| OSVDB ID | Disclosure Date | Title |
|
10332
Description:
(Description Provided by CVE) : Ceilidh allows remote attackers to obtain the real path of the Ceilidh directory via the translated_path hidden form field.
|
2000-06-08
|
Ceilidh translated_path Form Field Path Disclosure
|
|
6287
Description:
McAfee VirusScan contains a flaw that may allow a malicious user to send an unlimited amount of alerts to the Central Alert server. The issue is triggered due to insecure permissions of the alert text file, which contains informations such as username, computer name and informations about detected viruses. It is possible that the flaw may allow an malicious user to arbitrary modify these informations resulting in a loss of integrity.
|
2000-06-07
|
McAfee VirusScan Unauthorized User Alert File Modification
|
|
6220
Description:
(Description Provided by CVE) : The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the "Linux kernel setuid/setcap vulnerability."
|
2000-06-07
|
Linux Kernel capabilities CAP_SETUID Feature Local Privilege Escalation
|
|
2715
Description:
A remote overflow exists in WU-FTPD if S/KEY support is enabled. The skey_challenge function in ftpd.c fails to perform bounds checking on the name variable resulting in a buffer overflow. With a specially crafted request, a remote attacker can execute arbitrary code.
|
2000-06-07
|
WU-FTPD S/KEY Authentication ftpd.c skey_challenge Function Remote Overflow
|
|
1390
Description:
(Description Provided by CVE) : The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to modify SNMP configuration or gain privileges.
|
2000-06-07
|
HP-UX snmpd.conf SNMPD File Permission Weakness Local Privilege Escalation
|
|
3399
Description:
ColdFusion Web Server's administrative login page allows a remote attacker to launch a denial of service. The issue is due to a lack of sanity checks on user submitted content passed to the password field. If a password of 40,000 characters is provided, the web server may crash.
|
2000-06-07
|
ColdFusion Administrator Login Page Remote DoS
|
|
13686
Description:
(Description Provided by CVE) : Buffer overflow in restore program 0.4b17 and earlier in dump package allows local users to execute arbitrary commands via a long tape name.
|
2000-06-07
|
Linux restore Tape Name Variable Local Overflow
|
|
1387
Description:
SSH port in FreeBSD contains a misconfiguration in its sshd_config file that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the SSH daemon is configured to listen on network port 722, in addition to the usual port 22. This flaw may allow malicious users to bypass firewall restrictions and lead to a loss of integrity.
|
2000-06-07
|
FreeBSD SSH Port Extra Network Port
|
|
1388
Description:
(Description Provided by CVE) : Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request.
|
2000-06-07
|
i-drive Filo HTTP GET Request Overflow
|
|
1389
Description:
APS Filter Development Team apsfilter contains a flaw that when used on FreeBSD may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when apsfilter, which uses the lpd printing daemon with a setuid of root, insecurely reads filter configurations created by a malicious user. This flaw may lead to a loss of integrity.
|
2000-06-07
|
FreeBSD apsfilter lpd Arbitrary Command Execution
|
|
4866
Description:
eTrust contains a flaw that may lead to an unauthorized password exposure. It is possible to gain access to plaintext passwords by accessing a specific registry key and decoding the encrypted passwords, which may lead to a loss of integrity.
|
2000-06-07
|
CA eTrust Intrusion Detection Password Exposure
|
|
338
Description:
(Description Provided by CVE) : Buffer overflow in innd 2.2.2 allows remote attackers to execute arbitrary commands via a cancel request containing a long message ID.
|
2000-06-06
|
INN verifycancels Option Cancel Request Message Overflow
|
|
1376
Description:
(Description Provided by CVE) : ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information.
|
2000-06-06
|
ICQ 2000A Mailclient Temporary Link
|
|
1380
Description:
(Description Provided by CVE) : Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a long MKD command.
|
2000-06-06
|
Etype Eserv MKD Command Logging Remote Overflow
|
|
1392
Description:
(Description Provided by CVE) : When configured to store configuration information in an LDAP directory, Shiva Access Manager 5.0.0 stores the root DN (Distinguished Name) name and password in cleartext in a file that is world readable, which allows local users to compromise the LDAP server.
|
2000-06-06
|
Shiva Access Manager World Readable LDAP Password
|
|
81028
Description:
CGIProxy contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an unspecified error occurs when handling headers, which will disclose private information to an attacker.
|
2000-06-06
|
CGIProxy Content-Type: Header Handling Unspecified Private Information Disclosure
|
|
7817
Description:
Microsoft Internet Explorer contains a flaw that may lead to an unauthorized information disclosure. The problem is due to improper enforcement of frames separation in the same window residing in different domains, which could allow a malicious Web site operator to open a frame in his own domain and a frame that refers to the visiting victim's file system. It is possible to view arbitrary files on a visiting victim's computer if the remote attacker knows or can guess the name and location of the file and if the file can be displayed in a Web browser window resulting in a loss of confidentiality.
