| OSVDB ID | Disclosure Date | Title |
|
11796
Description:
(Description Provided by CVE) : man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.
|
2003-08-06
|
man-db .manpath File DEFINE Directive Local Privilege Escalation
|
|
60577
Description:
man-db contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when the open_cat_stream() function is called, allowing a local attacker to gain root privileges.
|
2003-08-06
|
man-db open_cat_stream() Function Local Code Execution
|
|
59799
Description:
Unknown / Incomplete
|
2003-08-05
|
Firestorm IDS IPX Matching Code Unspecified DoS
|
|
59798
Description:
Unknown / Incomplete
|
2003-08-05
|
Firestorm IDS fagrouter Unspecified DoS
|
|
59797
Description:
Unknown / Incomplete
|
2003-08-05
|
Firestorm IDS TCP Options Parsing Unspecified Remote DoS
|
|
2121
Description:
Mollensoft FTP server contains a flaw that allows malicious users to obtain usernames and passwords. This is possible due to Mollensoft's insecure storage of user information unencrypted on the filesystem. Local access to the system running Mollensoft FTP server is required.
|
2003-08-05
|
Mollensoft FTP Server Password Exposure
|
|
2371
Description:
Unknown / Incomplete
|
2003-08-05
|
vqSoft vqServer irunin.ini Cleartext Admin Credential Local Disclosure
|
|
2372
Description:
Unknown / Incomplete
|
2003-08-05
|
bj Http Web Server config/users.properties Authentication Credential Cleartext Disclosure
|
|
30241
Description:
Unknown / Incomplete
|
2003-08-05
|
bj Http Web Server Default Administrator Password
|
|
2369
Description:
Unknown / Incomplete
|
2003-08-05
|
TightVNC QueryAllowNoPass Unspecified Authentication Bypass
|
|
2367
Description:
Unknown / Incomplete
|
2003-08-05
|
RobotFTP Server rftpsrvr.bot Account Credential Cleartext Disclosure
|
|
44162
Description:
Unknown / Incomplete
|
2003-08-05
|
Asset Tracker Unspecified SQL Injection
|
|
3184
Description:
IISShield contains a flaw that may allow a remote attacker to bypass the default rules that prevent malicious attacks from reaching the IIS server. The flaw occurs when a specific byte check is sent to the server, IISShield recognizes it as a bad request but fails to drop the request.
|
2003-08-05
|
IISShield HTTP Request Bypass Ruleset
|
|
6859
Description:
phpGroupWare contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that variables in the 'infolog' module are not verified properly and will allow a remote attacker to inject or manipulate SQL queries. No further details have been provided.
|
2003-08-05
|
phpGroupWare Infolog Module Multiple Parameter SQL Injection
|
|
9492
Description:
(Description Provided by CVE) : IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
|
2003-08-05
|
IBM DB2 db2job Symlink Privilege Escalation
|
|
9493
Description:
(Description Provided by CVE) : IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
|
2003-08-05
|
IBM DB2 db2job2 Symlink Privilege Escalation
|
|
3855
Description:
e107 contains a flaw that allows a remote attacker to access and use the resetcore.php script. This allows someone to change the theme of the CMS and alter the appearance of the site.
|
2003-08-04
|
e107 resetcore.php Change Arbitrary Theme
|
|
2362
Description:
Unknown / Incomplete
|
2003-08-04
|
Perception LiteServe accounts22.dat Account Credential Cleartext Disclosure
|
|
2363
Description:
Unknown / Incomplete
|
2003-08-04
|
Small HTTP Server http.cfg Administrator Account Cleartext Disclosure
|
|
2375
Description:
ZoneAlarm contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when two specially crafted requests are created using the DeviceIoControl function from the vsdatant.sys driver. This flaw may lead to a loss of integrity.
|
2003-08-04
|
ZoneAlarm TrueVector Device Driver vsdatant.sys DeviceIoControl Function Privilege Escalation
|
|
2360
Description:
Unknown / Incomplete
|
2003-08-04
|
RAV AntiVirus ActiveX Component update() Function Overflow
|
|
2361
Description:
Unknown / Incomplete
|
2003-08-04
|
Novell GroupWise HTTP GET Request Log File Authentication Credential Disclosure
|
|
2370
Description:
(Description Provided by CVE) : Buffer overflow in xtokkaetama allows local users to gain privileges via a long -nickname command line argument, a different vulnerability than CVE-2003-0611.
|
2003-08-04
|
xtokkaetama -nickname Privilege Escalation
|
|
12884
Description:
Unknown / Incomplete
|
2003-08-04
|
PHPObject useKey Directive Unspecified Security Issue
|
|
2376
Description:
NetBSD contains a flaw that may allow a remote denial of service. The issue is triggered when a malicious user sends a carefully prepared OSI networking packet to a victim system that is using the OSI networking kernel (sys/netiso), and will result in loss of availability for the platform.
