| OSVDB ID | Disclosure Date | Title |
|
17807
Description:
(Description Provided by CVE) : Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters.
|
2001-08-25
|
Netegrity SiteMinder Unicode URL Filter Bypass
|
|
19894
Description:
Unknown / Incomplete
|
2001-08-25
|
PHProjekt Multiple Modules Unspecified Issues
|
|
12485
Description:
Qpopper contains a flaw that may allow a malicious user to get unauthorized information. The issue is due to different error messages being output when authentication attempts are made using valid and invalid usernames. When qpopper is used in conjunction with PAM, remote attackers can enumerate valid account usernames, resulting in a loss of confidentiality.
|
2001-08-25
|
Qpopper PAM Authentication Error Message User Name Enumeration
|
|
14144
Description:
(Description Provided by CVE) : Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registry key to decrypt the password and gain privileges.
|
2001-08-24
|
Starfish Truesync Desktop Registry Password Storage Weak Encryption
|
|
14145
Description:
(Description Provided by CVE) : Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to restrict access, which allows an attacker to read the files using a different application.
|
2001-08-24
|
Starfish Truesync Desktop Insecure File Storage
|
|
14146
Description:
(Description Provided by CVE) : Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly guess the key via a brute force attack.
|
2001-08-24
|
Starfish Truesync Desktop Small Keyspace Brute Force Weakness
|
|
63720
Description:
(Description Provided by CVE) : NWFTPD.nlm before 5.01w in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via an anonymous STOU command.
|
2001-08-24
|
Novell NetWare FTP Server NWFTPD.nlm Anonymous STOU Command Remote DoS
|
|
14818
Description:
Adobe Acrobat for Linux contains a flaw in the libCoolType library. The issue is triggered when the application creates the AdobeFnt.lst file with insecure permissions. With a specially crafted request, a local attacker can manipulate arbitrary files.
|
2001-08-23
|
Adobe Acrobat (acroread) libCoolType Library AdobeFnt.lst Permission Weakness
|
|
8823
Description:
(Description Provided by CVE) : Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets.
|
2001-08-23
|
Cisco 600 Series Routers Multiple Service Connection Flood Remote DoS
|
|
11802
Description:
(Description Provided by CVE) : Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can read the WEBCT.SVR file to decrypt the passwords and gain additional privileges.
|
2001-08-23
|
Respondus for WebCT WEBCT.SVR File Weak Encryption
|
|
14071
Description:
(Description Provided by CVE) : UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read the file to decrypt the passwords and gain privileges.
|
2001-08-23
|
UltraEdit uedit32.ini Password Storage Encryption Weakness
|
|
1936
Description:
(Description Provided by CVE) : BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space.
|
2001-08-23
|
BSCW Groupware Data-Bag Symbolic Link Arbitrary File Access
|
|
1943
Description:
(Description Provided by CVE) : Buffer overflow in uidadmin in Caldera Open Unix 8.0.0 and UnixWare 7 allows local users to gain root privileges via a long -S (scheme) command line argument.
|
2001-08-23
|
Caldera uidadmin Scheme Overflow
|
|
8828
Description:
(Description Provided by CVE) : Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack.
|
2001-08-23
|
Cisco 600 Series Routers Web-based Configuration Utility Persistence
|
|
11011
Description:
(Description Provided by CVE) : Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.
|
2001-08-23
|
Microsoft Windows NT Netbt.sys Malformed DNS Response DoS
|
|
88586
Description:
CuteFTP contains a flaw that is due to the program using what has been reported to be a insecure encoding for the sm.dat file which stores password information. This may allow a local attacker to more easily gain access to password information if the site manager password has not been set.
|
2001-08-23
|
CuteFTP sm.dat Password Storage Weak Encryption
|
|
1939
Description:
(Description Provided by CVE) : Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP request with a long Authorization header.
|
2001-08-22
|
AOLServer Authorization Header HTTP Request Remote Overflow
|
|
14711
Description:
Unknown / Incomplete
|
2001-08-22
|
WebGUI Poll Unauthorized Vote
|
|
8605
Description:
(Description Provided by CVE) : BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request.
|
2001-08-22
|
BadBlue Personal Edition Null Byte Request Source Code Disclosure
|
|
8981
Description:
Dynu FTP Server contains a flaw that allows a remote attacker to traverse directories outside of the web path. The issue is due to the program not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the CWD command.
|
2001-08-22
|
Dynu FTP Server CD Command Arbitrary File Access
|
|
14232
Description:
A remote overflow exists in A-V Tronics: InetServ. The Webmail interface fails to verify the length of the 'Username' and 'Password' fields resulting in a buffer overflow. With a specially crafted request, an attacker can cause denial of service via network, execution of arbitrary code via network, or root access via network resulting in a loss of confidentiality, integrity, and availability.
|
2001-08-22
|
A-V Tronics Inetserv Webmail Interface Username Overflow
|
|
5456
Description:
Panda Antivirus Platinum contains a flaw that may allow a REMOTE denial of service. The issue is triggered when a malformed UPX packed exe examination occurs, and will result in loss of availability for the Antivirus Functionality.
