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.
|
2000-10-28
|
Multiple Unix Shell << Redirect Symlink Arbitrary File Overwrite
|
|
1621
Description:
IIS 5.0 Indexing Services for Windows 2000 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the CiRestriction parameter in a .htw request upon submission, allowing Active Scripting to execute on a the host's browser. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server. A remote attacker can visit a Web page containing malicious code that requests an .htw file, causing Active Scripting to execute active content on a visiting user's computer.
|
2000-10-28
|
Microsoft Indexing Services for Windows 2000 .htw XSS
|
|
1620
Description:
A remote overflow exists in bftpd. The USER command fails to validate user-supplied input resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2000-10-27
|
bftpd USER Command Buffer Overflow
|
|
1622
Description:
(Description Provided by CVE) : nss_ldap earlier than 121, when run with nscd (name service caching daemon), allows remote attackers to cause a denial of service via a flood of LDAP requests.
|
2000-10-27
|
nss_ldap nscd LDAP Request Flood DoS
|
|
1630
Description:
(Description Provided by CVE) : CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.
|
2000-10-27
|
CGI Script Center News Update Unauthenticated Admin Password Modification
|
|
8570
Description:
(Description Provided by CVE) : The presence of the Distributed GL Daemon (dgld) service on port 5232 on SGI IRIX systems allows remote attackers to identify the target host as an SGI system.
|
2000-10-27
|
IRIX Port 5232 dgld Service Information Disclosure
|
|
1627
Description:
(Description Provided by CVE) : cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.
|
2000-10-26
|
Cyrus SASL (cyrus-sasl) User Authentication Restriction Bypass
|
|
8813
Description:
(Description Provided by CVE) : Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.
|
2000-10-26
|
Cisco Virtual Central Office Credential Encryption Weakness
|
|
444
Description:
Cisco Catalyst contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when a specially crafted URL is sent to the web interface. It is possible that the flaw may allow arbitrary code execution resulting in a loss of confidentiality, integrity, and/or availability.
|
2000-10-26
|
Cisco Catalyst Web Interface /exec Remote Command Execution
|
|
486
Description:
iPlanet Certificate Management System contains a flaw that allows a remote attacker to access arbitrary files of the web path. The issue is due to the server not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the URI.
|
2000-10-26
|
iPlanet CMS Traversal Arbitrary File Access
|
|
4086
Description:
Netscape Directory Server contains a flaw that allows a remote attacker to access arbitrary files of the web path. The issue is due to the server not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the URI.
|
2000-10-26
|
Netscape Directory Server Traversal Arbitrary File Access
|
|
5830
Description:
MAILsweeper for SMTP contains a flaw that may allow a remote denial of service. The issue is triggered when a corrupt document is attached to an email, and will result in loss of availability for the MAILsweeper service.
|
2000-10-26
|
MAILsweeper for SMTP Corrupt CDA Document DoS
|
|
437
Description:
(Description Provided by CVE) : Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.
|
2000-10-26
|
iPlanet Web Server SHTML Logging Filename Remote Overflow
|
|
3206
Description:
TIS Internet Firewall Toolkit (FWTK) contains a flaw that allows a remote attacker to execute arbitrary code on the vulnerable system. The flaw is due to the pmsg() function in the x-gw package. If an attacker supplied malicious code, the sanity checks the function performs will not report the error only, instead it reports the error along with the malicious code which it executes.
|
2000-10-26
|
Firewall ToolKit x-gw Exectue Arbitrary Code
|
|
4087
Description:
iPlanet CMS has a flaw that allows a local or remote attacker to obtain the administrative password. The issue is due to the software storing the administrator password plaintext in the admin-serv/config/adm.conf file. Used in conjunction with other vulnerabilities present in this software, a remote attacker could request this file and obtain the password.
|
2000-10-26
|
iPlanet CMS Admin Password Stored Cleartext
|
|
4088
Description:
Netscape Directory Server has a flaw that allows a local or remote attacker to obtain the administrative password. The issue is due to the software storing the administrator password plaintext in the admin-serv/config/adm.conf file. Used in conjunction with other vulnerabilities present in this software, a remote attacker could request this file and obtain the password.
|
2000-10-26
|
Netscape Directory Server Admin Password Stored Cleartext
|
|
7245
Description:
(Description Provided by CVE) : The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.
|
2000-10-26
|
MySQL Pluggable Authentication Module (pam_mysql) Password Disclosure
|
|
7008
Description:
(Description Provided by CVE) : HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.
|
2000-10-25
|
Sun HotJava Browser Javascript Arbitrary DOM Access
|
|
1513
Description:
A remote overflow exists in ntop when running in 'web server' (-w) mode. The program fails to validate input to the filename variable resulting in a buffer overflow. With a specially crafted request, an attacker can execute arbitrary code resulting in a loss of integrity.
|
2000-10-25
|
ntop -w Option Filename Buffer Overflow
|
|
6717
Description:
Cisco devices running IOS software may be prone to a denial of service attack if a URL containing the question mark followed by a slash (?/) is requested. The device will enter an infinite loop when the supplied with the URL containing a "?/" and an enable password. Subequently, the router or switch will crash in two minutes after the watchdog timer has expired and will then reload. In certain cases the device will not reload and restart. In such a case, however, a manual restart would be required to regain normal functionality.
|
2000-10-25
|
Cisco IOS HTTP Server ?/ String Handling Local DoS
|
|
6782
Description:
Web+ contains a flaw related to ODBC connections. No further details have been provided.
|
2000-10-25
|
talentsoft Web+ Unspecified ODBC Connection Issue
|
|
545
Description:
(Description Provided by CVE) : The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands.
|
2000-10-25
|
Oracle Enterprise Listener (tnslsnr) Multiple Variable Log/Trace Manipulation Local Privilege Escalation
|