|
2000-06-06
|
Microsoft IE Frame Domain Validation Arbitrary File Access
|
|
7900
Description:
(Description Provided by CVE) : The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.
|
2000-06-06
|
Microsoft IE WebBrowser Control NavigateComplete2 Policy Bypass
|
|
7669
Description:
phpGroupWare contains a flaw related to the addressbook. No further details have been provided.
|
2000-06-05
|
phpGroupWare Addressbook Unspecified Issues
|
|
1379
Description:
FireWall-1 contains a flaw that may allow a remote denial of service. The issue is triggered when a remote attacker sends a large amount of incomplete framgented packets, and will result in loss of availability for the platform.
|
2000-06-05
|
Check Point FireWall-1 Fragmented Packet Parsing Remote DoS
|
|
517
Description:
(Description Provided by CVE) : Savant web server allows remote attackers to read source code of CGI scripts via a GET request that does not include the HTTP version number.
|
2000-06-05
|
Savant Web Server Malformed GET Request CGI Source Disclosure
|
|
1385
Description:
(Description Provided by CVE) : BRU backup software allows local users to append data to arbitrary files by specifying an alternate configuration file with the BRUEXECLOG environmental variable.
|
2000-06-05
|
BRU BRUEXECLOG Variable Arbitrary File Modification
|
|
1378
Description:
(Description Provided by CVE) : Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities.
|
2000-06-05
|
Microsoft IE SSL Certificates Validation Failure (v1)
|
|
1382
Description:
(Description Provided by CVE) : Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to execute arbitrary commands via a long GET request.
|
2000-06-05
|
Computalynx CMail Web Interface Buffer Overflow
|
|
1383
Description:
(Description Provided by CVE) : Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to cause a denial of service by sending a large user name to the user dialog running on port 8002.
|
2000-06-05
|
Computalynx CMail Web Interface CPU Consumption DoS
|
|
7826
Description:
(Description Provided by CVE) : Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities.
|
2000-06-05
|
Microsoft IE SSL Certificate Validation Failure (v2)
|
|
20188
Description:
(Description Provided by CVE) : Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.
|
2000-06-04
|
Microsoft Windows Crafted SMB SMBnegprots Request DOS
|
|
408
Description:
(Description Provided by CVE) : Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.
|
2000-06-04
|
Microsoft Windows Malformed DCE/RPC SMBwriteX Request DoS
|
|
1417
Description:
(Description Provided by CVE) : xinetd 2.1.8.x does not properly restrict connections if hostnames are used for access control and the connecting host does not have a reverse DNS entry.
|
2000-06-04
|
xinetd Connection Filtering Via Hostname
|
|
11416
Description:
(Description Provided by CVE) : Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.
|
2000-06-04
|
Microsoft Outlook/Express Blank Header DoS
|
|
6493
Description:
(Description Provided by CVE) : PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords.
|
2000-06-03
|
PassWD Weogj System Passwords Storage Encryption Weakness
|
|
7668
Description:
phpGroupWare contains a flaw related to the 'login.php3' script. No further details have been provided.
|
2000-06-02
|
phpGroupWare login.php3 Unspecified Issue
|
|
1374
Description:
(Description Provided by CVE) : man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.
|
2000-06-02
|
HP-UX man Symlink Arbitrary File Overwrite
|
|
83441
Description:
rxvtcontains a flaw that may allow a denial of service. The issue is triggered when a remote attacker is able to resize the terminal window via escape character sequences, which will cause a denial of service. This flaw will result in loss of availability for the xterm.
|
2000-06-02
|
rxvt Embedded Escape Character Handling DoS
|
|
1491
Description:
The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability.
|
2000-06-02
|
Microsoft Windows 9x IPX Ping Packet DoS
|
|
83442
Description:
X11R6 contains a flaw that may allow a denial of service. The issue is triggered when a remote attacker is able to resize the terminal window via escape character sequences, which will cause a denial of service. This flaw will result in loss of availability for the xterm.
|
2000-06-01
|
XFree86 X11R6 Embedded Escape Character Handling DoS
|
|
8348
Description:
PuTTY contains a flaw that may allow a denial of service. The issue is triggered when a remote attacker is able to resize the terminal windows size by escape character sequences, which will cause a denial of service. This flaw will result in loss of availability for the xterm.
|
2000-06-01
|
PuTTY xterm Client Embedded Escape Character DoS
|
|
83443
Description:
Eterm contains a flaw that may allow a denial of service. The issue is triggered when a remote attacker is able to resize the terminal window via escape character sequences, which will cause a denial of service. This flaw will result in loss of availability for the xterm.
|
2000-06-01
|
Eterm Embedded Escape Character Handling DoS
|
|
337
Description:
(Description Provided by CVE) : Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command.
|
2000-06-01
|
Imate Webmail Server HELO Command Remote Overflow
|
|
340
Description:
(Description Provided by CVE) : Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request.
|
2000-06-01
|
NetWin DSMTP (Dmail) ETRN Command Overflow
|