| OSVDB ID | Disclosure Date | Title |
|
579
Description:
(Description Provided by CVE) : PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.
|
2001-06-30
|
PHP Safe Mode mail() Function 5th Parameter Arbitrary Command Execution
|
|
1885
Description:
(Description Provided by CVE) : Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field.
|
2001-06-30
|
Citrix Nfuse launch.asp Path Disclosure
|
|
650
Description:
A remote overflow exists in the cgiemail cgicso. The script fails to verify input resulting in a buffer overflow. With a specially crafted request, an attacker can cause the execution of arbitrary code resulting in a loss of integrity.
|
2001-06-30
|
cgiemail cgicso Arbitrary Command Execution
|
|
12057
Description:
(Description Provided by CVE) : Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD.
|
2001-06-30
|
CesarFTPD Multiple Command Remote Overflow
|
|
56515
Description:
Unknown / Incomplete
|
2001-06-29
|
SmallHTTP URI Handling Overflow DoS
|
|
8033
Description:
(Description Provided by CVE) : PowerNet IX allows remote attackers to cause a denial of service via a port scan.
|
2001-06-29
|
PowerNet IX Portscan DoS
|
|
12124
Description:
(Description Provided by CVE) : Buffer overflow in internal string handling routines of xinetd before 2.1.8.8 allows remote attackers to execute arbitrary commands via a length argument of zero or less, which disables the length check.
|
2001-06-29
|
xinetd Internal String Handling Routine Remote Overflow
|
|
12403
Description:
(Description Provided by CVE) : vWebServer 1.2.0 allows remote attackers to view arbitrary ASP scripts via a request for an ASP script that ends with a URL-encoded space character (%20).
|
2001-06-29
|
vWebServer Encoded Space (%20) Request Arbitrary ASP Script Disclosure
|
|
12404
Description:
(Description Provided by CVE) : vWebServer 1.2.0 allows remote attackers to cause a denial of service via a URL that contains MS-DOS device names.
|
2001-06-29
|
vWebServer MS-DOS Device Name GET Request DoS
|
|
12405
Description:
(Description Provided by CVE) : vWebServer 1.2.0 allows remote attackers to cause a denial of service (hang) via a small number of long URL requests, possibly due to a buffer overflow.
|
2001-06-29
|
vWebServer Multiple Long URL Request DoS
|
|
88643
Description:
CylantSecure contains a flaw in the Kernel module. The issue is may allow a local attacker to escape monitoring and perform a syscall rerouting outside the system's infrastructure. This may allow the attacker to execute arbitrary local programs.
|
2001-06-29
|
CylantSecure Kernel Module Syscall Rerouting Infrastructure Bypass
|
|
19754
Description:
A remote overflow exists in MacOS. The 'Personal Web Sharing' control panel fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request containing an overly long password, a remote attacker can cause the system to freeze resulting in a loss of availability.
|
2001-06-28
|
Mac OS Personal Web Sharing Long Password Overflow DoS
|
|
5542
Description:
(Description Provided by CVE) : Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response, which is not properly handled by the svc_logprint function.
|
2001-06-28
|
xinetd Long Ident Response Remote Overflow
|
|
584
Description:
McAfee ASaP VirusScan agent contains a flaw that allows a remote attacker to view arbitrary files outside of the web path. The issue is due to the built in web server not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the URI.
|
2001-06-28
|
McAfee ASaP VirusScan Arbitrary File Access
|
|
5585
Description:
A local buffer overflow exists in IBM AIX library libi18n. The library function _GETLAYOUTINITFUNC fails to validate the length of the LANG environment variable resulting in a buffer overflow. With a specially crafted request, an attacker can gain root privileges resulting in a loss of confidentiality and/or integrity.
|
2001-06-28
|
IBM AIX libi18n Library Long LANG Variable Overflow
|
|
6172
Description:
A remote overflow exists in Trend Micro InterScan VirusWall. The HttpSaveCVP.dll file fails to validate bounds checking resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2001-06-28
|
Trend Micro InterScan VirusWall HttpSaveCVP.dll Overflow
|
|
6173
Description:
A remote overflow exists in Trend Micro InterScan VirusWall. The HttpSaveCSP.dll file fails to validate bounds checking resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2001-06-28
|
Trend Micro InterScan VirusWall HttpSaveCSP.dll Overflow
|
|
6178
Description:
(Description Provided by CVE) : Buffer overflow in smtpscan.dll for Trend Micro InterScan VirusWall 3.51 for Windows NT has allows remote attackers to execute arbitrary code via a certain configuration parameter.
|
2001-06-28
|
Trend Micro InterScan VirusWall smtpscan.dll Overflow
|
|
578
Description:
IOS contains a flaw that may allow a malicious user to bypass authentication. The issue is triggered when an attacker sends a specially crafted URL to the HTTP server. It is possible that the flaw may allow an attacker to gain administrative privileges resulting in a loss of confidentiality, integrity, and/or availability.