|
2003-08-04
|
NetBSD OSI Networking Kernel DoS
|
|
3068
Description:
Microsoft Internet Explorer contains a flaw that allows remote attackers to launch external programs such as "Notepad" as a form of denial of service. The flaw is due to the behavior of IE to automatically open certain MIME types and protocols. This allows an attacker to load specific files in notepad, regardless of content or size. By creating a page that loads hundreds of instances of a 20 meg file, an attacker could effectively crash the machine.
|
2003-08-04
|
Microsoft IE MSHTML/EditFlag Auto Open DoS
|
|
2377
Description:
Compaq Insight Manager HTTP Server contains a flaw that may allow a malicious user to compromise the Insight Manager system. The issue is triggered when a long URL with malicious data is sent to the server. It is possible that the flaw may allow the execution of arbitrary code with LocalSystem privileges resulting in a loss of control.
|
2003-08-03
|
Compaq Insight Agent Format String
|
|
6551
Description:
Postfix contains a design flaw which may allow an attacker to use the mail server in SMTP 'bounce' scanning or even DDoS attacks. A specially crafted recipient field can cause the mail server to connect and communicate with an arbitrary host/port.
|
2003-08-03
|
Postfix Bounce Scan / Packet Amplification DDoS
|
|
10544
Description:
(Description Provided by CVE) : The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.
|
2003-08-03
|
Postfix Malformed Envelope Address nqmgr DoS
|
|
10545
Description:
(Description Provided by CVE) : The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.
|
2003-08-03
|
Postfix Multiple Mail Header SMTP listener DoS
|
|
15209
Description:
Cisco LEAP contains a flaw that may allow a malicious user to recover user accounts and passwords. Cisco LEAP is a modified implementation of MS-CHAPv2, which is vulnerable to dictionary attacks. It is possible that the flaw may allow offline brute force recovery of usernames and passwords resulting in a loss of confidentiality.
|
2003-08-02
|
Cisco LEAP Challenge/Response Authentication Weakness
|
|
2364
Description:
The netfilter module of the Linux kernel contains a flaw that may allow a remote denial of service. The issue is triggered when Network Address Translation (NAT) is enabled, and either the ip_nat_ftp or ip_nat_irc modules have been loaded or CONFIG_IP_NF_NAT_FTP or CONFIG_IP_NF_NAT_IRC are enabled. This will result in loss of availability for the platform.
|
2003-08-02
|
Linux IPTables / Netfilter NAT SACK mangle DoS
|
|
6061
Description:
The netfilter (iptables) module of the Linux kernel contains a flaw that may allow a remote denial of service. The issue is triggered only when the connection tracking module ip_conntrack is loaded. When a large number of packets are sent to a machine so configured, one-way traffic packets are marked incorrectly as UNCONFIRMED statein the linked list, and assigned a very high timeout. This eventually consumes large amounts of system memory, and will result in loss of availability for the platform.
|
2003-08-02
|
Linux IPTables / Netfilter Connection Tracking Linked List DoS
|
|
2356
Description:
(Description Provided by CVE) : mindi 0.58 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.
|
2003-08-02
|
mindi Symlink Arbitrary File Overwrite
|
|
2359
Description:
cdrecord in cdrtools contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The problem is that the rscsi helper binary is installed setuid root. By specifying the target file as a command line argument, a malicious user could overwrite arbitrary files to gain root privileges resulting in a loss of integrity.
|
2003-08-01
|
cdrtools cdrecord rscsi Arbitrary File Overwrite Privilege Escalation
|
|
2354
Description:
(Description Provided by CVE) : Multiple buffer overflows in the atari800.svgalib setuid program of the Atari 800 emulator (atari800) before 1.2.2 allow local users to gain privileges via long command line arguments, as demonstrated with the -osa_rom argument.
|
2003-08-01
|
Atari800 Multiple Unspecified Local Overflows
|
|
2349
Description:
Unknown / Incomplete
|
2003-08-01
|
mSQL msqlSelectDB Function Format String
|
|
3518
Description:
Posadis DNS server contains a flaw that allows a local attacker to create a denial of service. The issue is due to two unspecified memory leaks which can be exploited by local users to consume system resources, thereby crashing the service or rendering it useless.
|
2003-08-01
|
Posadis Unspecified Local Memory Leak DoS
|
|
3519
Description:
Posadis DNS server contains a flaw that allows a remote attacker to crash the service. The issue is due to the server not handling SIGFPE signals correctly which causes the service not to close TCP connections. An attacker can send excessive crafted packets that take advantage of this, denying service to the remote machine.
|
2003-08-01
|
Posadis SIGFPE Remote DoS
|
|
3520
Description:
Posadis DNS server contains a flaw that allows a remote attacker to crash the service. The issue is due to the secondary zone configuration. No further details have been provided.
|
2003-08-01
|
Posadis Secondary Zone Remote DoS
|