|
2001-08-21
|
Panda Anti-Virus Platinum Malformed Executable DoS
|
|
14170
Description:
BSD contains a flaw that may allow a local denial of service. The issue is triggered when a malicious user compiles and executes shell code that causes a bad system call, resulting in a reboot and loss of availability for the platform.
|
2001-08-21
|
BSDI Malformed System Call Local DoS
|
|
608
Description:
This host is running the IrDa service. This service provides infrared-based connectivity to Windows hosts. A buffer overflow exists in the IrDa handling code in Windows 2000. An attacker can use this to shutdown the machine if they can physically locate themselves within a few feet of the server.
|
2001-08-21
|
Microsoft Windows IrDa Driver Malformed Packet Remote Overflow DoS
|
|
1938
Description:
linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.
|
2001-08-21
|
FreeBSD linprocfs Privileged Process Memory Disclosure
|
|
8735
Description:
(Description Provided by CVE) : ns6install installation script for Netscape 6.01 on Solaris, and other versions including 6.2.1 beta, allows local users to overwrite arbitrary files via a symlink attack.
|
2001-08-21
|
Netscape on Solaris ns6install Symlink Arbitrary File Overwrite
|
|
8957
Description:
(Description Provided by CVE) : Directory traversal vulnerability in WhitSoft Development SlimFTPd 2.2 allows an attacker to read arbitrary files and directories via a ... (modified dot dot) in the CD command.
|
2001-08-21
|
SlimFTPd CD Command Triple Dot Traversal Arbitrary File Access
|
|
14119
Description:
Sage Software MAS 200 contains a flaw that may allow a remote denial of service. The issue is triggered when a malicious user telnets to port 10000 on the server and then inputs ctrl-x 10 times, and will result in loss of availability for the service.
|
2001-08-21
|
Sage Software MAS Port 10000 Malformed Data DoS
|
|
86902
Description:
Apache contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an HTTP request without a trailing '/' character returns a 3xx redirect error code. This error code contains a 'location' response-header, which may allow a remote attacker to gain access to the server's internal address.
|
2001-08-21
|
Apache HTTP Server 3xx Redirect Internal IP Address Remote Disclosure
|
|
88585
Description:
FreeBSD contains a flaw that may lead to an unauthorized information disclosure. The issue is due to an error in the procfs file system that allows processes that initially had debugging rights to an arbitrary process to retain these rights even if the targeted process has gained escalated privileges. This may allow a local attacker to access the targeted processes memory space and gain access to potentially sensitive information.
|
2001-08-21
|
FreeBSD procfs Privileged Process Memory Local Disclosure
|
|
14174
Description:
(Description Provided by CVE) : Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by decrypting the information, e.g., with the Disengage tool.
|
2001-08-20
|
Intego FileGuard User Information Storage Weak Encryption
|
|
8958
Description:
(Description Provided by CVE) : Directory traversal vulnerability in ASCII NT WinWrapper Professional allows remote attackers to read arbitrary files via a .. (dot dot) in the server request.
|
2001-08-20
|
ASCII NT WinWrapper Double Dot Arbitrary File Access
|
|
10816
Description:
(Description Provided by CVE) : Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.
|
2001-08-20
|
IBM Lotus Domino SMTP Server Forged Localhost Mail Header DoS
|
|
14056
Description:
(Description Provided by CVE) : Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."
|
2001-08-20
|
Surf-Net ASP Forum Predictable Cookie Weakness
|
|
59413
Description:
(Description Provided by CVE) : Directory traversal vulnerability in ACI 4d webserver allows remote attackers to read arbitrary files via a .. (dot dot) or drive letter (e.g., C:) in an HTTP request.
|
2001-08-20
|
4D Web Server URI Traversal Arbitrary File Access
|
|
90027
Description:
AlphaTCL contains a flaw that is due to ftpMenu handling weakly encoded or not encrypting FTP credentials. This may allow a context-dependent attacker to more easily access credential information.
|
2001-08-20
|
AlphaTCL ftpMenu FTP Credential Handling Weakness
|
|
1951
Description:
Check Point FireWall-1 contains a flaw that may allow a malicious administrator to execute arbitrary code on the vulnerable system. The issue is due to a buffer overflow in the GUI log view utility which can be accessed by administrators. If an attacker with permissions to view logs via the GUI interface sends specially crafted data, they may be able to execute arbitrary commands with root privileges.
|
2001-08-19
|
Check Point FireWall-1 GUI Log Viewer Overflow
|
|
605
Description:
Sendmail versions 8.10.0 through 8.11.5, and 8.12.0 betas, contain a signed integer overflow in the handling of large numbers passed to the '-d' command line parameter. Local attackers can execute arbitrary code with elevated privileges if sendmail is setuid/setgid (which it typically is).
|
2001-08-17
|
Sendmail -d category Value Local Overflow
|
|
1935
Description:
(Description Provided by CVE) : glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.
|
2001-08-17
|
glFTPd Asterisk Character LIST Command Remote DoS
|
|
1937
Description:
FreeBSD contains a flaw that may allow a malicious user to bypass a firewall. The issue is triggered when ipfw is used with the "me" identifier on a point to point interface. It is possible that the flaw may allow unintended access to the local system by a remote host resulting in a loss of integrity.
|
2001-08-17
|
FreeBSD IPFW me PPP Ruleset Bypass
|