|
2001-06-27
|
Cisco IOS HTTP Unauthorized Administrative Access
|
|
9427
Description:
A buffer overflow exists in Oracle. The TNS Listener fails to validate passed to the STATUS, PING, SERVICES, TRC_FILE, SAVE_CONFIG and RELOAD commands resulting in a stack overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2001-06-27
|
Oracle TNS Listener Multiple Command Argument Handling Remote Overflow
|
|
12326
Description:
Active Classifieds contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue occurs because several subroutines in admin.cgi do not check for valid user authentication before processing input. This flaw may lead to execution of arbitrary code causing a loss of integrity.
|
2001-06-27
|
Active Classifieds admin.cgi table_width Parameter Arbitrary Command Execution
|
|
45904
Description:
(Description Provided by CVE) : Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary code via a long LDAP_OPTIONS environment variable to a privileged program that uses libsldap.
|
2001-06-27
|
Solaris LDAP Naming Services Library (libsldap) LDAP_OPTIONS Environment Variable Local Overflow
|
|
3561
Description:
Cisco IOS, CatOS and WebNS contain a flaw that may lead to an unauthorized information disclosure. The issue is triggered by the disclosure of password length by SSH protocol, which will disclose information of value in a brute force attack resulting in a loss of confidentiality.
|
2001-06-27
|
Cisco Devices SSH Password Length Disclosure
|
|
9323
Description:
(Description Provided by CVE) : Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.
|
2001-06-27
|
SCO UnixWare uucp Command Line Argument Local Overflow
|
|
9324
Description:
(Description Provided by CVE) : Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.
|
2001-06-27
|
SCO UnixWare uux Command Line Argument Local Overflow
|
|
9325
Description:
(Description Provided by CVE) : Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.
|
2001-06-27
|
SCO UnixWare bnuconvert Command Line Argument Local Overflow
|
|
9326
Description:
(Description Provided by CVE) : Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.
|
2001-06-27
|
SCO UnixWare uucico Command Line Argument Local Overflow
|
|
9327
Description:
(Description Provided by CVE) : Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.
|
2001-06-27
|
SCO UnixWare uuxcmd Command Line Argument Local Overflow
|
|
9328
Description:
(Description Provided by CVE) : Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.
|
2001-06-27
|
SCO UnixWare uuxqt Command Line Argument Local Overflow
|
|
9426
Description:
(Description Provided by CVE) : Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension.
|
2001-06-27
|
Oracle Transparent Network Substrate (TNS) Malformed SQLNet Connection Request Remote DoS
|
|
19241
Description:
(Description Provided by CVE) : Buffer overflow in cron in Caldera UnixWare 7 allows local users to execute arbitrary code via a command line argument.
|
2001-06-27
|
Caldera UnixWare cron Command Line Argument Overflow
|
|
59511
Description:
(Description Provided by CVE) : Vulnerability in CIFS/9000 Server (SAMBA) A.01.06 and earlier in HP-UX 11.0 and 11.11, when configured as a print server, allows local users to overwrite arbitrary files by modifying certain resources.
|
2001-06-27
|
HP-UX CIFS/9000 Server (SAMBA) Unspecified Resource Modification Arbitrary File Overwrite
|
|
88704
Description:
The Linux Kernel contains a flaw that may lead to unauthorized privileges being gained. The issue is due to the procfs mem file (/proc/$$/mem) insecurely handling user access. By reading from 'mem' via close()ing fd 0, open()ing it with /proc/<current_pid>/mem, and then using lseek(), a local attacker can read arbitrary memory offsets in a running process. This may disclose sensitive information including passwords that can be used to gain privileges.
|
2001-06-27
|
Linux Kernel procfs mem Informaiton Disclosure Local Privilege Escalation
|
|
1883
Description:
Icecast contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the server not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the URI.
|
2001-06-26
|
Icecast Encoded Traversal Arbitrary File Access
|
|
7040
Description:
Mac OS X contains a flaw that may lead to an unauthorized password exposure. It is possible to gain access to encrypted passwords using the nidump command, which may lead to a loss of confidentiality.
|
2001-06-26
|
Apple Mac OS X nidump Encrypted Password Disclosure
|
|
1882
Description:
It was reported that early/beta versions of Mac OS X created each user's Desktop folder with world-readable and world-writable permissions by default. After further testing by the security community, this was demonstrated to be untrue.
|
2001-06-26
|
Apple Mac OS X Insecure Default Desktop Folder Permissions
|
|
11621
Description:
(Description Provided by CVE) : gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.
|
2001-06-26
|
GNATS GnatsWeb gnatsweb.pl Arbitrary Command Execution
|
|
14260
Description:
(Description Provided by CVE) : cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.
|
2001-06-26
|
idtools cvmlogin pathexec_env Function Local Privilege Escalation
|
|
14261
Description:
(Description Provided by CVE) : cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.
|
2001-06-26
|
idtools statfile pathexec_env Function Local Privilege Escalation
|
|
577
Description:
Microsoft Front Page Server Extensions (FPSE), included in IIS Web Server, contain a flaw that may allow a remote attacker to execute arbitrary code. The issue is due to a sub-component in FPSE called Visual Studio Remote Application Deployment (RAD) which allows Visual InterDev users to register and un-register programming components on the IIS server. The sub-component contains an unchecked buffer that may allow an attacker to execute arbitrary code with IUSR_Machine privileges.
|
2001-06-25
|
FrontPage Server Extensions Visual Studio RAD Support Overflow
|